AIGO — NIST AI RMF Governance Mapping
AIGO — AI Governance Operating Framework
Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-MAP-NIST-AIRMF-006
Mapping Standard: NIST AI RMF 1.0
Mapping Type: Governance Mapping
1. Purpose
This document defines the relationship between the governance requirements and outcomes described by the NIST AI Risk Management Framework (AI RMF) and the governance architecture of the AIGO AI Governance Operating Framework. The mapping establishes traceability between NIST AI RMF governance concepts and AIGO mechanisms for:- accountability;
- authority;
- roles;
- responsibilities;
- policies;
- risk governance;
- stakeholder engagement;
- organizational context;
- AI system governance;
- oversight;
- decision-making;
- escalation;
- monitoring;
- assurance;
- continual improvement.
2. Governance Mapping Objectives
The objectives are to:- establish NIST-to-AIGO governance traceability;
- define how AI governance responsibilities are allocated;
- connect AI risk management with organizational governance;
- establish governance decision authority;
- define accountability and oversight;
- connect governance with AI lifecycle activities;
- connect governance with controls and evidence;
- support consistent AI governance implementation;
- support assurance and auditability;
- provide a basis for continual governance improvement.
3. Governance as a Foundation
AI governance provides the organizational structure within which AI risk management operates.4. NIST AI RMF GOVERN Function
The NIST AI RMF GOVERN Function establishes governance as a cross-cutting capability supporting AI risk management. The GOVERN Function addresses areas including:- governance structures;
- accountability;
- policies;
- organizational context;
- legal and regulatory considerations;
- stakeholder engagement;
- risk culture;
- management responsibility.
5. AIGO Governance Architecture
AIGO governance consists of interconnected layers:6. Governance Principles
AIGO governance should be based on principles including:- accountability;
- transparency;
- proportionality;
- risk-based decision-making;
- traceability;
- human oversight;
- evidence-based governance;
- lifecycle accountability;
- continual improvement.
7. Governance Authority
Governance authority establishes who has the legitimate authority to:- establish AI governance policy;
- approve risk criteria;
- approve AI systems;
- accept residual risk;
- approve exceptions;
- require remediation;
- suspend systems;
- authorize retirement;
- oversee AI governance performance.
8. Governance Accountability
Accountability means that responsibility for AI governance outcomes is assigned to identifiable roles.9. Governance Roles
AIGO governance may include:
Actual titles may differ by organization.
10. Role Segregation
Where practical, governance should separate:- system ownership;
- risk ownership;
- control operation;
- assessment;
- approval;
- assurance.
11. Governance Decision Rights
Decision rights should define who may:- initiate an AI system;
- classify a system;
- approve risk;
- approve controls;
- authorize deployment;
- approve material changes;
- accept residual risk;
- authorize suspension;
- authorize retirement.
12. Decision Authority Model
13. Governance Policies
AI governance should be supported by documented policies. Relevant policies may address:- AI governance;
- AI risk;
- AI system use;
- data governance;
- security;
- privacy;
- human oversight;
- third-party AI;
- incident management;
- change management;
- assurance.
14. Policy Hierarchy
15. Governance and Organizational Context
AI governance should account for:- organizational objectives;
- operating environment;
- legal obligations;
- regulatory requirements;
- stakeholder expectations;
- technology environment;
- organizational risk appetite;
- available resources.
16. Context Assessment
The governance context should be periodically reviewed. Relevant changes include:- strategic changes;
- regulatory changes;
- technology changes;
- organizational restructuring;
- new AI use cases;
- significant incidents;
- stakeholder concerns.
17. Stakeholder Governance
AI governance should identify relevant stakeholders. Stakeholders may include:- users;
- customers;
- employees;
- affected individuals;
- regulators;
- suppliers;
- partners;
- communities;
- governance bodies.
18. Stakeholder Engagement
Stakeholder engagement may support:- risk identification;
- impact assessment;
- system design;
- deployment decisions;
- monitoring;
- incident response;
- improvement.
19. Governance and Risk Management
Governance establishes the environment in which AI risks are managed.20. Governance and AI Lifecycle
Governance applies across all lifecycle stages.21. Lifecycle Governance Model
22. AI System Governance
Every governed AI system should have an identifiable governance record. The record should establish, where applicable:- system identity;
- system owner;
- purpose;
- classification;
- risk profile;
- applicable controls;
- approval status;
- operating conditions;
- monitoring requirements;
- review requirements;
- retirement status.
23. AI System Registration
AI system registration establishes the governance baseline. Registration should capture sufficient information to enable:- accountability;
- classification;
- risk assessment;
- control assignment;
- approval;
- monitoring;
- assurance.
