AIGO — Management Review Schema Documentation
1. Document Purpose
This document describes the machine-readable AIGO Management Review Schema. The schema provides the structured representation of management reviews of AI governance arrangements under the AIGO AI Governance Operating Framework. It is intended to support:- management review planning;
- review scope and objectives;
- review participants and authority;
- review inputs;
- AI portfolio review;
- governance performance;
- risk performance;
- control performance;
- monitoring performance;
- incident trends;
- change activity;
- classification performance;
- approval performance;
- human oversight;
- security and privacy;
- fairness and impact;
- assurance results;
- third-party performance;
- regulatory developments;
- governance exceptions;
- resources and competence;
- documentation and evidence;
- stakeholder feedback;
- governance maturity;
- continual improvement;
- management decisions;
- governance changes;
- action plans;
- follow-up;
- conclusions;
- approval;
- closure; and
- review scheduling.
2. Schema Information
3. Scope
The Management Review Schema applies to formal reviews of the suitability, adequacy, effectiveness, performance, and continuing improvement of AI governance arrangements. A management review may cover:- the organization’s AI portfolio;
- governance arrangements;
- strategic alignment;
- risk profile;
- control performance;
- monitoring;
- incidents;
- changes;
- assurance;
- approvals;
- human oversight;
- security;
- privacy;
- fairness;
- suppliers;
- regulatory developments;
- resources;
- competence;
- evidence;
- governance maturity; and
- continual improvement.
4. Object Model
The primary object represented by this schema is:- individual risk records;
- control assessments;
- monitoring records;
- incident records;
- assurance engagements;
- improvement records;
- approval records; and
- operational governance records.
5. Core Identity
A Management Review record should contain stable identity information. Key fields include:id;objectType;objectVersion;schemaVersion;- review type;
- review scope;
- review objectives;
- review inputs;
- review owner;
- review authority; and
- status.
6. Purpose of Management Review
Management review exists to provide management with a structured opportunity to evaluate whether AI governance remains:- suitable;
- adequate;
- effective;
- aligned with organizational objectives;
- proportionate to AI risks; and
- capable of continual improvement.
7. Review Types
A management review may be:- serious incident;
- material change;
- regulatory development;
- significant assurance finding;
- major change in AI portfolio;
- risk exceeding tolerance;
- governance failure; or
- another defined governance trigger.
8. Review Owner
The review should have an accountable owner responsible for coordinating:- scope;
- agenda;
- participants;
- inputs;
- analysis;
- decisions;
- actions;
- records;
- follow-up; and
- closure.
9. Review Chair
The chair should have sufficient authority to:- conduct the review;
- challenge information;
- request clarification;
- facilitate decisions;
- identify escalation;
- confirm conclusions; and
- ensure actions are assigned.
10. Review Authority
The review authority identifies the governance body or management authority responsible for the review. It may include:- executive management;
- AI governance committee;
- risk committee;
- board committee;
- business-unit leadership;
- delegated governance authority; or
- another authorized body.
11. Review Scope
The review scope should identify:- organizational units;
- business functions;
- jurisdictions;
- AI systems;
- lifecycle stages;
- environments;
- governance domains;
- review period; and
- exclusions.
12. Review Objectives
Review objectives may include:- assess governance effectiveness;
- evaluate AI risk profile;
- review control performance;
- review incidents;
- review monitoring;
- review assurance findings;
- confirm strategic alignment;
- evaluate resource adequacy;
- assess regulatory readiness;
- review governance maturity;
- identify improvement opportunities; and
- make governance decisions.
13. Review Participants
Participants may include:- AI governance owner;
- executive management;
- AI system owners;
- risk owners;
- control owners;
- security;
- privacy;
- legal;
- compliance;
- technical leadership;
- business representatives;
- assurance representatives; and
- other subject-matter experts.
14. Quorum
Where the governing body requires a quorum, the management review record should capture:- quorum requirement;
- minimum participants;
- actual participants;
- whether quorum was achieved; and
- rationale for exceptions.
15. Review Period
The record should identify the period being reviewed. For example:16. Review Inputs
Management review should be evidence-based. Inputs may include:- governance performance;
- AI inventory;
- risk profile;
- control assessments;
- monitoring;
- incidents;
- changes;
- assurance;
- stakeholder feedback;
- regulatory developments;
- accepted risks;
- exceptions;
- resources;
- competence;
- maturity assessments;
- improvement activity; and
- previous management review actions.
