Skip to main content

AIGO — NIST AI RMF Implementation Mapping

AIGO — AI Governance Operating Framework

Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier: AIGO-MAP-NIST-AIRMF-008 Mapping Standard: NIST AI RMF 1.0 Mapping Type: Implementation Mapping

1. Purpose

This document defines how the AIGO AI Governance Operating Framework can be implemented in alignment with the NIST AI Risk Management Framework (AI RMF). The purpose of this mapping is to translate the conceptual relationship between NIST AI RMF and AIGO into an operational implementation structure. The mapping connects:
  • NIST AI RMF Functions;
  • NIST Categories and Subcategories;
  • AIGO governance requirements;
  • AIGO lifecycle activities;
  • AIGO controls;
  • AIGO procedures;
  • AIGO roles;
  • implementation activities;
  • evidence;
  • assurance;
  • continual improvement.

2. Implementation Objectives

The objectives of this mapping are to:
  1. provide an implementation path from NIST AI RMF concepts to AIGO practices;
  2. establish an operational relationship between governance and implementation;
  3. support organizations implementing AIGO with NIST AI RMF alignment;
  4. connect governance requirements to executable activities;
  5. identify implementation responsibilities;
  6. establish implementation evidence;
  7. support assessment and assurance;
  8. support risk-based prioritization;
  9. support phased implementation;
  10. support continual improvement.

3. Implementation Philosophy

AIGO implementation should be risk-based, lifecycle-oriented, proportionate, and evidence-driven.
Implementation should not be treated as a one-time compliance exercise.

4. NIST AI RMF Implementation Structure

The NIST AI RMF implementation relationship is organized around:
  • GOVERN;
  • MAP;
  • MEASURE;
  • MANAGE.
These Functions are implemented through AIGO governance, lifecycle, risk, controls, procedures, monitoring, assurance, and improvement.

5. AIGO Implementation Architecture

The AIGO lifecycle provides the operational structure through which NIST AI RMF activities can be implemented.

6. Implementation Layers

AIGO implementation can be understood through the following layers:

7. Implementation Prerequisites

Before implementing AIGO, an organization should establish:
  • governance sponsorship;
  • organizational scope;
  • AI-system scope;
  • accountable roles;
  • governance authority;
  • risk-management approach;
  • documentation structure;
  • evidence repository;
  • implementation roadmap.

8. Implementation Scope

Implementation scope should identify:
  • organizational units;
  • AI systems;
  • AI use cases;
  • lifecycle stages;
  • third parties;
  • relevant processes;
  • applicable regulations;
  • applicable standards;
  • governance boundaries.

9. Implementation Governance

Implementation should have an accountable governance structure.

10. Implementation Roles


11. Implementation Workstreams

AIGO implementation can be organized into workstreams:
  1. Governance;
  2. AI inventory;
  3. lifecycle;
  4. risk management;
  5. control implementation;
  6. procedures;
  7. evidence;
  8. monitoring;
  9. assurance;
  10. continual improvement.

12. Implementation Roadmap


13. Phase 1 — Initiate

The organization establishes the implementation program. Activities include:
  • appoint sponsor;
  • define implementation owner;
  • establish governance;
  • define objectives;
  • approve implementation approach.

14. Phase 2 — Scope

The organization determines the boundaries of the implementation. Scope should consider:
  • AI portfolio;
  • business units;
  • AI lifecycle;
  • technology;
  • third parties;
  • jurisdictions;
  • risk exposure.

15. Phase 3 — Current-State Assessment

The organization assesses existing capabilities. Assessment areas may include:
  • governance;
  • policies;
  • AI inventory;
  • risk management;
  • controls;
  • lifecycle;
  • monitoring;
  • assurance;
  • evidence.

16. Current-State Assessment Model


17. Phase 4 — Target-State Design

The target state defines how AIGO should operate within the organization. The target state should establish:
  • governance structure;
  • lifecycle;
  • controls;
  • procedures;
  • roles;
  • evidence;
  • monitoring;
  • assurance.

18. Phase 5 — Gap Analysis

Gap analysis should compare current capability against the desired AIGO operating model.

19. Phase 6 — Prioritization

Implementation priorities should consider:
  • risk;
  • legal requirements;
  • regulatory requirements;
  • business criticality;
  • AI-system impact;
  • control weakness;
  • resource requirements.

20. Implementation Priority Model


21. Phase 7 — Governance Implementation

Governance implementation establishes:
  • policy;
  • authority;
  • accountability;
  • roles;
  • decision rights;
  • escalation;
  • oversight.

