AI governance lifecycle controls

Operationalise AI governance across the lifecycle.

Translate applicable requirements and risk considerations into defined governance, lifecycle controls, responsibilities and reviewable evidence.

From source to implementation and assurance

  1. Authoritative source
  2. Applicability
  3. Governance & risk decisions
  4. Lifecycle controls
  5. Evidence
  6. Assurance

Lifecycle controls are where applicable governance requirements and risk decisions are translated into activities, responsibilities, controls and evidence across the AI system lifecycle.

Nine-stage organising model

Data and system governance must remain connected.

Across the lifecycle
01

Concept and Requirements

Purpose
Define intended purpose, context, stakeholders, requirements, constraints and initial governance boundaries before solution commitment.
Governance considerations
Confirm decision ownership, intended purpose, affected stakeholders, required approvals and governance interfaces.
Applicability considerations
Identify relevant jurisdictions, actor or role, sector, use context, decision impact and source-specific triggers.
Risk & impact considerations
Identify foreseeable harms, impacts, uncertainty, misuse and risk criteria appropriate to the applicable source and context.
Control areas
Intended-purpose definition; requirements; stakeholder and impact analysis; initial applicability and risk assessment; accountability.
Evidence considerations
Approved purpose and requirements; applicability rationale; risk and impact record; decision and approval record.
02

Data Acquisition and Preparation

Purpose
Establish that data used to develop, configure, evaluate or operate the AI system is suitable for its intended purpose and governed throughout use.
Governance considerations
Define data accountability, provenance expectations, permitted use, quality criteria and review responsibilities.
Applicability considerations
Consider privacy and data-protection, IP and licensing, sector restrictions, geographic restrictions and source-specific data requirements.
Risk & impact considerations
Assess representativeness, quality, bias, provenance, leakage, security, rights and changes in data or context.
Control areas
Data sourcing; provenance; quality; preparation; representativeness; access; privacy; rights; lineage.
Evidence considerations
Data inventory and records; provenance; quality checks; preparation records; approvals; limitations; dataset and version traceability.
03

Acquisition and Third-Party Management

Purpose
Control externally acquired AI systems, models, services, components, data and supporting services.
Governance considerations
Define acquisition ownership, due diligence, contractual and control expectations, supplier oversight and exit or change responsibilities.
Applicability considerations
Identify obligations affected by provider, deployer or other source-specific roles, outsourcing, supply chain, data transfers and sector requirements.
Risk & impact considerations
Assess dependency, transparency limitations, vendor change, concentration, security, continuity, performance and contractual risks.
Control areas
Due diligence; requirements in acquisition; supplier assessment; contractual controls; change notification; service and support; exit.
Evidence considerations
Assessment record; requirements and contract evidence; supplier information; approvals; change notices; performance and service records.
04

System and Model Design

Purpose
Translate requirements, governance decisions and risk treatments into an AI system and operating design.
Governance considerations
Define design authority, human oversight, decision boundaries, security, explainability and transparency, and control ownership.
Applicability considerations
Map applicable requirements to design features, interfaces, disclosures, records and operational controls.
Risk & impact considerations
Evaluate design choices, model limitations, automation boundaries, foreseeable misuse, security and resilience, and human factors.
Control areas
Architecture; model and system design; human oversight; interfaces; security; explainability; logging; fallback; configuration.
Evidence considerations
Design specifications; architecture; design decisions; risk treatments; oversight design; traceability to requirements.
05

Development, Verification and Validation

Purpose
Build or configure the system and obtain evidence that specified requirements and intended-use expectations are met before deployment.
Governance considerations
Define independent review where appropriate, acceptance authority, test ownership, issue handling and release criteria.
Applicability considerations
Determine source-specific testing, documentation, validation, conformity or assessment expectations. Validation is not universally equivalent to GxP CSV.
Risk & impact considerations
Test performance, robustness, bias and fairness where relevant, security, failure modes, human oversight and residual risks under representative conditions.
Control areas
Development and configuration control; verification; validation; evaluation; testing; issue resolution; acceptance.
Evidence considerations
Versioned build and configuration; test plans and results; evaluation records; defects and issues; approvals; residual-risk decisions; release evidence.
06

Transition and Deployment

Purpose
Move the approved AI system into its intended operating environment under controlled conditions.
Governance considerations
Define deployment authority, readiness criteria, operational ownership, user competence, fallback and support arrangements.
Applicability considerations
Confirm deployment-specific obligations, notices and transparency, registrations or documentation where applicable, and local or context changes.
Risk & impact considerations
Assess environment mismatch, integration and configuration risk, access and security, user reliance, operational readiness and rollback or fallback.
Control areas
Deployment readiness; configuration; access; training; communication; integration; fallback and rollback; baseline establishment.
Evidence considerations
Deployment approval; configuration baseline; access records; training and communication records; readiness checklist; release notes.
07

Operation and Maintenance

Purpose
Operate and support the AI system within approved boundaries while controlling service, configuration and maintenance changes.
Governance considerations
Maintain operational ownership, support responsibilities, escalation, service controls and authorised change decision-making.
Applicability considerations
Reassess applicability when use, users, jurisdiction, supplier, data, model or context changes.
Risk & impact considerations
Manage operational failures, service degradation, configuration drift, security events, human reliance and maintenance or retraining impacts.
Control areas
Operation; maintenance; service requests; incident and problem handling; configuration; change enablement; access; support; supplier management.
Evidence considerations
Operational logs; service, incident and problem records; configuration and change records; maintenance and retraining records; approvals; support evidence.
08

Monitoring and Continual Evaluation

Purpose
Monitor performance, risk, impacts and control effectiveness and determine when intervention, reassessment or change is required.
Governance considerations
Define monitoring ownership, thresholds, review cadence and triggers, escalation, intervention and decision authority.
Applicability considerations
Track changes in law, guidance, standards and operational circumstances that can alter obligations or control expectations.
Risk & impact considerations
Monitor performance and drift, emerging harms and impacts, bias and fairness where relevant, incidents, misuse, security, control effectiveness and residual risk.
Control areas
Performance monitoring; drift; event monitoring; periodic review; incident trend; regulatory change; control review; continual evaluation.
Evidence considerations
Monitoring outputs; threshold and breach records; review minutes; trend analysis; incident records; reassessments; decisions and actions.
09

Retirement and Disposal

Purpose
End use of the AI system or component in a controlled manner while preserving required records, continuity and obligations.
Governance considerations
Define retirement authority, stakeholder communication, record retention, data and model disposition, supplier exit and residual accountability.
Applicability considerations
Identify retention, deletion, archival, contractual, sector, privacy, records and continuing-obligation requirements.
Risk & impact considerations
Assess continuity, dependency, residual decisions and outputs, data and model retention, security, transfer and replacement risks.
Control areas
Decommissioning; archival and retention; data and model disposition; access removal; supplier exit; transition; post-retirement obligations.
Evidence considerations
Retirement approval; disposition and retention records; access closure; archive; migration and transition evidence; supplier closure; lessons learned.

About this lifecycle structure

The nine-stage lifecycle is a RegulatedAI.in organising structure. It uses recognised lifecycle terminology where appropriate and does not represent a lifecycle model prescribed by any single standard, framework or regulatory source.

Continue exploring