Model Lifecycle and Monitoring
Governing AI from development through deployment to retirement. Covers the registries, monitoring systems, explainability standards, and incident response processes that keep AI systems operating safely in production, and that give regulators and auditors the evidence they need.
Key board-level questions
- 1.Do we continuously monitor for model drift, bias, and performance degradation?
- 2.Are all models registered, versioned, and explainable in production?
- 3.Do we have real-time observability and incident response for AI systems?
- 4.Can we produce audit-ready evidence for every AI-driven decision?
Regulatory frameworks
NIST Artificial Intelligence Risk Management Framework Playbook
The voluntary NIST AI RMF Playbook provides implementation guidance, suggested actions, and example outputs across AI use cases. It supports GOVERN, MAP, MEASURE, and MANAGE throughout the system lifecycle.
ISO/IEC 42001:2023 - Artificial Intelligence Management System
ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.
NIST AI 600-1 Generative AI Profile
This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models.
EU AI Act: AI Literacy and Prohibited AI Systems Provisions (Applicable 2 February 2026)
This entry lists February 2, 2026 as the EU AI Act’s first major compliance deadline. It requires AI developers and deployers in the EU to establish workforce literacy measures. It also describes enforceable prohibitions on unacceptable-risk practices. Organizations must cease prohibited practices and demonstrate adequate staff competency by that date.
Treasury Department AI Risk Management Framework for Financial Services
Treasury’s February 2026 framework translates NIST AI RMF principles into 230 financial-sector control objectives. It covers Treasury-supervised institutions, including banks, asset managers, insurers, and payment processors developing or deploying AI. Controls address model lifecycles, identity resolution, data governance, and compatibility with SOC 2 and NIST cybersecurity requirements.