22. GOVERN Implementation Mapping

The NIST GOVERN Function maps primarily to AIGO:
  • charter;
  • principles;
  • governance domains;
  • governance roles;
  • lifecycle governance;
  • controls;
  • procedures;
  • monitoring;
  • assurance;
  • continual improvement.

23. GOVERN Implementation Activities

Implementation activities include:
  1. establish AI governance authority;
  2. define AI governance policy;
  3. define accountability;
  4. establish risk governance;
  5. define decision rights;
  6. establish oversight;
  7. define documentation requirements;
  8. establish assurance mechanisms.

24. GOVERN Implementation Evidence

Evidence may include:
  • governance charter;
  • approved policies;
  • role assignments;
  • committee records;
  • governance decisions;
  • risk appetite;
  • management reviews.

25. Phase 8 — AI Inventory Implementation

The organization establishes and maintains an AI system inventory. Inventory records should identify:
  • system;
  • owner;
  • purpose;
  • status;
  • lifecycle stage;
  • classification;
  • risk;
  • controls.

26. MAP Implementation Mapping

The NIST MAP Function maps primarily to AIGO:
  • AI system profiles;
  • context identification;
  • classification;
  • stakeholder identification;
  • risk assessment;
  • impact assessment.

27. MAP Implementation Activities

Activities include:
  1. identify AI systems;
  2. identify intended purpose;
  3. identify stakeholders;
  4. identify operating context;
  5. identify dependencies;
  6. classify the system;
  7. identify risks;
  8. identify potential impacts.

28. MAP Implementation Evidence

Evidence may include:
  • AI inventory;
  • AI system profile;
  • stakeholder analysis;
  • context assessment;
  • classification;
  • risk register.

29. Phase 9 — Risk Implementation

Risk management translates identified risks into prioritized actions.

30. Risk Implementation Activities

Activities include:
  • risk identification;
  • risk analysis;
  • risk evaluation;
  • treatment;
  • acceptance;
  • escalation;
  • monitoring.

31. MEASURE Implementation Mapping

The NIST MEASURE Function maps primarily to:
  • AIGO risk measurement;
  • control assessment;
  • monitoring;
  • testing;
  • validation;
  • assurance.

32. MEASURE Implementation Activities

Activities may include:
  1. define metrics;
  2. establish evaluation criteria;
  3. conduct testing;
  4. measure performance;
  5. assess risks;
  6. analyze results;
  7. document conclusions.

33. MEASURE Evidence

Evidence may include:
  • evaluation plans;
  • test records;
  • measurements;
  • validation reports;
  • monitoring outputs;
  • assessment results.

34. Phase 10 — Control Implementation

Controls translate governance requirements into operational mechanisms. Controls should define:
  • objective;
  • requirement;
  • owner;
  • frequency;
  • implementation;
  • evidence;
  • assessment.

35. Control Implementation Lifecycle


36. Phase 11 — Procedure Implementation

Procedures define how governance activities are performed consistently. AIGO procedures cover:
  • governance;
  • registration;
  • risk assessment;
  • classification;
  • control assessment;
  • approval;
  • change;
  • incident;
  • monitoring;
  • assurance;
  • risk acceptance;
  • retirement;
  • continual improvement.

37. Procedure Implementation Model


38. Phase 12 — Lifecycle Implementation

The AIGO lifecycle provides the operational backbone for AI governance.

39. Lifecycle Implementation Activities

Each AI system should be managed according to its applicable lifecycle stage. Implementation should define:
  • stage entry criteria;
  • stage activities;
  • required controls;
  • required evidence;
  • decision authority;
  • stage exit criteria.

40. Phase 13 — Evidence Implementation

Evidence implementation establishes how governance activities are demonstrated. Evidence should be:
  • attributable;
  • traceable;
  • protected;
  • current;
  • retrievable;
  • sufficient.

41. Evidence Implementation Model


42. Phase 14 — Monitoring Implementation

Monitoring should establish continuous or periodic observation of relevant AI governance and risk indicators. Potential monitoring areas include:
  • AI-system performance;
  • risk;
  • incidents;
  • controls;
  • compliance;
  • drift;
  • security;
  • privacy.

43. Monitoring Implementation Model


44. Phase 15 — MANAGE Implementation

The NIST MANAGE Function maps to AIGO risk treatment, decision-making, corrective action, and lifecycle intervention. Implementation activities include:
  • prioritize risk;
  • select treatment;
  • implement controls;
  • accept residual risk;
  • escalate;
  • suspend;
  • change;
  • continue;
  • retire.

