What governance evidence do we need when a model version changes?

When an AI model version changes, governance evidence must demonstrate adherence to a structured change management process. This includes documented impact assessments covering performance, risks, ethical implications, and regulatory compliance. Evidence should show re-validation against specified requirements, approval by authorised personnel, and updated documentation reflecting the new version's characteristics and operational procedures, ensuring continued alignment with the AI management system.

Practitioners must establish and maintain a formal change management process for AI systems, as mandated by ISO 42001. This process requires documenting the rationale for the change, a comprehensive impact assessment, and a re-evaluation of the AI system's risks and opportunities, including those related to data privacy, bias, and explainability. The impact assessment must consider the potential effects on the AI system's intended purpose, performance metrics, and compliance with legal and ethical requirements. Evidence should include records of these assessments, demonstrating due diligence in understanding the implications of the new model version before deployment.

A common oversight is failing to adequately re-validate the AI system against its original or updated performance criteria and ethical guidelines. Organisations frequently neglect to assess the cumulative effect of minor version changes, which can subtly degrade system performance or introduce new vulnerabilities over time. Governance evidence must therefore include records of re-validation activities, such as testing results, performance benchmarks, and re-assessments of fairness and robustness. Furthermore, evidence of management review and authorisation for the new version's deployment is crucial, ensuring accountability and demonstrating that the change aligns with the organisation's AI policy and objectives.

Sources

  • ISO/IEC 42001:2023, Clause 8.4 AI system change management
  • ISO/IEC 42001:2023, Clause 8.1 Operational planning and control
  • ISO/IEC 42001:2023, Clause 6.1 Actions to address risks and opportunities for AI systems

Related