A.6 / AI control area

AI system lifecycle

Control AI systems from idea and design through data work, model selection, testing, release, operation, change, and retirement.

AIMSEVIDENCEDATAEVIDENCEMODELEVIDENCEHUMANEVIDENCEAI GOVERNANCEA.6 AI EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

How to implement it

  1. 01Define lifecycle gates for AI systems
  2. 02Document intended use and design assumptions
  3. 03Test against performance, robustness, bias, security, and misuse criteria
  4. 04Control model, prompt, dataset, and provider changes

Evidence to keep

  • - Lifecycle procedure
  • - Design records
  • - Test results
  • - Release approval and change logs

Metrics to watch

  • - Systems passing lifecycle gates
  • - Failed release criteria
  • - Unauthorized AI changes
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map