GAO AI Accountability Framework principle 3: performance
Catalogue components, define precise, consistent and reproducible metrics, assess each component and the whole system against them, identify biases and define procedures for human supervision
AIGE-OBL-USGAO-PERF. Drawn from chapter 08.
Text alternative
- Clause: GAO AI Accountability, principle 3, practices 3.1….
- Duty holder: Federal agencies and other….
- Applies from: 2021-06-30, Voluntary.
- Artefact: Eval suite with versioned….
- Layers: Layer 03, Layer 04.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 23 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-USGAO-PERF- Instrument
- GAO AI Accountability Framework (GAO-21-519SP) framework
- Clause
- principle 3 (performance), practices 3.1 to 3.9
- In scope
- Federal agencies and other entities; auditors and third-party assessors
- Authority
- U.S. Government Accountability Office; inspectors general
- Applies from
- Voluntary · Non-binding audit framework; published 2021-06-30
The artefact that evidences it
Eval suite with versioned metrics per component and system; bias eval; human-oversight procedure.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Documentation and transparency
- EU AI Act Art. 11 Technical documentation (core)
- EU AI Act Art. 13 Transparency and provision of information to deployers (core)
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models (core)
- ISO 42001 7.5 Documented information (core)
- ISO 42001 A.6 AI system life cycle (core)
- ISO 42001 A.8 Information for interested parties (core)
- China AI Labelling Label Art. 4 Explicit labels for generated content (core)
- China AI Labelling Label Art. 5 Implicit (metadata) labels (core)
- China GenAI Measures GenAI Art. 12 Labelling of generated content (core)
- China Deep Synthesis DeepSyn Art. 16 Implicit technical labels (core)
- China Deep Synthesis DeepSyn Art. 17 Conspicuous labels for confusable content (core)
- GPAI Code Transparency 1.1 Drawing up and keeping up-to-date model documentation (core)
- GDPR Arts. 13–14 Information to be provided to the data subject (core)
- CSA AICM MDS-03 Model Documentation (core)
- Korea AI Act Art. 31 Transparency: prior notice, output labelling, realistic synthetic content (core)
- UK ATRS ATRS Tier 1 Summary information (core)
- Singapore GenAI GenAI 3 Trusted Development and Deployment (core)
- CoE Convention CoE Art. 14(2) Documentation sufficient to contest decisions; complaint to authorities (core)
- OECD AI Principles OECD 1.3 Transparency and explainability (core)
- G7 Code G7 Action 3 Publicly report capabilities, limitations and domains of use (core)
- GAO AI Accountability 1.9 Transparency: enable external stakeholders to access information on the design, operation, and limitations of the AI system (core)
- EU AI Act Art. 50 Transparency obligations for providers and deployers of certain AI systems
- NIST AI RMF MAP 1 MAP 1: Context is established and understood
- NIST AI RMF MEASURE 2.8 MEASURE 2.8: Risks associated with transparency and accountability are examined and documented
- China GenAI Measures GenAI Art. 19 Disclosure to regulators
- China Algo. Rec. AlgoRec Art. 16 Notice that recommendation is used
- GB/T 45654 GB/T 45654 Content labelling Generated-content labelling requirements (clause not verified)
- EU AI Act Art. 86 Right to explanation of individual decision-making
- EU AI Act Art. 18 Documentation keeping
- EU AI Act Art. 43 Conformity assessment
- EU AI Act Art. 53(1)(d) Public summary of the content used for training
- EU AI Act Art. 50(2), 50(4) Machine-readable marking of synthetic content; disclosure of deep fakes
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Art. 30 Records of processing activities
- NIST AI RMF MAP 1.6 MAP 1.6: System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks
- NIST AI RMF MEASURE 2.9 MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance
- CSA AICM MDS-04 Model Documentation Requirements
- Korea AI Act Art. 34(1)(2) Explanation plan: result, main criteria, training-data overview
- UK ATRS ATRS 2.2 Description and rationale
- CoE Convention CoE Art. 15(2) Notification of interaction with an AI system