24. Governance Classification
AI systems should be classified according to organizational criteria. Classification may consider:- intended purpose;
- risk;
- impact;
- autonomy;
- affected stakeholders;
- legal requirements;
- operational criticality.
25. Proportional Governance
Governance should be proportional to:- AI system risk;
- potential impact;
- organizational context;
- regulatory significance;
- degree of autonomy;
- system complexity.
26. Governance Thresholds
Governance thresholds may determine:- required assessments;
- approval authority;
- control requirements;
- monitoring frequency;
- assurance requirements;
- review frequency;
- escalation requirements.
27. Governance Exception Management
Exceptions should be formally governed. An exception record should identify:- requirement;
- requested exception;
- rationale;
- risk;
- compensating controls;
- approving authority;
- duration;
- review date.
28. Exception Governance Model
29. Governance Risk Appetite
AI governance should establish or align with organizational risk appetite. Risk appetite informs:- acceptable AI risk;
- escalation thresholds;
- approval requirements;
- control strength;
- monitoring intensity.
30. Governance and Risk Acceptance
Risk acceptance should be performed by an authorized role. Acceptance should not be implied by failure to act. A material risk should require an explicit decision where organizational policy requires formal acceptance.31. Governance Escalation
Escalation should occur when:- risk exceeds authority;
- risk exceeds tolerance;
- controls fail;
- material incidents occur;
- governance requirements cannot be met;
- uncertainty becomes material.
32. Escalation Model
33. Governance Oversight
Oversight should determine whether AI governance operates as intended. Oversight activities may include:- governance reviews;
- risk reviews;
- control assessments;
- monitoring;
- assurance;
- management reviews;
- internal audit.
34. Governance Monitoring
Governance monitoring should consider:- AI system inventory;
- approval status;
- risk status;
- control status;
- incidents;
- exceptions;
- overdue reviews;
- assurance findings;
- corrective actions.
35. Governance Performance Indicators
Potential indicators include:- percentage of AI systems registered;
- percentage classified;
- percentage risk-assessed;
- percentage approved;
- percentage with assigned owners;
- percentage with required controls;
- overdue governance reviews;
- open exceptions;
- unresolved assurance findings.
36. Governance Dashboard
37. Governance Evidence
Governance decisions should produce evidence. Examples include:- policies;
- committee records;
- approval records;
- risk decisions;
- meeting minutes;
- assessment records;
- control assessments;
- monitoring reports;
- assurance reports;
- exception records.
38. Governance Traceability
The governance chain should be traceable.39. Governance Documentation
Governance documentation should be:- controlled;
- current;
- attributable;
- versioned;
- accessible to authorized personnel;
- retained appropriately.
40. Governance Recordkeeping
Records should demonstrate:- decisions;
- approvals;
- responsibilities;
- assessments;
- exceptions;
- risk acceptance;
- monitoring;
- assurance;
- corrective actions.
41. Governance and Controls
Controls translate governance expectations into operational mechanisms.42. Governance Control Ownership
Each material control should have an identifiable owner. Control ownership should include responsibility for:- implementation;
- operation;
- evidence;
- testing;
- remediation;
- review.
43. Governance and Procedures
AIGO procedures operationalize governance requirements. Relevant procedures include:- AI Governance Procedure;
- AI System Registration Procedure;
- AI Risk Assessment Procedure;
- AI Classification Procedure;
- AI Control Assessment Procedure;
- AI Approval Procedure;
- AI Change Management Procedure;
- AI Incident Management Procedure;
- AI Monitoring Procedure;
- AI Assurance Procedure;
- AI Risk Acceptance Procedure;
- AI Retirement Procedure;
- Continuous Improvement Procedure.
44. Governance and Evidence
Governance decisions should be evidence-based. Evidence should support:- risk decisions;
- control decisions;
- approvals;
- exceptions;
- monitoring;
- assurance.
45. Governance Evidence Chain
46. Governance and Assurance
Assurance evaluates whether governance is:- established;
- implemented;
- effective;
- documented;
- monitored;
- improved.
- internal assurance functions;
- internal audit;
- independent assessors;
- external assurance providers.
47. Independence
Where assurance requires independence, the assurance activity should be sufficiently separated from the activity being assessed. The appropriate level of independence depends on:- risk;
- organizational structure;
- assurance objective;
- applicable requirements.
48. Governance Findings
Governance findings may identify:- missing accountability;
- inadequate policies;
- ineffective controls;
- incomplete records;
- unauthorized systems;
- unresolved risks;
- overdue actions.
