AI system lifecycle
Control AI systems from idea and design through data work, model selection, testing, release, operation, change, and retirement.
How to implement it
- 01Define lifecycle gates for AI systems
- 02Document intended use and design assumptions
- 03Test against performance, robustness, bias, security, and misuse criteria
- 04Control model, prompt, dataset, and provider changes
Evidence to keep
- - Lifecycle procedure
- - Design records
- - Test results
- - Release approval and change logs
Metrics to watch
- - Systems passing lifecycle gates
- - Failed release criteria
- - Unauthorized AI changes
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Secure development policyUse for ISO 27001 A.8.25 to A.8.32, source code controls, change management, and SOC 2 change controls.Cloud services and outsourcing policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, and oversight of cloud and outsourced service providers.
Open the control-to-policy map