Lifecycle
Deployment
10 controls apply at this stage.
- preventive
AI-CTRL-004
Third-Party AI Vendor Due Diligence
Ensure that third-party AI products and AI-enabled services are subject to risk-based due diligence covering data handling, model provenance, security testing, incident response, compliance posture, and contractual safeguards before procurement and on an ongoing basis.
Third-Party AIISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +4v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-005
AI Risk Assessment and Impact Assessment
Ensure that each AI system is subject to a documented risk assessment and AI System Impact Assessment (AIIA) aligned with ISO/IEC 23894 and ISO/IEC 42005, completed prior to production deployment and refreshed on material change or annually.
AI Risk ManagementISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-006
Human-in-the-Loop Design for High-Risk Decisions
Ensure that AI systems producing decisions with legal or similarly significant effects on individuals incorporate meaningful human oversight in the decision flow, with documented design, training, and audit trails.
Human OversightISO 42001 NIST AI RMF EU AI Act OWASP Agentic Top 10 +2v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-007
Output Filtering and Content Moderation
Apply layered output filtering and content moderation to LLM and generative AI systems to prevent disclosure of sensitive data, prohibited content, executable payloads, and policy-violating outputs.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-008
AI System Logging and Monitoring
Ensure that AI systems produce logs sufficient to detect abuse, investigate incidents, demonstrate compliance, and reconstruct decisions, with logs protected from tampering and retained per regulatory requirements.
Logging & MonitoringISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +4v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-010
Model Versioning and Change Control
Ensure that every model promoted to production is uniquely versioned, traceable to its training data, evaluation results, and approval, and subject to controlled change-management with rollback capability.
Change ManagementISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +4v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-012
AI System Documentation and Model Cards
Maintain current, accessible technical documentation (model cards, datasheets, system cards) for every production AI system, sufficient to enable risk-based use, regulatory review, and downstream consumer understanding.
Transparency & ExplainabilityISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +1v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-013
Personal Data Minimization in Training and Inference
Ensure that personal data used in training, fine-tuning, evaluation, and inference is minimized to the data strictly necessary for the stated purpose, processed under a defensible lawful basis, and subject to the rights of affected individuals.
PrivacyISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-017
Pre-Production AI Evaluation Gates
Require explicit, documented evaluation against defined thresholds — covering performance, fairness, robustness, safety, and (where applicable) drift baselines — as a gate to production deployment for every AI system.
Model LifecycleISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +2v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-019
Agentic AI Tool Authorization Boundaries
Restrict agentic AI systems to least-privilege tool authorizations; enforce approval boundaries for high-impact actions; log and review all tool invocations; and prevent privilege escalation across multi-step or multi-agent workflows.
Inference & OutputISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01