> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 06 AIGO NIST AI RMF Governance Mapping v0.1

# AIGO — NIST AI RMF Governance Mapping

## AIGO — AI Governance Operating Framework

**Version:** 0.1
**Status:** Draft
**Working Name:** AIGO
**Full Name:** AI Governance Operating Framework
**Document Identifier:** `AIGO-MAP-NIST-AIRMF-006`
**Mapping Standard:** NIST AI RMF 1.0
**Mapping Type:** Governance Mapping

***

## 1. Purpose

This document defines the relationship between the governance requirements and outcomes described by the NIST AI Risk Management Framework (AI RMF) and the governance architecture of the AIGO AI Governance Operating Framework.

The mapping establishes traceability between NIST AI RMF governance concepts and AIGO mechanisms for:

* accountability;
* authority;
* roles;
* responsibilities;
* policies;
* risk governance;
* stakeholder engagement;
* organizational context;
* AI system governance;
* oversight;
* decision-making;
* escalation;
* monitoring;
* assurance;
* continual improvement.

This document complements the AIGO-NIST AI RMF Mapping, Requirements Mapping, Control Mapping, Lifecycle Mapping, Risk Mapping, Evidence Mapping and Implementation Mapping documents.

***

# 2. Governance Mapping Objectives

The objectives are to:

1. establish NIST-to-AIGO governance traceability;
2. define how AI governance responsibilities are allocated;
3. connect AI risk management with organizational governance;
4. establish governance decision authority;
5. define accountability and oversight;
6. connect governance with AI lifecycle activities;
7. connect governance with controls and evidence;
8. support consistent AI governance implementation;
9. support assurance and auditability;
10. provide a basis for continual governance improvement.

***

# 3. Governance as a Foundation

AI governance provides the organizational structure within which AI risk management operates.

```text theme={null}
Organizational Governance
        ↓
AI Governance
        ↓
AI Risk Governance
        ↓
AI System Governance
        ↓
Lifecycle Governance
        ↓
Controls
        ↓
Evidence
        ↓
Assurance
```

Governance therefore operates across the complete AIGO framework rather than being limited to a single lifecycle stage.

***

# 4. NIST AI RMF GOVERN Function

The NIST AI RMF GOVERN Function establishes governance as a cross-cutting capability supporting AI risk management.

The GOVERN Function addresses areas including:

* governance structures;
* accountability;
* policies;
* organizational context;
* legal and regulatory considerations;
* stakeholder engagement;
* risk culture;
* management responsibility.

AIGO operationalizes these concepts through its governance architecture.

***

# 5. AIGO Governance Architecture

AIGO governance consists of interconnected layers:

```text theme={null}
Governance Authority
        ↓
Governance Principles
        ↓
Governance Domains
        ↓
Governance Roles
        ↓
Policies
        ↓
Risk Management
        ↓
Controls
        ↓
Lifecycle Processes
        ↓
Evidence
        ↓
Assurance
        ↓
Improvement
```

***

# 6. Governance Principles

AIGO governance should be based on principles including:

* accountability;
* transparency;
* proportionality;
* risk-based decision-making;
* traceability;
* human oversight;
* evidence-based governance;
* lifecycle accountability;
* continual improvement.

These principles provide the foundation for governance decisions.

***

# 7. Governance Authority

Governance authority establishes who has the legitimate authority to:

* establish AI governance policy;
* approve risk criteria;
* approve AI systems;
* accept residual risk;
* approve exceptions;
* require remediation;
* suspend systems;
* authorize retirement;
* oversee AI governance performance.

Authority should be formally assigned.

***

# 8. Governance Accountability

Accountability means that responsibility for AI governance outcomes is assigned to identifiable roles.

```text theme={null}
Governance Requirement
        ↓
Accountable Role
        ↓
Responsible Activity
        ↓
Decision
        ↓
Evidence
        ↓
Oversight
```

Accountability should remain clear even where activities are delegated.

***

# 9. Governance Roles

AIGO governance may include:

| Role                           | Primary Governance Responsibility      |
| ------------------------------ | -------------------------------------- |
| Executive Governance Authority | Overall organizational AI governance   |
| AI Governance Authority        | AI governance framework oversight      |
| AI System Owner                | System accountability                  |
| Risk Owner                     | AI risk accountability                 |
| Control Owner                  | Control accountability                 |
| Assessor                       | Assessment                             |
| Assurance Function             | Independent or objective assurance     |
| Compliance Function            | Regulatory and policy alignment        |
| Security Function              | Security governance                    |
| Privacy Function               | Privacy governance                     |
| Legal Function                 | Legal interpretation and advice        |
| Operational Owner              | Operational governance                 |
| Internal Audit                 | Independent assurance where applicable |

Actual titles may differ by organization.

***

# 10. Role Segregation

Where practical, governance should separate:

* system ownership;
* risk ownership;
* control operation;
* assessment;
* approval;
* assurance.