49. Corrective Action Governance
Corrective actions should have:- defined owner;
- target date;
- root cause;
- required action;
- verification;
- effectiveness review.
50. Corrective Action Model
51. Governance and Incidents
Material AI incidents should be governed through:- notification;
- containment;
- investigation;
- escalation;
- risk reassessment;
- corrective action;
- management review.
52. Governance and Change Management
AI changes should be governed according to their significance. Changes may include:- model changes;
- data changes;
- architecture changes;
- use-case changes;
- provider changes;
- operating-environment changes.
53. Change Governance Model
54. Governance and Monitoring
Monitoring provides governance visibility into ongoing AI operation. Monitoring may include:- performance;
- risk indicators;
- incidents;
- control performance;
- compliance;
- user feedback;
- emerging risks.
55. Governance Review Frequency
Governance reviews should occur at frequencies appropriate to:- risk;
- system criticality;
- regulatory requirements;
- organizational policy;
- changes;
- incidents.
- periodic;
- event-driven;
- management-triggered;
- risk-triggered.
56. Triggered Governance Review
A governance review may be triggered by:- material incident;
- significant model change;
- regulatory change;
- major risk increase;
- control failure;
- serious stakeholder concern;
- significant organizational change.
57. Management Review
Management review should evaluate the continued suitability and effectiveness of AI governance. Inputs may include:- AI portfolio;
- risk profile;
- control performance;
- incidents;
- assurance findings;
- exceptions;
- stakeholder feedback;
- regulatory developments.
58. Management Review Outputs
Outputs may include:- policy changes;
- resource decisions;
- control improvements;
- risk decisions;
- governance changes;
- system restrictions;
- additional assurance;
- improvement actions.
59. Governance Continual Improvement
AI governance should evolve based on:- experience;
- incidents;
- emerging risks;
- assurance findings;
- stakeholder feedback;
- regulatory change;
- technology change.
60. Governance Culture
Effective AI governance depends on organizational culture. A mature governance culture encourages:- responsible escalation;
- transparent reporting;
- evidence-based decisions;
- challenge;
- accountability;
- continuous learning.
61. Governance Competence
Relevant personnel should have appropriate competence. Competence may include:- AI knowledge;
- risk management;
- governance;
- legal and regulatory awareness;
- data governance;
- cybersecurity;
- privacy;
- assurance.
62. Competence Governance
The organization should identify competence requirements for relevant AI governance roles. Competence gaps should be addressed through:- training;
- qualification;
- mentoring;
- recruitment;
- specialist support.
63. Governance Resources
AI governance requires sufficient resources. Resources may include:- personnel;
- technical capability;
- assessment tools;
- monitoring systems;
- assurance capability;
- documentation systems;
- training.
64. Governance Communication
Governance expectations should be communicated to relevant personnel. Communication may include:- policies;
- procedures;
- training;
- governance meetings;
- risk reports;
- management communications.
65. Governance Transparency
Appropriate transparency should exist regarding:- AI system purpose;
- accountability;
- governance responsibilities;
- decision processes;
- risk status;
- applicable controls.
- confidentiality;
- security;
- privacy;
- intellectual property.
66. Governance Accountability for Third Parties
Third-party AI services should not create an accountability gap. Contracts and governance arrangements should address, where relevant:- responsibilities;
- security;
- privacy;
- performance;
- incident notification;
- changes;
- evidence;
- audit or assurance rights.
67. Third-Party Governance Model
68. Governance of AI Supply Chains
AI supply-chain governance should consider:- model providers;
- data providers;
- software dependencies;
- infrastructure;
- APIs;
- outsourced services.
69. Governance and Legal Requirements
AI governance should identify applicable:- laws;
- regulations;
- contractual obligations;
- standards;
- internal requirements.
70. Governance Compliance
Compliance should not be treated solely as documentation. Governance should verify:- applicable requirements are identified;
- responsibilities are assigned;
- controls address requirements;
- evidence exists;
- compliance status is monitored.
71. Governance and Regulatory Change
Regulatory changes should trigger governance review where material.72. Governance and Human Oversight
Governance should define where human oversight is required. Oversight requirements may address:- decision review;
- intervention;
- override;
- escalation;
- competence;
- accountability.
73. Human Oversight Governance
74. Governance and AI Autonomy
Higher autonomy may require stronger governance mechanisms. Governance should consider:- degree of autonomy;
- decision authority;
- reversibility;
- potential harm;
- human intervention capability.