45. MANAGE Implementation Evidence

Evidence may include:
  • risk treatment plans;
  • corrective actions;
  • risk acceptance;
  • escalation;
  • incident records;
  • change records;
  • suspension decisions;
  • retirement decisions.

46. Phase 16 — Assurance Implementation

Assurance evaluates whether AIGO implementation is operating as intended. Assurance may include:
  • control assessments;
  • internal reviews;
  • audits;
  • independent assessments;
  • technical validation;
  • management reviews.

47. Assurance Implementation Model


48. Phase 17 — Continual Improvement

Continual improvement should use:
  • findings;
  • incidents;
  • monitoring;
  • assessments;
  • audits;
  • stakeholder feedback;
  • changes in regulation;
  • changes in technology.

49. Improvement Implementation Model


50. NIST-to-AIGO Implementation Matrix


51. NIST GOVERN Implementation Matrix


52. NIST MAP Implementation Matrix


53. NIST MEASURE Implementation Matrix


54. NIST MANAGE Implementation Matrix


55. Implementation Dependency Model

AIGO implementation dependencies should generally follow:

56. Implementation Sequencing

Organizations should avoid implementing isolated controls without establishing the supporting governance architecture. For example:

57. Minimum Viable Implementation

An organization beginning AIGO implementation should establish, at minimum:
  • governance authority;
  • AI inventory;
  • AI system ownership;
  • classification;
  • risk assessment;
  • core controls;
  • approval process;
  • monitoring;
  • evidence;
  • assurance.

58. Risk-Based Implementation

Not every AI system requires identical implementation depth. Implementation should be proportionate to:
  • potential impact;
  • risk;
  • system criticality;
  • regulatory exposure;
  • organizational context;
  • lifecycle stage.

59. Implementation Tiering

AIGO implementation may use tiers such as:

60. Implementation of High-Risk AI Systems

Higher-risk systems should generally receive stronger implementation measures. These may include:
  • enhanced assessment;
  • additional controls;
  • stronger approval;
  • increased monitoring;
  • additional assurance;
  • stricter change management.

61. Implementation of Lower-Risk AI Systems

Lower-risk systems may use proportionate controls while still maintaining:
  • inventory;
  • ownership;
  • classification;
  • risk evaluation;
  • appropriate oversight.

62. Implementation and Third Parties

Third-party AI systems should be incorporated into AIGO governance according to organizational risk. Implementation should address:
  • supplier identification;
  • responsibilities;
  • contractual controls;
  • evidence;
  • monitoring;
  • change notification;
  • incident escalation.

63. Implementation and AI Supply Chain

Supply-chain implementation should identify relevant:
  • models;
  • data;
  • providers;
  • components;
  • services;
  • dependencies.

64. Implementation and Security

Security implementation should integrate relevant security governance into:
  • lifecycle;
  • risk assessment;
  • controls;
  • monitoring;
  • incident management.

65. Implementation and Privacy

Privacy implementation should integrate privacy considerations into:
  • context;
  • data governance;
  • risk;
  • controls;
  • monitoring;
  • incidents.

66. Implementation and Data Governance

Data governance implementation may include:
  • data ownership;
  • data classification;
  • data quality;
  • lineage;
  • access;
  • retention;
  • usage restrictions.

67. Implementation and Model Governance

Model governance implementation may include:
  • model identification;
  • version control;
  • validation;
  • approval;
  • performance monitoring;
  • change management.

68. Implementation and Human Oversight

Where human oversight is required, implementation should define:
  • oversight role;
  • decision authority;
  • intervention mechanism;
  • escalation;
  • evidence;
  • review.

69. Implementation and Transparency

Implementation should establish appropriate transparency mechanisms based on:
  • users;
  • stakeholders;
  • risk;
  • system context;
  • applicable requirements.

70. Implementation and Explainability

Where explainability is relevant, implementation should establish:
  • explanation objectives;
  • methods;
  • responsible roles;
  • testing;
  • limitations;
  • evidence.

71. Implementation and Monitoring

Monitoring implementation should define:
  • what is monitored;
  • why it is monitored;
  • who monitors it;
  • frequency;
  • thresholds;
  • escalation;
  • evidence.

72. Implementation and Incident Management

Incident implementation should establish:
  • detection;
  • classification;
  • escalation;
  • response;
  • investigation;
  • corrective action;
  • closure.