This separation reduces conflicts of interest and strengthens decision integrity.

***

# 11. Governance Decision Rights

Decision rights should define who may:

* initiate an AI system;
* classify a system;
* approve risk;
* approve controls;
* authorize deployment;
* approve material changes;
* accept residual risk;
* authorize suspension;
* authorize retirement.

***

# 12. Decision Authority Model

```text theme={null}
AI System
   ↓
Assessment
   ↓
Risk Rating
   ↓
Governance Threshold
   ↓
Decision Authority
   ↓
Approval / Escalation
```

Decision authority should be proportional to risk.

***

# 13. Governance Policies

AI governance should be supported by documented policies.

Relevant policies may address:

* AI governance;
* AI risk;
* AI system use;
* data governance;
* security;
* privacy;
* human oversight;
* third-party AI;
* incident management;
* change management;
* assurance.

***

# 14. Policy Hierarchy

```text theme={null}
Organizational Policy
        ↓
AI Governance Policy
        ↓
AI Governance Standards
        ↓
Procedures
        ↓
Controls
        ↓
Records / Evidence
```

Policies should establish direction rather than duplicate detailed procedures.

***

# 15. Governance and Organizational Context

AI governance should account for:

* organizational objectives;
* operating environment;
* legal obligations;
* regulatory requirements;
* stakeholder expectations;
* technology environment;
* organizational risk appetite;
* available resources.

***

# 16. Context Assessment

The governance context should be periodically reviewed.

Relevant changes include:

* strategic changes;
* regulatory changes;
* technology changes;
* organizational restructuring;
* new AI use cases;
* significant incidents;
* stakeholder concerns.

***

# 17. Stakeholder Governance

AI governance should identify relevant stakeholders.

Stakeholders may include:

* users;
* customers;
* employees;
* affected individuals;
* regulators;
* suppliers;
* partners;
* communities;
* governance bodies.

***

# 18. Stakeholder Engagement

Stakeholder engagement may support:

* risk identification;
* impact assessment;
* system design;
* deployment decisions;
* monitoring;
* incident response;
* improvement.

Stakeholder involvement should be proportionate to the AI system and its potential impacts.

***

# 19. Governance and Risk Management

Governance establishes the environment in which AI risks are managed.

```text theme={null}
Governance
   ↓
Risk Criteria
   ↓
Risk Identification
   ↓
Risk Assessment
   ↓
Risk Treatment
   ↓
Risk Decision
   ↓
Risk Oversight
```

***

# 20. Governance and AI Lifecycle

Governance applies across all lifecycle stages.

| AIGO Lifecycle Stage | Governance Activity             |
| -------------------- | ------------------------------- |
| Govern               | Governance establishment        |
| Identify             | Governance context              |
| Classify             | Governance classification       |
| Assess               | Governance oversight            |
| Treat                | Risk treatment governance       |
| Approve              | Decision governance             |
| Deploy               | Deployment authorization        |
| Operate              | Operational oversight           |
| Monitor              | Performance and risk oversight  |
| Assure               | Independent or objective review |
| Improve              | Governance improvement          |
| Change               | Change authorization            |
| Continue             | Continuation decision           |
| Retire               | Retirement authorization        |

***

# 21. Lifecycle Governance Model

```text theme={null}
Govern
   ↓
Identify
   ↓
Classify
   ↓
Assess
   ↓
Treat
   ↓
Approve
   ↓
Deploy
   ↓
Operate
   ↓
Monitor
   ↓
Assure
   ↓
Improve
   ↓
Change / Continue / Retire
```

Governance remains applicable throughout the cycle.

***

# 22. AI System Governance

Every governed AI system should have an identifiable governance record.

The record should establish, where applicable:

* system identity;
* system owner;
* purpose;
* classification;
* risk profile;
* applicable controls;
* approval status;
* operating conditions;
* monitoring requirements;
* review requirements;
* retirement status.

***

# 23. AI System Registration

AI system registration establishes the governance baseline.

Registration should capture sufficient information to enable:

* accountability;
* classification;
* risk assessment;
* control assignment;
* approval;
* monitoring;
* assurance.

***

# 24. Governance Classification

AI systems should be classified according to organizational criteria.

Classification may consider:

* intended purpose;
* risk;
* impact;
* autonomy;
* affected stakeholders;
* legal requirements;
* operational criticality.

Classification determines the level of governance required.

***

# 25. Proportional Governance

Governance should be proportional to:

* AI system risk;
* potential impact;
* organizational context;
* regulatory significance;
* degree of autonomy;
* system complexity.

High-risk systems should receive stronger governance oversight.

***

# 26. Governance Thresholds

Governance thresholds may determine:

* required assessments;
* approval authority;
* control requirements;
* monitoring frequency;
* assurance requirements;
* review frequency;
* escalation requirements.

***

# 27. Governance Exception Management

Exceptions should be formally governed.