75. Governance of High-Risk AI
High-risk AI systems may require:- enhanced approval;
- stronger controls;
- additional assurance;
- increased monitoring;
- more frequent review;
- documented risk acceptance.
76. Governance of Low-Risk AI
Lower-risk systems may use simplified governance where justified. Simplification should not remove:- accountability;
- basic registration;
- appropriate risk consideration;
- required legal compliance.
77. Governance Proportionality Model
78. Governance Maturity
AIGO governance maturity may progress through:
These levels should align with the AIGO maturity model.
79. Governance Maturity Indicators
Indicators may include:- governance coverage;
- role clarity;
- policy completeness;
- risk integration;
- control effectiveness;
- evidence quality;
- assurance maturity;
- continual improvement.
80. Governance Integration
Governance should integrate:81. NIST GOVERN-to-AIGO Traceability
82. GOVERN and AIGO Governance Domains
NIST GOVERN concepts map across AIGO governance domains rather than to a single domain. Relevant AIGO domains include:- governance;
- risk;
- lifecycle;
- controls;
- monitoring;
- assurance;
- improvement.
83. GOVERN-to-Risk Relationship
84. GOVERN-to-Control Relationship
Governance establishes control expectations.85. GOVERN-to-Evidence Relationship
Governance must be demonstrable through evidence. Evidence may demonstrate:- accountability;
- decisions;
- approvals;
- oversight;
- monitoring;
- corrective action.
86. Governance Traceability Matrix
87. Governance-to-Lifecycle Traceability
88. Governance-to-Procedure Traceability
89. Governance-to-Evidence Traceability
90. Governance Gap Analysis
A governance gap may exist where:- responsibility is undefined;
- authority is unclear;
- policy is absent;
- risk decisions lack ownership;
- controls lack ownership;
- evidence is unavailable;
- oversight is absent;
- assurance is ineffective.
91. Governance Gap Record
92. Governance Effectiveness
Governance effectiveness should be evaluated using evidence. Potential indicators include:- role clarity;
- decision timeliness;
- risk escalation effectiveness;
- control effectiveness;
- audit findings;
- unresolved exceptions;
- incident trends;
- management review outcomes.
93. Governance Review Cycle
94. Governance Decision Records
Material decisions should record:- decision;
- decision date;
- authority;
- issue;
- risk;
- evidence;
- rationale;
- conditions;
- review date.
95. Governance Decision Traceability
96. Governance and Organizational Accountability
AIGO governance should integrate with existing organizational structures where practical. It should avoid unnecessary duplication while ensuring AI-specific risks and responsibilities are adequately addressed.97. Governance Committee Structure
Organizations may establish an AI governance committee or assign AI governance responsibilities to an existing governance body. Possible responsibilities include:- portfolio oversight;
- risk review;
- policy approval;
- exception review;
- system approval;
- assurance review;
- improvement oversight.
98. Governance Meeting Inputs
Governance meetings may consider:- new AI systems;
- high-risk systems;
- significant incidents;
- emerging risks;
- exceptions;
- assurance findings;
- regulatory changes;
- performance trends;
- improvement opportunities.
99. Governance Meeting Outputs
Outputs may include:- approvals;
- risk decisions;
- escalations;
- corrective actions;
- policy changes;
- control changes;
- resource decisions;
- monitoring requirements.
100. Governance Communication Records
Governance communications should be retained where they constitute evidence of material decisions or instructions. Examples include:- meeting minutes;
- decision records;
- formal approvals;
- risk notifications;
- governance directives.
101. Governance and Resource Allocation
Governance should consider whether sufficient resources exist to manage AI risks. Where resources are insufficient, governance should determine whether to:- increase resources;
- reduce scope;
- restrict use;
- delay deployment;
- discontinue the system.
102. Governance and Portfolio Management
Where an organization operates multiple AI systems, governance should consider the portfolio. Portfolio governance may examine:- aggregate risk;
- shared dependencies;
- concentration risk;
- common controls;
- common providers;
- common incidents;
- resource requirements.
103. AI Portfolio Governance
104. Governance of Shared AI Services
Shared AI services should have defined:- owner;
- risk profile;
- controls;
- service boundaries;
- users;
- monitoring;
- escalation mechanisms.
105. Governance and AI Inventory
The AI inventory provides governance visibility. It should support identification of:- active systems;
- systems under development;
- retired systems;
- owners;
- classifications;
- risk levels;
- approval status.
106. Governance Inventory Review
The AI inventory should be periodically reconciled against actual AI use. This helps identify:- unauthorized systems;
- shadow AI;
- outdated records;
- missing owners;
- missing risk assessments.