73. Implementation and Change Management

Change implementation should ensure that material changes are:
  • identified;
  • assessed;
  • risk-evaluated;
  • tested;
  • approved;
  • implemented;
  • monitored.

74. Implementation and Retirement

Retirement implementation should address:
  • decision authority;
  • shutdown;
  • data;
  • dependencies;
  • records;
  • residual risk;
  • lessons learned.

75. Implementation Evidence

Implementation evidence may include:
  • implementation plans;
  • gap assessments;
  • risk assessments;
  • control records;
  • procedures;
  • approvals;
  • training records;
  • monitoring;
  • assurance;
  • improvement records.

76. Implementation Readiness

Before operational deployment, implementation readiness should consider:

77. Implementation Validation

Implementation should be validated before being considered operational. Validation may assess:
  • design;
  • implementation;
  • operation;
  • evidence;
  • effectiveness.

78. Implementation Acceptance

Implementation acceptance should identify:
  • scope;
  • completed requirements;
  • outstanding gaps;
  • residual risk;
  • conditions;
  • approving authority.

79. Implementation Handover

Where implementation is delivered as a project, transition into operations should include:
  • ownership transfer;
  • documentation;
  • evidence;
  • monitoring;
  • support;
  • assurance;
  • open risks.

80. Implementation Training

Relevant personnel should receive training appropriate to their responsibilities. Training may cover:
  • AI governance;
  • risk;
  • controls;
  • procedures;
  • evidence;
  • escalation;
  • incident management.

81. Implementation Communications

Implementation should establish communication mechanisms for:
  • governance decisions;
  • policy changes;
  • risk changes;
  • incidents;
  • control changes;
  • regulatory changes.

82. Implementation Performance

Implementation performance should be measured using indicators such as:
  • implementation completion;
  • control coverage;
  • evidence coverage;
  • unresolved gaps;
  • overdue actions;
  • assurance findings;
  • training completion.

83. Implementation Dashboard


84. Implementation Gap Management

Implementation gaps should be recorded, prioritized, assigned, tracked, and closed. Each material gap should have:
  • identifier;
  • description;
  • risk;
  • owner;
  • action;
  • target;
  • status;
  • closure evidence.

85. Implementation Exception Management

Where implementation requirements cannot be completed as planned, an exception should be:
  • documented;
  • risk-assessed;
  • approved;
  • time-bounded;
  • monitored.

86. Implementation Risk Register

The implementation program should maintain an implementation risk register where appropriate.

87. Implementation Control Register

The implementation control register should identify:
  • control;
  • owner;
  • implementation status;
  • evidence;
  • assessment;
  • gaps;
  • corrective actions.

88. Implementation Evidence Register

The evidence register should identify:
  • evidence ID;
  • requirement;
  • source;
  • owner;
  • location;
  • status;
  • retention;
  • review.

89. Implementation Traceability


90. Implementation and Assurance Traceability

Assurance should be able to trace implementation from requirement through evidence.

91. Implementation Maturity

AIGO implementation maturity may be assessed through five levels.

92. Level 1 — Initial

Characteristics include:
  • informal governance;
  • incomplete inventory;
  • inconsistent risk management;
  • limited evidence;
  • reactive implementation.

93. Level 2 — Developing

Characteristics include:
  • defined responsibilities;
  • emerging procedures;
  • basic risk assessment;
  • initial controls;
  • developing evidence.

94. Level 3 — Defined

Characteristics include:
  • documented governance;
  • standardized lifecycle;
  • defined controls;
  • established procedures;
  • consistent evidence.

95. Level 4 — Managed

Characteristics include:
  • measurable implementation;
  • integrated monitoring;
  • regular assurance;
  • risk-based prioritization;
  • management oversight.

96. Level 5 — Optimized

Characteristics include:
  • continuous improvement;
  • automation;
  • predictive monitoring;
  • integrated evidence;
  • advanced assurance;
  • dynamic risk management.

97. Implementation Improvement Cycle


98. NIST AI RMF Implementation Operating Model

The AIGO implementation operating model can be represented as:

99. Implementation Integration Model

These components should operate as an integrated governance system rather than independent processes.

100. Implementation Control Gates

AIGO may use governance gates at critical lifecycle points. Examples include:
  • registration gate;
  • classification gate;
  • risk gate;
  • treatment gate;
  • approval gate;
  • deployment gate;
  • monitoring gate;
  • retirement gate.

