Home / Framework
The AIGSB Accountability Framework
Six domains, one continuous lifecycle and a maturity model any organization can use to see where it stands.
The lifecycle
Accountability is continuous, not a one-time review
AI estates change weekly: new agents are built, people change roles, models are swapped, spend shifts. The framework treats accountability as a loop that runs all the time.
- Discover every AI system, agent, model connection and user.
- Assign a named, accountable owner and a stated purpose.
- Measure usage, cost and data exposure.
- Control access, privileges and dangerous capability.
- Evidence that each control works, labeled by strength.
- Review on a set cadence and on change.
Domains and control objectives
What each domain asks you to prove
| Domain | Control objective | Typical evidence |
|---|---|---|
| AIGS 100 Accountable Ownership | Every AI system and agent has a named, current, human owner and a stated purpose. | Inventory with owner of record; leaver reassignment log; owner attestations. |
| AIGS 200 Cost and Token Accountability | AI consumption is attributed to an owner, purpose and budget, with alerts before overruns. | Spend by owner and system; budget thresholds; exception reviews. |
| AIGS 300 Usage and Access | The organization knows who uses which AI, and whether that use is sanctioned. | Sanctioned AI list; usage telemetry; unsanctioned-use findings and actions. |
| AIGS 400 Data Protection | Personal and confidential data reaches AI only where classified, permitted and logged. | Data classification coverage; permitted-use register; data-loss events. |
| AIGS 500 Agent and Tool Security | Agents act with least privilege and dangerous capability combinations are found and treated. | Agent permission reviews; capability-combination findings; tool allow-lists. |
| AIGS 600 Evidence and Assurance | Every governance claim is backed by evidence labeled by strength, and reported to leadership. | Evidence register; strength labels; board reporting pack. |
Maturity model
Five levels of AI accountability
Use the model to set a target and report progress. Level 3 is the practical baseline for regulated organizations.
Alignment
How the framework relates to existing references
AIGS standards are designed to sit alongside established frameworks and regulations, turning their principles into specific, testable accountability requirements. The relationships below are informative, not a substitute for legal advice.
| Reference | Relationship to the AIGS series |
|---|---|
| NIST AI Risk Management Framework (Govern, Map, Measure, Manage) | AIGS 100 and 600 support Govern; AIGS 300 and 400 support Map; AIGS 200 and 300 support Measure; AIGS 500 supports Manage. |
| ISO/IEC 42001 AI management system | AIGS standards supply operational control detail and evidence for an AI management system. |
| EU AI Act deployer obligations | Ownership, logging, human oversight and data governance evidence from AIGS 100, 300, 400 and 600 support deployer record keeping. |
| NYDFS 23 NYCRR Part 500 | The AI inventory, ownership and access evidence supports risk assessment (500.9), access privileges (500.7), third-party service providers (500.11) and asset inventory (500.13). |