An exception record should identify:

* requirement;
* requested exception;
* rationale;
* risk;
* compensating controls;
* approving authority;
* duration;
* review date.

***

# 28. Exception Governance Model

```text theme={null}
Requirement
   ↓
Exception Request
   ↓
Risk Assessment
   ↓
Compensating Controls
   ↓
Authority Review
   ↓
Approve / Reject
   ↓
Monitor
   ↓
Expire / Renew / Close
```

***

# 29. Governance Risk Appetite

AI governance should establish or align with organizational risk appetite.

Risk appetite informs:

* acceptable AI risk;
* escalation thresholds;
* approval requirements;
* control strength;
* monitoring intensity.

***

# 30. Governance and Risk Acceptance

Risk acceptance should be performed by an authorized role.

Acceptance should not be implied by failure to act.

A material risk should require an explicit decision where organizational policy requires formal acceptance.

***

# 31. Governance Escalation

Escalation should occur when:

* risk exceeds authority;
* risk exceeds tolerance;
* controls fail;
* material incidents occur;
* governance requirements cannot be met;
* uncertainty becomes material.

***

# 32. Escalation Model

```text theme={null}
Issue / Risk
     ↓
Operational Owner
     ↓
Risk Owner
     ↓
AI Governance Authority
     ↓
Executive Governance Authority
     ↓
Decision
```

Actual escalation levels should be defined by the organization.

***

# 33. Governance Oversight

Oversight should determine whether AI governance operates as intended.

Oversight activities may include:

* governance reviews;
* risk reviews;
* control assessments;
* monitoring;
* assurance;
* management reviews;
* internal audit.

***

# 34. Governance Monitoring

Governance monitoring should consider:

* AI system inventory;
* approval status;
* risk status;
* control status;
* incidents;
* exceptions;
* overdue reviews;
* assurance findings;
* corrective actions.

***

# 35. Governance Performance Indicators

Potential indicators include:

* percentage of AI systems registered;
* percentage classified;
* percentage risk-assessed;
* percentage approved;
* percentage with assigned owners;
* percentage with required controls;
* overdue governance reviews;
* open exceptions;
* unresolved assurance findings.

***

# 36. Governance Dashboard

```text theme={null}
AI Portfolio
     ↓
Registered Systems
     ↓
Risk Profile
     ↓
Control Status
     ↓
Approval Status
     ↓
Exceptions
     ↓
Incidents
     ↓
Assurance Findings
     ↓
Management Actions
```

***

# 37. Governance Evidence

Governance decisions should produce evidence.

Examples include:

* policies;
* committee records;
* approval records;
* risk decisions;
* meeting minutes;
* assessment records;
* control assessments;
* monitoring reports;
* assurance reports;
* exception records.

***

# 38. Governance Traceability

The governance chain should be traceable.

```text theme={null}
Requirement
   ↓
Governance Rule
   ↓
Responsible Role
   ↓
Procedure
   ↓
Control
   ↓
Evidence
   ↓
Decision
   ↓
Oversight
```

***

# 39. Governance Documentation

Governance documentation should be:

* controlled;
* current;
* attributable;
* versioned;
* accessible to authorized personnel;
* retained appropriately.

***

# 40. Governance Recordkeeping

Records should demonstrate:

* decisions;
* approvals;
* responsibilities;
* assessments;
* exceptions;
* risk acceptance;
* monitoring;
* assurance;
* corrective actions.

***

# 41. Governance and Controls

Controls translate governance expectations into operational mechanisms.

```text theme={null}
Governance Objective
        ↓
Control Objective
        ↓
Control
        ↓
Procedure
        ↓
Evidence
        ↓
Control Assessment
```

***

# 42. Governance Control Ownership

Each material control should have an identifiable owner.

Control ownership should include responsibility for:

* implementation;
* operation;
* evidence;
* testing;
* remediation;
* review.

***

# 43. Governance and Procedures

AIGO procedures operationalize governance requirements.

Relevant procedures include:

* AI Governance Procedure;
* AI System Registration Procedure;
* AI Risk Assessment Procedure;
* AI Classification Procedure;
* AI Control Assessment Procedure;
* AI Approval Procedure;
* AI Change Management Procedure;
* AI Incident Management Procedure;
* AI Monitoring Procedure;
* AI Assurance Procedure;
* AI Risk Acceptance Procedure;
* AI Retirement Procedure;
* Continuous Improvement Procedure.

***

# 44. Governance and Evidence

Governance decisions should be evidence-based.

Evidence should support:

* risk decisions;
* control decisions;
* approvals;
* exceptions;
* monitoring;
* assurance.

***

# 45. Governance Evidence Chain

```text theme={null}
Governance Requirement
       ↓
Activity
       ↓
Control
       ↓
Record
       ↓
Evidence
       ↓
Review
       ↓
Decision
```

***

# 46. Governance and Assurance

Assurance evaluates whether governance is:

* established;
* implemented;
* effective;
* documented;
* monitored;
* improved.

