Model Lifecycle and Monitoring
Governing AI from development through deployment to retirement. Covers the registries, monitoring systems, standards for explaining how AI reaches its outputs, and incident response processes that keep AI systems operating safely in production, and that give regulators and auditors the evidence they need.
Key board-level questions
- 1.Do we continuously monitor for bias, falling accuracy, and drift (a model's behavior slowly changing over time)?
- 2.Are all models registered, versioned, and explainable in production?
- 3.Do we have real-time observability and incident response for AI systems?
- 4.Can we produce audit-ready evidence for every AI-driven decision?
Regulatory frameworks
NIST AI Risk Management Framework (AI RMF 1.0) and Playbook
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.
ISO/IEC 42001:2023 - Artificial Intelligence Management System
ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.
NIST AI 600-1 Generative AI Profile
This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models (general-purpose models that handle text, images, and audio).
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
Financial Services AI Risk Management Framework (FS AI RMF)
The US Treasury released the Financial Services AI Risk Management Framework on 19 February 2026, with the Cyber Risk Institute. It adapts the NIST AI RMF into 230 control objectives for financial institutions, organized by AI adoption stage. It is voluntary guidance, released alongside a shared AI lexicon.