17. AI Portfolio Review
Management review may evaluate the AI portfolio as a whole. Portfolio information may include:- total AI systems;
- new systems;
- retired systems;
- restricted systems;
- suspended systems;
- classification distribution;
- risk distribution;
- system trends; and
- significant portfolio changes.
18. Strategic Alignment
Management should assess whether AI governance remains aligned with organizational strategy. Strategic alignment may consider:- organizational objectives;
- AI strategy;
- business priorities;
- risk appetite;
- stakeholder expectations;
- technology strategy;
- regulatory strategy; and
- sustainability objectives where applicable.
19. Organizational Context
Management review should consider significant changes in organizational context. Examples include:- organizational restructuring;
- new business activities;
- new jurisdictions;
- acquisitions;
- divestments;
- changes in AI strategy;
- technology changes;
- supplier changes;
- stakeholder changes;
- risk-environment changes; and
- regulatory developments.
20. Governance Performance
Management review should consider whether governance objectives are being achieved. Performance information may include:- governance metrics;
- decision timeliness;
- governance coverage;
- approval performance;
- control effectiveness;
- risk treatment;
- incident trends;
- assurance findings; and
- improvement completion.
21. Risk Performance
Management review should evaluate the current AI risk profile. This may include:- overall risk level;
- distribution by risk category;
- highest risks;
- risks above tolerance;
- emerging risks;
- systemic risks;
- accepted risks;
- overdue treatments; and
- changes since the previous review.
22. Risk Acceptance Review
Management may review accepted risks. The review may identify:- current accepted risks;
- expiring risk acceptances;
- changed residual risk;
- conditions;
- acceptance authority;
- monitoring requirements; and
- whether acceptance should continue.
23. Control Performance
Management review should consider whether key controls are:- designed appropriately;
- implemented;
- operating effectively;
- supported by evidence;
- monitored;
- independently assessed; and
- appropriately remediated when deficient.
24. Monitoring Performance
Management should review monitoring results. This may include:- indicator performance;
- threshold breaches;
- monitoring coverage;
- significant deviations;
- enhanced monitoring;
- monitoring gaps;
- false alerts;
- monitoring failures; and
- monitoring effectiveness.
25. Incident Performance
Management review should examine incident activity. Information may include:- incidents by severity;
- open and closed incidents;
- significant incidents;
- incident trends;
- repeat incidents;
- root causes;
- control failures;
- lessons learned; and
- outstanding remediation.
26. Change Performance
The review should consider AI-related change activity. This may include:- number of changes;
- material changes;
- emergency changes;
- failed changes;
- rolled-back changes;
- change-related incidents;
- overdue changes; and
- post-change issues.
27. Classification Performance
Management may review whether AI system classifications remain appropriate. Indicators may include:- number of reclassifications;
- classification disputes;
- classification-related findings;
- changes in risk or intended purpose; and
- regulatory developments.
28. Approval Performance
Management review may consider:- approvals completed;
- approval delays;
- conditional approvals;
- rejected decisions;
- deferred decisions;
- overdue approval conditions;
- emergency approvals; and
- revoked or expired approvals.
29. Human Oversight Performance
Management should consider whether human oversight remains effective. Review may include:- oversight indicators;
- review completion;
- intervention rates;
- override rates;
- escalation;
- competence;
- workload;
- automation bias; and
- oversight-related findings or incidents.
30. Security and Privacy Performance
Management review should consider significant:- security events;
- privacy events;
- vulnerability trends;
- unauthorized access;
- data incidents;
- privacy findings;
- control weaknesses; and
- outstanding remediation.
31. Fairness and Impact Performance
Where fairness or impact is relevant, management may review:- fairness indicators;
- impact assessments;
- affected-person feedback;
- complaints;
- differential outcomes;
- mitigation effectiveness; and
- unresolved fairness findings.
32. Assurance Performance
Management review should consider assurance activity and findings. This may include:- assurance completed;
- outstanding findings;
- repeat findings;
- high-severity findings;
- overdue remediation;
- assurance coverage;
- independence; and
- conclusion trends.
33. Third-Party Performance
Where AI systems depend on external providers, management may review:- supplier risk;
- assurance status;
- incidents;
- changes;
- service performance;
- contractual issues;
- regulatory issues;
- concentration risk; and
- termination readiness.
34. Regulatory Performance
Management review should consider changes in:- laws;
- regulations;
- standards;
- contractual obligations;
- regulatory guidance;
- enforcement trends; and
- external commitments.