Assurance may be performed by:

* internal assurance functions;
* internal audit;
* independent assessors;
* external assurance providers.

***

# 47. Independence

Where assurance requires independence, the assurance activity should be sufficiently separated from the activity being assessed.

The appropriate level of independence depends on:

* risk;
* organizational structure;
* assurance objective;
* applicable requirements.

***

# 48. Governance Findings

Governance findings may identify:

* missing accountability;
* inadequate policies;
* ineffective controls;
* incomplete records;
* unauthorized systems;
* unresolved risks;
* overdue actions.

***

# 49. Corrective Action Governance

Corrective actions should have:

* defined owner;
* target date;
* root cause;
* required action;
* verification;
* effectiveness review.

***

# 50. Corrective Action Model

```text theme={null}
Finding
   ↓
Root Cause
   ↓
Corrective Action
   ↓
Owner
   ↓
Implementation
   ↓
Verification
   ↓
Effectiveness
   ↓
Closure
```

***

# 51. Governance and Incidents

Material AI incidents should be governed through:

* notification;
* containment;
* investigation;
* escalation;
* risk reassessment;
* corrective action;
* management review.

***

# 52. Governance and Change Management

AI changes should be governed according to their significance.

Changes may include:

* model changes;
* data changes;
* architecture changes;
* use-case changes;
* provider changes;
* operating-environment changes.

***

# 53. Change Governance Model

```text theme={null}
Change Request
      ↓
Change Classification
      ↓
Impact Analysis
      ↓
Risk Assessment
      ↓
Control Review
      ↓
Approval
      ↓
Implementation
      ↓
Post-Change Review
```

***

# 54. Governance and Monitoring

Monitoring provides governance visibility into ongoing AI operation.

Monitoring may include:

* performance;
* risk indicators;
* incidents;
* control performance;
* compliance;
* user feedback;
* emerging risks.

***

# 55. Governance Review Frequency

Governance reviews should occur at frequencies appropriate to:

* risk;
* system criticality;
* regulatory requirements;
* organizational policy;
* changes;
* incidents.

Reviews may be:

* periodic;
* event-driven;
* management-triggered;
* risk-triggered.

***

# 56. Triggered Governance Review

A governance review may be triggered by:

* material incident;
* significant model change;
* regulatory change;
* major risk increase;
* control failure;
* serious stakeholder concern;
* significant organizational change.

***

# 57. Management Review

Management review should evaluate the continued suitability and effectiveness of AI governance.

Inputs may include:

* AI portfolio;
* risk profile;
* control performance;
* incidents;
* assurance findings;
* exceptions;
* stakeholder feedback;
* regulatory developments.

***

# 58. Management Review Outputs

Outputs may include:

* policy changes;
* resource decisions;
* control improvements;
* risk decisions;
* governance changes;
* system restrictions;
* additional assurance;
* improvement actions.

***

# 59. Governance Continual Improvement

AI governance should evolve based on:

* experience;
* incidents;
* emerging risks;
* assurance findings;
* stakeholder feedback;
* regulatory change;
* technology change.

```text theme={null}
Governance Experience
        ↓
Lessons Learned
        ↓
Gap / Opportunity
        ↓
Governance Change
        ↓
Implementation
        ↓
Evaluation
        ↓
Continual Improvement
        ↺
```

***

# 60. Governance Culture

Effective AI governance depends on organizational culture.

A mature governance culture encourages:

* responsible escalation;
* transparent reporting;
* evidence-based decisions;
* challenge;
* accountability;
* continuous learning.

***

# 61. Governance Competence

Relevant personnel should have appropriate competence.

Competence may include:

* AI knowledge;
* risk management;
* governance;
* legal and regulatory awareness;
* data governance;
* cybersecurity;
* privacy;
* assurance.

***

# 62. Competence Governance

The organization should identify competence requirements for relevant AI governance roles.

Competence gaps should be addressed through:

* training;
* qualification;
* mentoring;
* recruitment;
* specialist support.

***

# 63. Governance Resources

AI governance requires sufficient resources.

Resources may include:

* personnel;
* technical capability;
* assessment tools;
* monitoring systems;
* assurance capability;
* documentation systems;
* training.

Resource adequacy should be reviewed in proportion to AI risk.

***

# 64. Governance Communication

Governance expectations should be communicated to relevant personnel.

Communication may include:

* policies;
* procedures;
* training;
* governance meetings;
* risk reports;
* management communications.

***

# 65. Governance Transparency

Appropriate transparency should exist regarding:

* AI system purpose;
* accountability;
* governance responsibilities;
* decision processes;
* risk status;
* applicable controls.

Transparency should respect:

* confidentiality;
* security;
* privacy;
* intellectual property.

***

# 66. Governance Accountability for Third Parties

Third-party AI services should not create an accountability gap.