107. Governance of Shadow AI
Unauthorized or unmanaged AI use should be treated as a governance concern. Responses may include:- awareness;
- registration;
- risk assessment;
- restrictions;
- technical controls;
- policy enforcement.
108. Governance and Responsible AI
Responsible AI expectations should be translated into:- governance principles;
- risk criteria;
- controls;
- procedures;
- monitoring;
- evidence.
109. Governance and Ethical Considerations
Where ethical considerations are material, governance should provide mechanisms for:- identification;
- assessment;
- stakeholder input;
- escalation;
- decision-making;
- documentation.
110. Governance and Societal Impact
Where AI systems may create broader societal effects, governance should consider:- affected communities;
- public trust;
- social impacts;
- systemic risks;
- unintended consequences.
111. Governance and Fundamental Rights
Where applicable, governance should consider impacts on:- rights;
- freedoms;
- dignity;
- equality;
- privacy;
- access.
112. Governance and Sustainability
Where material, governance may consider:- environmental impacts;
- resource consumption;
- energy use;
- infrastructure impacts.
113. Governance and Model Lifecycle
Governance should remain applicable throughout:114. Governance and Data Lifecycle
AI governance should also consider:- data acquisition;
- preparation;
- use;
- storage;
- sharing;
- retention;
- deletion.
115. Governance and Documentation Quality
Governance documentation should support:- traceability;
- reproducibility where applicable;
- accountability;
- review;
- assurance.
116. Governance and Record Integrity
Governance records should protect against:- unauthorized alteration;
- loss;
- ambiguity;
- incomplete history.
117. Governance and Access Control
Access to governance information should follow:- least privilege;
- role-based access;
- confidentiality requirements;
- legal requirements.
118. Governance and Security
AI governance should integrate cybersecurity governance. Security should be addressed throughout the AI lifecycle and risk-management process.119. Governance and Privacy
Privacy governance should integrate with AI governance where personal data is involved. Responsibilities should be clearly assigned.120. Governance and Compliance Monitoring
Compliance monitoring should identify:- new requirements;
- non-compliance;
- control weaknesses;
- overdue actions;
- regulatory developments.
121. Governance and Assurance Reporting
Assurance results should be communicated to the appropriate governance authority. Material findings should receive timely attention.122. Governance and Internal Audit
Where applicable, internal audit may provide independent assurance over:- governance design;
- governance effectiveness;
- risk management;
- controls;
- compliance.
123. Governance and External Assurance
External assurance may be used where appropriate. Examples include:- certification assessment;
- independent assessment;
- specialist review;
- regulatory examination.
124. Governance Improvement Prioritization
Improvement opportunities should be prioritized according to:- risk;
- impact;
- urgency;
- regulatory significance;
- resource requirements.
125. Governance Improvement Model
126. NIST GOVERN Integration Summary
The NIST GOVERN Function is mapped to the AIGO governance architecture through:- governance authority;
- accountability;
- roles;
- policies;
- risk governance;
- stakeholder governance;
- lifecycle governance;
- control governance;
- evidence;
- assurance;
- continual improvement.
127. End-to-End Governance Traceability
128. Governance Mapping Summary
129. Mapping Limitations
This document:- does not reproduce the NIST AI RMF;
- does not constitute NIST certification;
- does not constitute NIST endorsement;
- does not constitute legal advice;
- does not by itself establish regulatory compliance;
- does not replace organization-specific governance requirements;
- does not replace technical or legal assessment.
130. Maintenance Requirements
This document should be reviewed when:- NIST AI RMF changes;
- AIGO governance architecture changes;
- AIGO roles change;
- AIGO policies change;
- risk governance changes;
- control architecture changes;
- material regulatory requirements change;
- governance gaps are identified;
- organizational context materially changes.
131. Document Change Record
132. Document Control
132.1 Controlled Information
133. Final Control Statement
This document establishes the governance relationship between the NIST AI Risk Management Framework and the AIGO AI Governance Operating Framework. It provides traceability between NIST AI RMF governance concepts and AIGO mechanisms for:- governance authority;
- accountability;
- roles and responsibilities;
- policies;
- organizational context;
- stakeholder engagement;
- AI system governance;
- risk governance;
- decision-making;
- oversight;
- controls;
- evidence;
- assurance;
- continual improvement.
134. End of Mapping Document
AIGO — NIST AI RMF Governance Mapping Document ID:AIGO-MAP-NIST-AIRMF-006
Version: 0.1
Status: Draft
Mapping Standard: NIST AI RMF 1.0
Mapping Type: Governance Mapping
End of Document