- GAO AI Accountability 1.7 Specifications: establish and document technical specifications
Inventory and registration
- EU AI Act Art. 49 Registration (core)
- EU AI Act Art. 71 EU database for high-risk AI systems (core)
- ISO 42001 A.4 Resources for AI systems (core)
- NIST AI RMF GOVERN 1.6 GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities (core)
- China Algo. Rec. AlgoRec Art. 24 Algorithm filing (core)
- China Deep Synthesis DeepSyn Art. 19 Filing for public-opinion services (core)
- China GenAI Measures GenAI Art. 17 Algorithm filing (core)
- UK ATRS ATRS Tier 1 Summary information (the published record) (core)
- EU AI Act Art. 6 Classification rules for high-risk AI systems
- TC260 Framework 3.0 TC260 App. 2 II.2 Identity and access management
- TC260 Framework 3.0 TC260 4.4.1 CII registration and filing
- EU AI Act Art. 3(1) Definition of an AI system
- EU AI Act Art. 52 Procedure
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness
- CSA AICM STA-08 Supply Chain Inventory
- CSA AICM IAM-03 Identity Inventory
- Korea AI Act Art. 33 Confirmation of high-impact AI
Human oversight
- EU AI Act Art. 14 Human oversight (core)
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- TC260 Framework 3.0 TC260 App. 2 II.3 Strengthen human approval (core)
- GDPR Art. 22 Automated individual decision-making, including profiling (core)
- NIST AI RMF MAP 3.5 MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function (core)
- CSA AICM GRC-15 Human supervision (core)
- Korea AI Act Art. 34(1)(4) Human management and supervision (core)
- UK DUAA UK GDPR Art. 22C Safeguards for automated decision-making (core)
- UK ATRS ATRS 2.3.2 Human review (core)
- Singapore Agentic Agentic 2.2.2 Design for meaningful human oversight (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF GOVERN 3.2 GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
- China Algo. Rec. AlgoRec Art. 17 User option to switch off
- China GenAI Measures GenAI Art. 10 User guidance and protection
- EU AI Act Art. 14(4)(b) Awareness of automation bias
- OWASP Agentic ASI09 Human-Agent Trust Exploitation
- CoE Convention CoE Art. 8 Transparency and oversight
- OECD AI Principles OECD 1.2(b) Human agency and oversight safeguards
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 3 Technological countermeasures (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- TC260 Framework 3.0 TC260 5.3.14 Resilience
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
Fairness and non-discrimination
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- EU AI Act Art. 4a Special-category data for bias detection (core)
- GDPR Art. 5(1)(a) Lawfulness, fairness and transparency (core)
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias as identified in the MAP function are evaluated and results are documented (core)
- CSA AICM GRC-11 Bias and Fairness Assessment (core)
- CoE Convention CoE Art. 10 Equality and non-discrimination (core)
- China GenAI Measures GenAI Art. 4(2) Prevent discrimination in design, data, training and service (core)
- GAO AI Accountability 2.7 Bias: assess reliability, quality, and representativeness of the data used in operation, including potential biases (core)
- GDPR Art. 9 Processing of special categories of personal data
- ISO 42001 A.5.4 Assessing AI system impact on individuals or groups of individuals (clause not verified)
- NIST AI RMF GOVERN 3.1 GOVERN 3.1: Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team
- UK ATRS ATRS 2.4.2 Model specification
- OECD AI Principles OECD 1.2 Rule of law, human rights and democratic values, including fairness and privacy
- China Algo. Rec. AlgoRec Art. 21 No unreasonable differential treatment in trading conditions
Source
Chapter 08, section Federal audit and oversight, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-usgao-perf.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). GAO AI Accountability Framework principle 3: performance (AIGE-OBL-USGAO-PERF). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-usgao-perf. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{GAO AI Accountability Framework principle 3: performance (AIGE-OBL-USGAO-PERF)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-usgao-perf},
note = {Version 0.5.0}
}