← All themes

Lifecycle & Change across ISO 42001, NIST AI RMF and the EU AI Act

// theme · lifecycle

Lifecycle & Change

Open in explorer →

Design, development, deployment, decommissioning, change management.

// Do once → satisfies all three
ONE stage-gate process (concept → design → deploy → operate → retire) with change-control for retraining.

Every framework expects lifecycle management. Stage gates with explicit change control make it observable in all three.

ISO 42001
Annex A.6 · Cl.8.1 · Cl.10.1
NIST AI RMF
MAP 1.1 · MANAGE 1.1 · MANAGE 4.2
EU AI Act
Art.17
// Evidence auditors expect
  • Stage-gate criteria from concept → retirement
  • Change-management record for retrains and prompt updates
  • Decommissioning plan with data and model disposal
  • Conformity-assessment record before market placement
// Common pitfalls
  • Retraining treated as 'just a model refresh' with no change control.
  • Decommissioning forgotten - old models still serving traffic with no owner.
  • Conformity assessment treated as launch checklist, not lifecycle obligation.
EU AI Act
1
Art.17 quality management system covers design and change; Art.43 conformity assessment is required before market placement.