← All themesOpen in explorer →
Lifecycle & Change across ISO 42001, NIST AI RMF and the EU AI Act
// theme · lifecycle
Lifecycle & Change
Design, development, deployment, decommissioning, change management.
// Do once → satisfies all three
ONE stage-gate process (concept → design → deploy → operate → retire) with change-control for retraining.
Every framework expects lifecycle management. Stage gates with explicit change control make it observable in all three.
ISO 42001
Annex A.6 · Cl.8.1 · Cl.10.1
NIST AI RMF
MAP 1.1 · MANAGE 1.1 · MANAGE 4.2
EU AI Act
Art.17
// Evidence auditors expect
- ✓ Stage-gate criteria from concept → retirement
- ✓ Change-management record for retrains and prompt updates
- ✓ Decommissioning plan with data and model disposal
- ✓ Conformity-assessment record before market placement
// Common pitfalls
- ⚠ Retraining treated as 'just a model refresh' with no change control.
- ⚠ Decommissioning forgotten - old models still serving traffic with no owner.
- ⚠ Conformity assessment treated as launch checklist, not lifecycle obligation.
ISO 42001
11Annex A.6 frames the AI lifecycle from requirements to retirement; Cl.8 controls operation.
Clause 4.4
AI Management System
Establish, implement, maintain and continually improve the AIMS and its processes.
Clause 8.1
Operational planning and control
Plan, implement and control operational processes for the AI lifecycle.
Clause 8.2
AI risk assessment (operational)
Perform risk assessments at planned intervals and on significant change.
Clause 10.1
Continual improvement
Continually improve suitability, adequacy and effectiveness of the AIMS.
Annex A.6.1.2
Objectives for responsible development
Set objectives that guide responsible development of AI systems across the lifecycle.
Annex A.6.1.3
Processes for responsible design and development
Define processes for the responsible design and development of AI systems.
Annex A.6.2.2
AI system requirements and specification
Specify and document requirements for each AI system, including performance and risk criteria.
Annex A.6.2.3
Documentation of AI system design and development
Document the design and development of AI systems to support review and audit.
Annex A.6.2.4
AI system verification and validation
Define and apply measures to verify and validate AI systems against requirements.
Annex A.6.2.5
AI system deployment
Plan and control the deployment of AI systems into production environments.
Annex A.6.2.6
AI system operation and monitoring
Operate and monitor AI systems in production, including drift and performance checks.
NIST AI RMF
3MAP/MEASURE/MANAGE explicitly apply across pre-design, design, deployment and operation.
MAP 1.1
Context established and understood
Intended purposes, settings and assumptions about the AI system are documented.
MAP 2.1
AI system tasks and methods defined
Task, method, and capabilities of the AI system are defined.
MANAGE 4.2
Continuous improvement
Measurable continual improvement activities are integrated.
EU AI Act
1Art.17 quality management system covers design and change; Art.43 conformity assessment is required before market placement.