Tier 2: Evidence-grade controls
AI model monitoring and drift management
Continuous oversight to detect performance degradation, data shifts, and unintended outcomes, with defined actions when thresholds are breached.
Board-defensible evidence
- Monitoring plan defining what is monitored (accuracy, drift, bias signals, latency, error types), how often, and the thresholds that trigger investigation or rollback, with named owners.
- Dashboards and alerting evidence showing real-time or periodic monitoring outputs, alert history, and ticket links documenting investigations and corrective actions taken.
- Drift analysis records showing what changed (data distribution, population, environment), when the change began, and how impact to outcomes was measured and reported to oversight teams.
- Operational playbooks showing what happens when thresholds are breached, including escalation paths, decision rights to pause the model, and communication requirements to stakeholders.
- Periodic performance review and revalidation records showing sign-off to continue operation, including documented rationale when operating near tolerance limits.
Why this matters
Post-incident questions are simple: what did you monitor, when did you know, and what did you do about it.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.