35. Governance Exceptions
Management should review open governance exceptions. The review may consider:- exception age;
- risk;
- compensating controls;
- expiry;
- repeated exceptions;
- exception trends; and
- whether the underlying requirement should change.
36. Resources and Capability
Management review should assess whether governance has sufficient:- personnel;
- competence;
- technology;
- funding;
- specialist expertise;
- external support; and
- operational capacity.
37. Competence and Training
Management may review:- required competencies;
- training completion;
- specialist skills;
- role readiness;
- competence gaps;
- emerging capability requirements; and
- training effectiveness.
38. Documentation and Evidence
Management review should determine whether governance documentation and evidence remain adequate. This may include:- documentation completeness;
- evidence quality;
- evidence gaps;
- record retention;
- traceability;
- document control; and
- access controls.
39. Stakeholder Feedback
Management should consider relevant stakeholder feedback. Potential sources include:- users;
- affected persons;
- customers;
- employees;
- suppliers;
- regulators;
- assurance providers;
- complaints;
- surveys; and
- governance forums.
40. Governance Maturity
Management review may consider current governance maturity. The review may identify:- maturity level;
- strengths;
- weaknesses;
- gaps;
- target maturity;
- capability priorities; and
- improvement needs.
41. Continual Improvement
Management review is a major source of continual-improvement opportunities. Sources may include:- incidents;
- monitoring;
- assurance;
- audits;
- assessments;
- stakeholder feedback;
- technology change;
- regulatory developments;
- repeat findings; and
- maturity assessments.
42. Management Analysis
Management should analyze the information rather than merely compile it. Analysis may identify:- strengths;
- weaknesses;
- emerging issues;
- emerging opportunities;
- material changes;
- systemic patterns;
- recurring failures;
- governance bottlenecks; and
- strategic implications.
43. Management Decisions
The Management Review record may capture decisions such as:- decision;
- rationale;
- owner;
- due date;
- evidence; and
- status where applicable.
44. Overall Management Decision
The review may produce an overall management conclusion. Possible outcomes include:45. Management Review Conclusion
The review may evaluate:Suitability
Whether the governance arrangement remains appropriate for its intended purpose.Adequacy
Whether sufficient structures, resources, controls, and processes exist.Effectiveness
Whether governance is achieving intended outcomes. The conclusion should identify the rationale for each conclusion where practical.46. Governance Changes
Management review may result in governance changes. Examples include:- policy change;
- role change;
- authority change;
- committee change;
- process change;
- control change;
- risk methodology change;
- monitoring change;
- assurance change;
- lifecycle change;
- documentation change; or
- resource change.
47. Action Plan
Management review actions should identify:- action;
- owner;
- priority;
- target date;
- source;
- status;
- dependencies; and
- completion evidence.
- corrective action;
- improvement;
- risk treatment;
- governance change;
- resource allocation;
- assurance;
- monitoring enhancement; or
- policy revision.
48. Action Status
Action statuses may include:49. Follow-Up
Management review should define follow-up where decisions or actions remain open. Follow-up should identify:- owner;
- review date;
- action references;
- verification evidence;
- closure criteria; and
- status.
50. Management Review Approval
Where the review requires formal approval, the record should identify:- approval requirement;
- approving authority;
- decision;
- date;
- conditions; and
- supporting evidence.
51. Management Review Closure
The review may be closed when:- the review was completed;
- conclusions were documented;
- decisions were issued;
- actions were assigned;
- required approvals were obtained; and
- records were retained.
52. Reopening a Management Review
A completed review may need to be reopened where:- material new information emerges;
- a major decision changes;
- significant governance failure occurs;
- the original review omitted material information;
- assurance identifies a material deficiency; or
- an external requirement requires reconsideration.
53. Review Inputs and Evidence
Material management decisions should be traceable to:- source records;
- evidence;
- metrics;
- assessments;
- assurance;
- incidents;
- monitoring;
- stakeholder feedback; and
- other relevant information.
54. Management Review and Risk
Management review should connect governance decisions to risk. For example:55. Management Review and Controls
Management may determine that controls should:- continue;
- be strengthened;
- be redesigned;
- be monitored more closely;
- undergo assurance;
- be replaced; or
- be retired.
56. Management Review and Monitoring
Management may decide to:- increase monitoring;
- change indicators;
- revise thresholds;
- establish enhanced monitoring;
- retire ineffective monitoring; or
- establish new monitoring for emerging risks.
57. Management Review and Assurance
Management may commission assurance when:- confidence is insufficient;
- repeated findings occur;
- governance effectiveness is uncertain;
- a high-risk decision is required;
- major change is planned; or
- a significant incident has occurred.
