Tier 2: Evidence-grade controls
Model governance and lifecycle controls
End-to-end controls that govern how AI models are proposed, built, tested, approved, deployed, changed, and retired.
Board-defensible evidence
- Lifecycle policy defining required gates (proposal, design review, testing, approval, deployment, monitoring, retirement), with required artifacts and accountable approvers for each gate.
- Release management and change-control records showing model versioning, what changed, who reviewed it, testing completed, and production deployment approvals with timestamps.
- Access control and segregation-of-duties evidence showing who can modify training data, code, and deployments, and how privileged actions are logged and reviewed.
- Retirement and decommission procedures showing how models are removed, data retention is handled, downstream dependencies are identified, and stakeholders are notified.
- Governance reporting showing lifecycle compliance rates, outstanding control gaps, overdue reviews, and escalation actions taken for non-compliance.
Why this matters
Without lifecycle controls, "one small model update" becomes an ungoverned change that is hard to defend after a failure.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.