Contracts and governance arrangements should address, where relevant:

* responsibilities;
* security;
* privacy;
* performance;
* incident notification;
* changes;
* evidence;
* audit or assurance rights.

***

# 67. Third-Party Governance Model

```text theme={null}
Third Party
    ↓
Contract
    ↓
Governance Requirements
    ↓
Risk Assessment
    ↓
Controls
    ↓
Monitoring
    ↓
Assurance
    ↓
Review
```

***

# 68. Governance of AI Supply Chains

AI supply-chain governance should consider:

* model providers;
* data providers;
* software dependencies;
* infrastructure;
* APIs;
* outsourced services.

Dependencies should be identified and risk-assessed.

***

# 69. Governance and Legal Requirements

AI governance should identify applicable:

* laws;
* regulations;
* contractual obligations;
* standards;
* internal requirements.

Legal requirements should be incorporated into relevant governance decisions.

***

# 70. Governance Compliance

Compliance should not be treated solely as documentation.

Governance should verify:

* applicable requirements are identified;
* responsibilities are assigned;
* controls address requirements;
* evidence exists;
* compliance status is monitored.

***

# 71. Governance and Regulatory Change

Regulatory changes should trigger governance review where material.

```text theme={null}
Regulatory Change
      ↓
Applicability Assessment
      ↓
Gap Analysis
      ↓
Risk Assessment
      ↓
Governance Change
      ↓
Control / Procedure Update
      ↓
Implementation
      ↓
Verification
```

***

# 72. Governance and Human Oversight

Governance should define where human oversight is required.

Oversight requirements may address:

* decision review;
* intervention;
* override;
* escalation;
* competence;
* accountability.

***

# 73. Human Oversight Governance

```text theme={null}
AI Output
   ↓
Human Review
   ↓
Decision
   ↓
Override / Accept / Escalate
   ↓
Record
```

The degree of human involvement should be proportionate to risk.

***

# 74. Governance and AI Autonomy

Higher autonomy may require stronger governance mechanisms.

Governance should consider:

* degree of autonomy;
* decision authority;
* reversibility;
* potential harm;
* human intervention capability.

***

# 75. Governance of High-Risk AI

High-risk AI systems may require:

* enhanced approval;
* stronger controls;
* additional assurance;
* increased monitoring;
* more frequent review;
* documented risk acceptance.

Exact requirements should follow applicable organizational and regulatory criteria.

***

# 76. Governance of Low-Risk AI

Lower-risk systems may use simplified governance where justified.

Simplification should not remove:

* accountability;
* basic registration;
* appropriate risk consideration;
* required legal compliance.

***

# 77. Governance Proportionality Model

```text theme={null}
Higher Risk
    ↓
Higher Governance Intensity
    ↓
More Controls
    ↓
More Evidence
    ↓
More Monitoring
    ↓
More Assurance
```

***

# 78. Governance Maturity

AIGO governance maturity may progress through:

| Level | Governance Capability |
| ----- | --------------------- |
| 1     | Ad hoc                |
| 2     | Defined               |
| 3     | Managed               |
| 4     | Measured              |
| 5     | Optimized             |

These levels should align with the AIGO maturity model.

***

# 79. Governance Maturity Indicators

Indicators may include:

* governance coverage;
* role clarity;
* policy completeness;
* risk integration;
* control effectiveness;
* evidence quality;
* assurance maturity;
* continual improvement.

***

# 80. Governance Integration

Governance should integrate:

```text theme={null}
Policy
  +
Risk
  +
Controls
  +
Lifecycle
  +
Evidence
  +
Assurance
  +
Improvement
```

These elements should operate as one governance system.

***

# 81. NIST GOVERN-to-AIGO Traceability

| NIST GOVERN Concept        | AIGO Governance Mechanism       |
| -------------------------- | ------------------------------- |
| Governance culture         | AIGO governance principles      |
| Accountability             | AIGO governance roles           |
| Policies                   | Governance policy structure     |
| Organizational context     | Context assessment              |
| Risk governance            | AIGO risk framework             |
| Stakeholder engagement     | Stakeholder governance          |
| Legal requirements         | Compliance governance           |
| Roles and responsibilities | Governance roles                |
| Oversight                  | Assurance and management review |
| Continual improvement      | Improvement framework           |

***

# 82. GOVERN and AIGO Governance Domains

NIST GOVERN concepts map across AIGO governance domains rather than to a single domain.

Relevant AIGO domains include:

* governance;
* risk;
* lifecycle;
* controls;
* monitoring;
* assurance;
* improvement.

***

# 83. GOVERN-to-Risk Relationship

```text theme={null}
GOVERN
   ↓
Risk Governance
   ↓
Risk Criteria
   ↓
Risk Assessment
   ↓
Risk Treatment
   ↓
Risk Decision
   ↓
Risk Oversight
```

***

# 84. GOVERN-to-Control Relationship

Governance establishes control expectations.

```text theme={null}
Governance Requirement
      ↓
Control Objective
      ↓
Control
      ↓
Procedure
      ↓
Evidence
      ↓
Assessment
```

***

# 85. GOVERN-to-Evidence Relationship

Governance must be demonstrable through evidence.