101. Implementation Gate Model


102. Implementation Gate Evidence

Gate evidence may include:
  • completed assessment;
  • risk status;
  • control status;
  • required approvals;
  • exceptions;
  • decision record.

103. Implementation Nonconformity

Where implementation does not meet defined requirements, the issue should be:
  • documented;
  • assessed;
  • assigned;
  • corrected;
  • verified.

104. Implementation Corrective Action

Corrective actions should address:
  1. immediate correction;
  2. root cause;
  3. preventive action where appropriate;
  4. effectiveness verification.

105. Implementation Lessons Learned

Implementation lessons should be captured and used to improve:
  • governance;
  • controls;
  • procedures;
  • implementation methodology;
  • training;
  • evidence.

106. Implementation Knowledge Management

Organizations should maintain institutional knowledge related to AI governance implementation. Knowledge may include:
  • implementation decisions;
  • lessons learned;
  • recurring findings;
  • control effectiveness;
  • implementation patterns.

107. Implementation Dependencies

Implementation dependencies should be identified where one capability relies on another. For example:

108. Implementation Resource Planning

Implementation planning should consider:
  • personnel;
  • expertise;
  • technology;
  • budget;
  • time;
  • assurance resources;
  • training.

109. Implementation Technology

Technology may support:
  • AI inventory;
  • risk management;
  • control management;
  • evidence;
  • workflow;
  • monitoring;
  • assurance.
Technology should support the governance model rather than replace governance accountability.

110. Implementation Automation

Automation may be used for:
  • evidence collection;
  • control reminders;
  • monitoring;
  • workflow;
  • reporting;
  • risk indicators.
Automated decisions should remain subject to appropriate governance.

111. Implementation Reporting

Implementation reporting should provide management with visibility into:
  • progress;
  • risks;
  • gaps;
  • controls;
  • evidence;
  • assurance;
  • resources.

112. Implementation Review

Implementation should be periodically reviewed to determine whether:
  • objectives remain appropriate;
  • controls remain effective;
  • risks changed;
  • scope changed;
  • resources remain adequate;
  • implementation remains aligned.

113. Management Review of Implementation

Management review should consider:
  • implementation status;
  • significant risks;
  • major findings;
  • resource requirements;
  • control effectiveness;
  • changes in context;
  • improvement opportunities.

114. Implementation Change Control

Changes to the AIGO implementation model should be controlled. Changes may result from:
  • regulatory developments;
  • standards changes;
  • organizational changes;
  • technology changes;
  • incidents;
  • assurance findings;
  • lessons learned.

115. Implementation Continuity

The organization should maintain continuity of AI governance during:
  • organizational restructuring;
  • personnel changes;
  • technology transitions;
  • supplier changes;
  • major incidents.

116. Implementation Resilience

Implementation resilience requires that governance activities remain effective despite changes or disruptions.

117. Implementation Escalation

Material implementation problems should be escalated according to defined governance authority.

118. Implementation Closure

An implementation initiative should not be considered complete solely because documents have been produced. Completion should consider:
  • implementation;
  • operational adoption;
  • evidence;
  • training;
  • monitoring;
  • assurance;
  • residual gaps.

119. Operationalization

The transition from implementation to normal operations should establish:

120. NIST AI RMF Operational Alignment

AIGO operationalization supports the NIST AI RMF Functions through:

121. Implementation Audit Readiness

An implementation should be capable of demonstrating:
  • what was implemented;
  • why it was implemented;
  • who was responsible;
  • when it was implemented;
  • what evidence exists;
  • how effectiveness was assessed.

122. Implementation Assurance Readiness

Before declaring implementation mature, the organization should evaluate:
  • design adequacy;
  • implementation status;
  • operating effectiveness;
  • evidence quality;
  • unresolved risks.

123. Implementation Readiness Checklist

  • Governance authority established
  • Scope approved
  • AI inventory established
  • AI system owners assigned
  • Classification implemented
  • Risk assessment implemented
  • Controls implemented
  • Procedures established
  • Evidence established
  • Monitoring implemented
  • Assurance established
  • Continual improvement established

124. Implementation Completion Criteria

Implementation may be considered operational when:
  1. governance is established;
  2. required scope is covered;
  3. responsibilities are assigned;
  4. relevant AI systems are inventoried;
  5. risk processes operate;
  6. controls operate;
  7. procedures operate;
  8. evidence is generated;
  9. monitoring operates;
  10. assurance is established;
  11. improvement mechanisms operate.