58. Management Review and Improvement
Management review is a principal source of improvement priorities. The relationship may be:59. Management Review and Retirement
Management review may determine that an AI system should be:- continued;
- restricted;
- suspended;
- replaced; or
- retired.
60. Management Review Reporting
Management review records may support executive and governance reporting. Useful metrics include:61. Review Frequency
Management review frequency should be defined by the governance arrangement. Possible schedules include:- monthly;
- quarterly;
- semi-annual;
- annual; or
- event-triggered.
- AI portfolio complexity;
- risk;
- regulatory expectations;
- incident history;
- governance maturity; and
- rate of change.
62. Triggered Reviews
A triggered management review may be required after:- serious incident;
- significant regulatory change;
- material governance failure;
- major AI system change;
- substantial portfolio expansion;
- material risk exceeding tolerance;
- major assurance finding;
- significant supplier failure; or
- other governance-defined conditions.
63. Previous Review Follow-Up
Each management review should consider the status of actions from previous reviews. The review should identify:- completed actions;
- overdue actions;
- blocked actions;
- repeated actions;
- ineffective actions; and
- actions requiring escalation.
64. Management Review Validation Requirements
A valid Management Review record should satisfy:Structural Validation
The JSON document must validate against:11-AIGO-Management-Review-Schema-v0.1.json
Scope Validation
The review scope should be defined.Objective Validation
Review objectives should be documented.Input Validation
Material review inputs should be identified.Authority Validation
The review should be conducted by an authorized management body.Participant Validation
Required participants or quorum should be addressed.Evidence Validation
Material conclusions should be supported by relevant evidence and source records.Decision Validation
Material decisions should identify authority, rationale, owner, and action where required.Action Validation
Actions should have accountable owners and target dates.Follow-Up Validation
Required follow-up should be assigned and tracked.Closure Validation
Closure should satisfy governance requirements.Traceability Validation
The review should remain traceable to the underlying AI systems, risks, controls, assessments, approvals, monitoring, incidents, changes, assurance, evidence, improvements, and retirement records as applicable.65. Schema Limitations
JSON Schema cannot independently determine:- whether management considered all relevant information;
- whether management conclusions are reasonable;
- whether participants have sufficient authority;
- whether evidence is sufficient;
- whether strategic alignment is adequate;
- whether resources are sufficient;
- whether governance is effective; or
- whether management decisions are appropriate.
66. Relationship to Templates
The Management Review Schema corresponds primarily to:guidance/03-templates/13-AIGO-AI-Management-Review-Template-v0.1.md
It may also use information generated by:
- AI system templates;
- risk assessment;
- control assessment;
- approval;
- monitoring;
- incident;
- change management;
- assurance;
- evidence;
- improvement; and
- retirement records.
67. Relationship to Procedures
The schema should be used with the AIGO management-review process and applicable governance procedures. The management-review process should define:- review frequency;
- inputs;
- participants;
- authority;
- decision rights;
- outputs;
- action management;
- follow-up; and
- closure.
68. Framework Traceability
69. Management Review Traceability Model
The recommended traceability chain is:70. Example Record
A conceptual Management Review record may look like:71. Schema Registry Relationship
This schema is registered in:schemas/00-AIGO-Schema-Registry-v0.1.json
The registry should maintain:
- schema identifier;
- object type;
- version;
- controlled path;
- status;
- dependencies;
- referenced schemas;
- owner;
- documentation path; and
- traceability metadata.
72. Change and Version Management
Changes to the Management Review Schema should be managed through AIGO change management. Potential impacts should be assessed against:- management review processes;
- governance committees;
- review templates;
- risk reporting;
- control reporting;
- monitoring;
- incident reporting;
- assurance reporting;
- improvement management;
- evidence;
- executive reporting;
- external mappings; and
- validation tooling.
73. Future Extensions
Future versions may support:- board-level review profiles;
- automated governance dashboards;
- portfolio trend structures;
- management decision workflows;
- quorum enforcement;
- voting or committee decision structures;
- integrated KPI and KRI models;
- automated follow-up;
- governance maturity analytics;
- cross-framework management reporting; and
- machine-readable strategic objectives.
74. Document Control
75. Document Status
Document: AIGO — Management Review Schema Documentation Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-SCHEMA-DOC-011
Document Type: Schema Documentation
This document provides the human-readable interpretation, governance context, validation expectations, and traceability guidance for the AIGO Management Review Schema.
End of Document