Evidence may demonstrate:

* accountability;
* decisions;
* approvals;
* oversight;
* monitoring;
* corrective action.

***

# 86. Governance Traceability Matrix

| Governance Element   | AIGO Reference         | Evidence           |
| -------------------- | ---------------------- | ------------------ |
| Governance authority | Governance structure   | Authority record   |
| Accountability       | Roles                  | Role assignment    |
| Policy               | Governance policy      | Approved policy    |
| Risk governance      | Risk framework         | Risk records       |
| Approval             | Approval process       | Approval record    |
| Oversight            | Monitoring / assurance | Review report      |
| Improvement          | Continual improvement  | Improvement record |

***

# 87. Governance-to-Lifecycle Traceability

| Governance Activity      | Lifecycle Application |
| ------------------------ | --------------------- |
| Governance establishment | Govern                |
| Context                  | Identify              |
| Classification authority | Classify              |
| Risk oversight           | Assess                |
| Treatment authorization  | Treat                 |
| Approval                 | Approve               |
| Deployment authorization | Deploy                |
| Operational oversight    | Operate               |
| Performance oversight    | Monitor               |
| Assurance                | Assure                |
| Improvement decisions    | Improve               |
| Change approval          | Change                |
| Continuation decision    | Continue              |
| Retirement authorization | Retire                |

***

# 88. Governance-to-Procedure Traceability

| Governance Requirement | AIGO Procedure                   |
| ---------------------- | -------------------------------- |
| Governance             | AI Governance Procedure          |
| Registration           | AI System Registration Procedure |
| Risk                   | AI Risk Assessment Procedure     |
| Classification         | AI Classification Procedure      |
| Controls               | AI Control Assessment Procedure  |
| Approval               | AI Approval Procedure            |
| Change                 | AI Change Management Procedure   |
| Incident               | AI Incident Management Procedure |
| Monitoring             | AI Monitoring Procedure          |
| Assurance              | AI Assurance Procedure           |
| Acceptance             | AI Risk Acceptance Procedure     |
| Retirement             | AI Retirement Procedure          |
| Improvement            | Continuous Improvement Procedure |

***

# 89. Governance-to-Evidence Traceability

```text theme={null}
Governance Requirement
       ↓
Governance Activity
       ↓
Responsible Role
       ↓
Procedure
       ↓
Control
       ↓
Evidence
       ↓
Assurance
```

***

# 90. Governance Gap Analysis

A governance gap may exist where:

* responsibility is undefined;
* authority is unclear;
* policy is absent;
* risk decisions lack ownership;
* controls lack ownership;
* evidence is unavailable;
* oversight is absent;
* assurance is ineffective.

***

# 91. Governance Gap Record

| Field          | Description               |
| -------------- | ------------------------- |
| Gap ID         | Unique identifier         |
| NIST Reference | NIST governance reference |
| AIGO Reference | AIGO governance element   |
| Gap            | Deficiency                |
| Impact         | Governance consequence    |
| Owner          | Responsible role          |
| Action         | Remediation               |
| Target Date    | Completion target         |
| Status         | Current status            |
| Evidence       | Closure evidence          |

***

# 92. Governance Effectiveness

Governance effectiveness should be evaluated using evidence.

Potential indicators include:

* role clarity;
* decision timeliness;
* risk escalation effectiveness;
* control effectiveness;
* audit findings;
* unresolved exceptions;
* incident trends;
* management review outcomes.

***

# 93. Governance Review Cycle

```text theme={null}
Governance Planning
      ↓
Implementation
      ↓
Monitoring
      ↓
Assurance
      ↓
Management Review
      ↓
Corrective Action
      ↓
Improvement
      ↺
```

***

# 94. Governance Decision Records

Material decisions should record:

* decision;
* decision date;
* authority;
* issue;
* risk;
* evidence;
* rationale;
* conditions;
* review date.

***

# 95. Governance Decision Traceability

```text theme={null}
Decision
   ↓
Authority
   ↓
Requirement
   ↓
Risk
   ↓
Evidence
   ↓
Rationale
   ↓
Outcome
```

***

# 96. Governance and Organizational Accountability

AIGO governance should integrate with existing organizational structures where practical.

It should avoid unnecessary duplication while ensuring AI-specific risks and responsibilities are adequately addressed.

***

# 97. Governance Committee Structure

Organizations may establish an AI governance committee or assign AI governance responsibilities to an existing governance body.

Possible responsibilities include:

* portfolio oversight;
* risk review;
* policy approval;
* exception review;
* system approval;
* assurance review;
* improvement oversight.

