Lifecycle
Evaluation & Testing
6 controls apply at this stage.
- detective
AI-CTRL-003
Adversarial Robustness Testing for LLM Systems
Validate that production-bound LLM and agentic AI systems have been tested against direct prompt injection, indirect prompt injection, jailbreak, refusal evasion, and (where applicable) multi-modal adversarial inputs, with documented findings, remediation, and re-test cycles.
Security & Adversarial RobustnessISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +6v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-005
AI Risk Assessment and Impact Assessment
Ensure that each AI system is subject to a documented risk assessment and AI System Impact Assessment (AIIA) aligned with ISO/IEC 23894 and ISO/IEC 42005, completed prior to production deployment and refreshed on material change or annually.
AI Risk ManagementISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-010
Model Versioning and Change Control
Ensure that every model promoted to production is uniquely versioned, traceable to its training data, evaluation results, and approval, and subject to controlled change-management with rollback capability.
Change ManagementISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +4v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-011
Bias Testing and Fairness Validation
Validate performance, fairness, and disparate-impact metrics for AI systems with protected-class implications, using methods appropriate to the system type and use case, with documented findings and remediation.
Bias & FairnessISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +1v1.0.0 Reviewed 2026-05-01 - detective
AI-CTRL-014
Adversarial Robustness Testing for Predictive ML and Computer Vision
Validate that production predictive ML, computer-vision, recommender, and speech models have been tested against evasion attacks, model-extraction attacks, membership-inference attacks, data-poisoning detection, and (for vision) physical-world perturbations, with documented findings and remediation.
Security & Adversarial RobustnessISO 42001 NIST AI RMF EU AI Act SOC 2 +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-017
Pre-Production AI Evaluation Gates
Require explicit, documented evaluation against defined thresholds — covering performance, fairness, robustness, safety, and (where applicable) drift baselines — as a gate to production deployment for every AI system.
Model LifecycleISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +2v1.0.0 Reviewed 2026-05-01