Skip to content

Methodology paper

AI Governance Rating Methodology: Scope, Evidence and Decision Governance

Methodology paper defining the rating lifecycle from scope and classification through assessment, challenge, rating action, monitoring, appeal and methodology governance.

ReferenceAIGR-M-2026-02
Versionv1.3
StatusPublished
ReviewedAugust 2026

Purpose

This publication sets out the institutional decision architecture for an AI Governance Rating. It defines the control points required to move from evidence collection to an issued categorical opinion while preserving scope integrity, analytical consistency, materiality and governance of judgment.

Rating lifecycle

Stage Institutional objective Primary record
1. Scope Fix the entity, system, use, lifecycle, jurisdiction and evidence period. Approved scope statement.
2. Classify Determine risk context, sector overlay and evidence expectations. Classification record.
3. Assess Evaluate controls, evidence states, deficiencies and material conditions. Assessment record.
4. Challenge Test material judgments, evidence sufficiency, conflicts and exceptions. Reviewer challenge record.
5. Rate Determine and approve the categorical rating action. Rating decision record.
6. Monitor Track validity, incidents and material change triggers. Monitoring and review record.

Separation of analytical score and rating designation

A detailed analytical score and a published rating designation serve different functions. The analytical layer supports diagnostics, domain comparison, sensitivity analysis and trend. The rating layer provides a stable categorical signal for executive and institutional use. A methodology should prevent direct interpretation of the rating designation as a percentage, probability or credit score.

The public AIGR™ methodology uses categorical designations from AIGR-100 through AIGR-40, with AIGR-NR for circumstances in which a rating cannot be supported. Conversion logic, thresholds and calibration rules may remain controlled where publication would materially increase gaming risk, provided the scale remains interpretable and methodology governance is documented.

Scope approval

Rating work should not begin with an undefined enterprise claim. The scope record should identify the precise rated object and the boundaries of excluded systems, functions or periods. Any material scope change during the assessment should be approved and recorded before a rating decision is made.

Assessment architecture

Assessment is performed across the applicable governance domains and criteria. Each criterion should record applicability, control state, evidence state, finding, severity where relevant, reviewer notes and remediation status. The methodology should distinguish a missing control from missing evidence, and both from a control that is present but operating ineffectively.

Materiality and gates

Not all deficiencies should have equal effect on the rating. Critical conditions can constrain the maximum available designation or require a rating to be withheld. Gate logic is appropriate where failure in a foundational control would make a higher designation analytically misleading regardless of strength in other domains.

Examples may include unresolved authority to deploy, material security failures, absence of required human oversight, integrity concerns affecting the evidence set, or unaddressed conditions that create significant exposure to affected parties. The exact gate structure should be governed by methodology version and scope.

Reviewer challenge

Material judgment should be subject to challenge before issuance. The challenge process should test at least the following:

  • whether the scope was applied consistently;
  • whether evidence supports the recorded control state;
  • whether severity and materiality were applied consistently;
  • whether exceptions and compensating controls were appropriately treated;
  • whether conflicts of interest were identified and managed;
  • whether any critical condition was overlooked or inappropriately offset.

The challenge record should preserve both the original analytical position and any resulting change.

Rating action

The rating action is the governed decision to issue, affirm, upgrade, downgrade, suspend, withdraw or not rate. The decision record should state the rating designation, effective date, methodology version, scope, rationale, material conditions and any limitations that materially affect interpretation.

The rating decision should be independent of commercial outcome. Fees, remediation opportunities or client preference should not determine the designation. Where independence cannot be maintained, the rating should be withheld or the engagement declined.

Monitoring and review triggers

Monitoring criteria should identify events that can make an existing rating materially stale. Triggers may include significant model changes, expanded use, changes in system permissions, material vendor changes, incidents, control failures, regulatory actions, acquisitions, changes in accountability or a significant deterioration in evidence continuity.

A trigger does not necessarily require an immediate rating change. It requires a governed determination of whether the existing opinion remains supported.

Appeal and correction

An appeal process should permit challenge based on factual error, omitted evidence, scope misstatement or misapplication of the methodology. Disagreement with the methodology itself is addressed through methodology governance rather than case-specific appeal. Corrections to factual records should be distinguishable from changes in analytical judgment.

Methodology governance

Each rating should identify the methodology version used. Material methodology revisions should have an effective date, change record and transition policy. Calibration should evaluate consistency across reviewers and cases. Archived versions should remain available internally so a historical decision can be reconstructed.

Research status and limitations

This publication describes institutional rating decision architecture. It does not disclose proprietary rating thresholds, weights or calibration logic and does not itself issue a rating.

Sources and research basis