***

# 98. Governance Meeting Inputs

Governance meetings may consider:

* new AI systems;
* high-risk systems;
* significant incidents;
* emerging risks;
* exceptions;
* assurance findings;
* regulatory changes;
* performance trends;
* improvement opportunities.

***

# 99. Governance Meeting Outputs

Outputs may include:

* approvals;
* risk decisions;
* escalations;
* corrective actions;
* policy changes;
* control changes;
* resource decisions;
* monitoring requirements.

***

# 100. Governance Communication Records

Governance communications should be retained where they constitute evidence of material decisions or instructions.

Examples include:

* meeting minutes;
* decision records;
* formal approvals;
* risk notifications;
* governance directives.

***

# 101. Governance and Resource Allocation

Governance should consider whether sufficient resources exist to manage AI risks.

Where resources are insufficient, governance should determine whether to:

* increase resources;
* reduce scope;
* restrict use;
* delay deployment;
* discontinue the system.

***

# 102. Governance and Portfolio Management

Where an organization operates multiple AI systems, governance should consider the portfolio.

Portfolio governance may examine:

* aggregate risk;
* shared dependencies;
* concentration risk;
* common controls;
* common providers;
* common incidents;
* resource requirements.

***

# 103. AI Portfolio Governance

```text theme={null}
AI System 1 ─┐
AI System 2 ─┤
AI System 3 ─┼──→ AI Portfolio
AI System 4 ─┤
AI System 5 ─┘
                 ↓
          Aggregate Risk
                 ↓
           Governance
                 ↓
          Portfolio Decision
```

***

# 104. Governance of Shared AI Services

Shared AI services should have defined:

* owner;
* risk profile;
* controls;
* service boundaries;
* users;
* monitoring;
* escalation mechanisms.

***

# 105. Governance and AI Inventory

The AI inventory provides governance visibility.

It should support identification of:

* active systems;
* systems under development;
* retired systems;
* owners;
* classifications;
* risk levels;
* approval status.

***

# 106. Governance Inventory Review

The AI inventory should be periodically reconciled against actual AI use.

This helps identify:

* unauthorized systems;
* shadow AI;
* outdated records;
* missing owners;
* missing risk assessments.

***

# 107. Governance of Shadow AI

Unauthorized or unmanaged AI use should be treated as a governance concern.

Responses may include:

* awareness;
* registration;
* risk assessment;
* restrictions;
* technical controls;
* policy enforcement.

***

# 108. Governance and Responsible AI

Responsible AI expectations should be translated into:

* governance principles;
* risk criteria;
* controls;
* procedures;
* monitoring;
* evidence.

***

# 109. Governance and Ethical Considerations

Where ethical considerations are material, governance should provide mechanisms for:

* identification;
* assessment;
* stakeholder input;
* escalation;
* decision-making;
* documentation.

***

# 110. Governance and Societal Impact

Where AI systems may create broader societal effects, governance should consider:

* affected communities;
* public trust;
* social impacts;
* systemic risks;
* unintended consequences.

***

# 111. Governance and Fundamental Rights

Where applicable, governance should consider impacts on:

* rights;
* freedoms;
* dignity;
* equality;
* privacy;
* access.

Applicable legal requirements should guide detailed treatment.

***

# 112. Governance and Sustainability

Where material, governance may consider:

* environmental impacts;
* resource consumption;
* energy use;
* infrastructure impacts.

Sustainability considerations should be integrated according to organizational context.

***

# 113. Governance and Model Lifecycle

Governance should remain applicable throughout:

```text theme={null}
Model Development
      ↓
Validation
      ↓
Approval
      ↓
Deployment
      ↓
Operation
      ↓
Monitoring
      ↓
Change
      ↓
Retirement
```

***

# 114. Governance and Data Lifecycle

AI governance should also consider:

* data acquisition;
* preparation;
* use;
* storage;
* sharing;
* retention;
* deletion.

***

# 115. Governance and Documentation Quality

Governance documentation should support:

* traceability;
* reproducibility where applicable;
* accountability;
* review;
* assurance.

Documentation quality should be proportionate to risk.

***

# 116. Governance and Record Integrity

Governance records should protect against:

* unauthorized alteration;
* loss;
* ambiguity;
* incomplete history.

Appropriate version control and access controls should be applied.

***

# 117. Governance and Access Control

Access to governance information should follow:

* least privilege;
* role-based access;
* confidentiality requirements;
* legal requirements.

***

# 118. Governance and Security

AI governance should integrate cybersecurity governance.

Security should be addressed throughout the AI lifecycle and risk-management process.

***

# 119. Governance and Privacy

Privacy governance should integrate with AI governance where personal data is involved.

Responsibilities should be clearly assigned.

***

# 120. Governance and Compliance Monitoring

Compliance monitoring should identify:

* new requirements;
* non-compliance;
* control weaknesses;
* overdue actions;
* regulatory developments.

***

# 121. Governance and Assurance Reporting

Assurance results should be communicated to the appropriate governance authority.

Material findings should receive timely attention.