125. Implementation Success Factors

Successful implementation depends on:
  • executive support;
  • clear accountability;
  • risk-based prioritization;
  • integration with existing processes;
  • practical procedures;
  • quality evidence;
  • effective communication;
  • continual improvement.

126. Common Implementation Failure Modes

Potential failure modes include:
  • documentation without implementation;
  • controls without owners;
  • risk assessments without treatment;
  • evidence without traceability;
  • governance without authority;
  • monitoring without escalation;
  • assurance without corrective action;
  • procedures disconnected from operations.

127. Implementation Failure Prevention

All components should be connected.

128. AIGO Implementation Operating Cycle

This represents the continuous operational relationship between AIGO lifecycle governance and NIST AI RMF risk-management concepts.

129. End-to-End Implementation Traceability


130. Implementation Control Model

AIGO implementation should establish a controlled relationship between requirements and operational execution.

131. Implementation Governance Model

The implementation governance model should maintain:
  • ownership;
  • authority;
  • accountability;
  • decision rights;
  • escalation;
  • evidence;
  • review.

132. Implementation Governance Chain


133. Implementation Review Cycle


134. Relationship to Other AIGO Mappings

This implementation mapping should be used together with:
  • AIGO NIST AI RMF Mapping;
  • AIGO NIST AI RMF Requirements Mapping;
  • AIGO NIST AI RMF Control Mapping;
  • AIGO NIST AI RMF Lifecycle Mapping;
  • AIGO NIST AI RMF Risk Mapping;
  • AIGO NIST AI RMF Governance Mapping;
  • AIGO NIST AI RMF Evidence Mapping.
Together, these documents provide a structured NIST-to-AIGO traceability architecture.

135. Relationship to AIGO Framework Documents

Implementation should reference the relevant AIGO framework components:
  • Charter;
  • Principles;
  • Governance Domains;
  • Governance Roles;
  • AI Governance Lifecycle;
  • AI Risk Management;
  • AI Governance Controls;
  • AI Governance Maturity;
  • AI System Profiles.

136. Relationship to AIGO Guidance

Implementation should be supported by:
  • Implementation Guide;
  • Governance Implementation;
  • AI System Implementation;
  • Risk Implementation;
  • Control Implementation;
  • Lifecycle Implementation;
  • Monitoring and Assurance Implementation;
  • Continuous Improvement.

137. Relationship to AIGO Procedures

Implementation should use applicable procedures for:
  • governance;
  • registration;
  • risk assessment;
  • classification;
  • control assessment;
  • approval;
  • change management;
  • incident management;
  • monitoring;
  • assurance;
  • risk acceptance;
  • retirement;
  • continual improvement.

138. Implementation Mapping Limitations

This mapping:
  • does not reproduce NIST AI RMF;
  • does not constitute NIST certification;
  • does not constitute NIST endorsement;
  • does not establish legal compliance;
  • does not replace organization-specific implementation decisions;
  • does not replace professional assurance;
  • does not prescribe a single implementation architecture.
It provides an AIGO implementation model aligned to NIST AI RMF concepts.

139. Maintenance Requirements

This document should be reviewed when:
  • NIST AI RMF changes;
  • AIGO implementation architecture changes;
  • AIGO controls change;
  • AIGO procedures change;
  • lifecycle requirements change;
  • governance requirements change;
  • applicable regulations change;
  • assurance findings identify implementation weaknesses;
  • organizational context materially changes.

140. Document Change Record


141. Document Control

141.1 Controlled Information


142. Final Control Statement

This document establishes the implementation-level relationship between the NIST AI Risk Management Framework and the AIGO AI Governance Operating Framework. It provides a structured approach for translating NIST AI RMF concepts into:
  • governance;
  • lifecycle activities;
  • risk management;
  • controls;
  • procedures;
  • evidence;
  • monitoring;
  • assurance;
  • continual improvement.
The implementation model is intended to be risk-based, proportionate, lifecycle-oriented, accountable, and evidence-driven. This document should be maintained as a controlled living document and updated whenever the underlying NIST framework, AIGO architecture, governance requirements, controls, procedures, lifecycle, implementation model, or organizational context materially changes.

143. End of Mapping Document

AIGO — NIST AI RMF Implementation Mapping Document ID: AIGO-MAP-NIST-AIRMF-008 Version: 0.1 Status: Draft Mapping Standard: NIST AI RMF 1.0 Mapping Type: Implementation Mapping End of Document