GAO AI Accountability Framework principle 2: data
Document the sources and origins of development data and assess their reliability, categorisation, variable selection and any synthetic, imputed or augmented data; assess the dependencies, bias, security and privacy of the data used in operation
AIGE-OBL-USGAO-DATA. Drawn from chapter 08.
Text alternative
- Clause: GAO AI Accountability, principle 2, practices 2.1….
- Duty holder: Federal agencies and other….
- Applies from: 2021-06-30, Voluntary.
- Artefact: Dataset datasheet with lineage.
- Layers: Layer 02, Layer 03.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 20 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-USGAO-DATA- Instrument
- GAO AI Accountability Framework (GAO-21-519SP) framework
- Clause
- principle 2 (data), practices 2.1 to 2.8
- In scope
- Federal agencies and other entities; auditors and third-party assessors
- Authority
- U.S. Government Accountability Office; inspectors general
- Applies from
- Voluntary · Non-binding audit framework; published 2021-06-30
The artefact that evidences it
Dataset datasheet with lineage; data-quality and representativeness evals; data-flow map.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- TC260 Framework 3.0 TC260 2.1.3 Data safety risks (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- EU AI Act Art. 4a Special-category data for bias detection
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- TC260 Framework 3.0 TC260 5.1 Model R&D safety guidelines
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- ISO 42001 A.10 Third-party and customer relationships (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MAP 4 MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data (core)
- NIST AI RMF MANAGE 3 MANAGE 3: AI risks and benefits from third-party entities are managed (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- NIST AI RMF MANAGE 3.1 MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP LLM LLM04:2026 Supply Chain (core)
- OWASP Agentic ASI04 Agentic Supply Chain Vulnerabilities (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- TC260 Framework 3.0 TC260 4.4.4 Open-source ecosystem
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
Fairness and non-discrimination
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- EU AI Act Art. 4a Special-category data for bias detection (core)
- GDPR Art. 5(1)(a) Lawfulness, fairness and transparency (core)
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias as identified in the MAP function are evaluated and results are documented (core)
- CSA AICM GRC-11 Bias and Fairness Assessment (core)
- CoE Convention CoE Art. 10 Equality and non-discrimination (core)
- China GenAI Measures GenAI Art. 4(2) Prevent discrimination in design, data, training and service (core)
- GAO AI Accountability 3.8 Bias: identify potential biases, inequities, and other societal concerns resulting from the AI system (core)
- GDPR Art. 9 Processing of special categories of personal data
- ISO 42001 A.5.4 Assessing AI system impact on individuals or groups of individuals (clause not verified)
- NIST AI RMF GOVERN 3.1 GOVERN 3.1: Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team
- UK ATRS ATRS 2.4.2 Model specification
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- China Algo. Rec. AlgoRec Art. 21 No unreasonable differential treatment in trading conditions
Privacy and data protection
- GDPR Art. 5 Principles relating to processing of personal data (core)
- GDPR Art. 6 Lawfulness of processing (core)
- GDPR Art. 25 Data protection by design and by default (core)
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system as identified in the MAP function is examined and documented (core)
- CSA AICM DSP-08 Data Privacy by Design and Default (core)
- OWASP LLM LLM02:2026 Sensitive Information Disclosure (core)
- CoE Convention CoE Art. 11 Privacy and personal data protection (core)
- China GenAI Measures GenAI Art. 7(3) Consent or another lawful basis for personal information in training data (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- EU AI Act Art. 59 Further processing of personal data in the AI regulatory sandbox
- EU AI Act Art. 4a Special-category data for bias detection
- GDPR Art. 35 Data protection impact assessment
- ISO 42001 A.7 Data for AI systems
- CSA AICM DSP-22 Privacy Enhancing Technologies
- UK DUAA UK GDPR Art. 22B Restrictions on automated decision-making
- Singapore GenAI GenAI 2 Data
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
Source
Chapter 08, section Federal audit and oversight, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-usgao-data.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). GAO AI Accountability Framework principle 2: data (AIGE-OBL-USGAO-DATA). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-usgao-data. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{GAO AI Accountability Framework principle 2: data (AIGE-OBL-USGAO-DATA)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-usgao-data},
note = {Version 0.5.0}
}