***

# 122. Governance and Internal Audit

Where applicable, internal audit may provide independent assurance over:

* governance design;
* governance effectiveness;
* risk management;
* controls;
* compliance.

Internal audit responsibilities should remain consistent with the organization's audit mandate.

***

# 123. Governance and External Assurance

External assurance may be used where appropriate.

Examples include:

* certification assessment;
* independent assessment;
* specialist review;
* regulatory examination.

***

# 124. Governance Improvement Prioritization

Improvement opportunities should be prioritized according to:

* risk;
* impact;
* urgency;
* regulatory significance;
* resource requirements.

***

# 125. Governance Improvement Model

```text theme={null}
Finding / Opportunity
       ↓
Prioritization
       ↓
Action
       ↓
Implementation
       ↓
Verification
       ↓
Effectiveness
       ↓
Governance Baseline Update
```

***

# 126. NIST GOVERN Integration Summary

The NIST GOVERN Function is mapped to the AIGO governance architecture through:

* governance authority;
* accountability;
* roles;
* policies;
* risk governance;
* stakeholder governance;
* lifecycle governance;
* control governance;
* evidence;
* assurance;
* continual improvement.

***

# 127. End-to-End Governance Traceability

```text theme={null}
NIST AI RMF
      ↓
GOVERN
      ↓
AIGO Governance
      ↓
Governance Requirement
      ↓
Accountable Role
      ↓
Risk / Control
      ↓
Procedure
      ↓
Evidence
      ↓
Decision
      ↓
Assurance
      ↓
Improvement
```

***

# 128. Governance Mapping Summary

| NIST AI RMF Governance Area | AIGO Governance Response             |
| --------------------------- | ------------------------------------ |
| GOVERN                      | AIGO Governance Architecture         |
| Accountability              | Governance Roles                     |
| Risk Governance             | AIGO Risk Management                 |
| Policies                    | Governance Documentation             |
| Stakeholders                | Stakeholder Governance               |
| Context                     | Organizational and AI System Context |
| Oversight                   | Monitoring and Assurance             |
| Decisions                   | Approval and Risk Acceptance         |
| Controls                    | AIGO Control Framework               |
| Evidence                    | Evidence Architecture                |
| Improvement                 | Continual Improvement                |

***

# 129. Mapping Limitations

This document:

* does not reproduce the NIST AI RMF;
* does not constitute NIST certification;
* does not constitute NIST endorsement;
* does not constitute legal advice;
* does not by itself establish regulatory compliance;
* does not replace organization-specific governance requirements;
* does not replace technical or legal assessment.

The mapping provides a structured governance traceability model.

***

# 130. Maintenance Requirements

This document should be reviewed when:

* NIST AI RMF changes;
* AIGO governance architecture changes;
* AIGO roles change;
* AIGO policies change;
* risk governance changes;
* control architecture changes;
* material regulatory requirements change;
* governance gaps are identified;
* organizational context materially changes.

***

# 131. Document Change Record

| Version | Date | Change                                 | Author | Reviewer | Approval |
| ------- | ---- | -------------------------------------- | ------ | -------- | -------- |
| 0.1     |      | Initial NIST AI RMF Governance Mapping |        |          |          |

***

# 132. Document Control

## 132.1 Controlled Information

| Field               | Value                                  |
| ------------------- | -------------------------------------- |
| Document Title      | AIGO — NIST AI RMF Governance Mapping  |
| Document ID         | `AIGO-MAP-NIST-AIRMF-006`              |
| Version             | 0.1                                    |
| Status              | Draft                                  |
| Framework           | AIGO AI Governance Operating Framework |
| Mapping Standard    | NIST AI RMF 1.0                        |
| Mapping Domain      | Governance                             |
| Primary Owner       |                                        |
| Technical Reviewer  |                                        |
| Governance Reviewer |                                        |
| Approver            |                                        |
| Effective Date      |                                        |
| Next Review Date    |                                        |

***

# 133. Final Control Statement

This document establishes the governance relationship between the NIST AI Risk Management Framework and the AIGO AI Governance Operating Framework.

It provides traceability between NIST AI RMF governance concepts and AIGO mechanisms for:

* governance authority;
* accountability;
* roles and responsibilities;
* policies;
* organizational context;
* stakeholder engagement;
* AI system governance;
* risk governance;
* decision-making;
* oversight;
* controls;
* evidence;
* assurance;
* continual improvement.

This document should be maintained as a controlled living document and updated whenever the underlying NIST framework, AIGO governance architecture, organizational context, policies, roles, controls or applicable requirements materially change.

***

# 134. End of Mapping Document

**AIGO — NIST AI RMF Governance Mapping**

**Document ID:** `AIGO-MAP-NIST-AIRMF-006`

**Version:** 0.1

**Status:** Draft

**Mapping Standard:** NIST AI RMF 1.0

**Mapping Type:** Governance Mapping

**End of Document**
