{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-001.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-001",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-001.json",
    "title": "Test Plan Frozen Before Evaluation",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "The test plan (suites, metrics, thresholds with their link to the error appetite, datasets, subgroups, sample sizes and the number of repeated runs) is frozen in the repository before evaluation starts, and a change to it after results are known is a diff with an approver.",
    "failureModes": [
      "Evaluation starts before the plan's metrics, thresholds, datasets, subgroups, sample sizes and number of repeated runs are fixed.",
      "A metric or threshold changes after the results are known with no approved diff: metric shopping, choosing the metric that passes after seeing all of them.",
      "A planned suite names no failure mode, or its threshold has no link to the error appetite.",
      "A test category is missing from the plan with no reason given in its scope."
    ],
    "scope": "Every system or model tested before a release, and every change to its test plan. The suites themselves, and whether a result is valid, are covered by AIGE-CTL-ASSURE-002 and AIGE-CTL-EVAL-009.",
    "enforcementPoints": [
      "pre_merge"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Test plan frozen in the repository before the first run: suites with metric, threshold, failure mode and whether a failure blocks, exit criteria, owner and approver",
        "schemaId": "test-plan",
        "schema": "https://aigovernanceengineer.com/schemas/test-plan.v1.json",
        "layer": 3
      }
    ],
    "failureResponse": {
      "effect": "require_approval",
      "text": "A change to the plan after results are known is a diff that needs an approver before it takes effect."
    },
    "layer": 3,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "eval-gate-in-ci",
        "title": "Eval Gate in CI",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "test-plan",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-test-plan"
      },
      {
        "kind": "pattern",
        "ref": "eval-gate-in-ci",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART9",
          "name": "EU AI Act Art. 9 risk management system",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
        },
        {
          "id": "AIGE-OBL-NISTRMF-MEASURE",
          "name": "MEASURE",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure"
        },
        {
          "id": "AIGE-OBL-ISO42001-A6",
          "name": "A.6 AI system life cycle",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.4",
          "title": "AI system verification and validation"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MEASURE 2.1",
          "title": "Test sets, metrics, and details about the tools used during TEVV are documented."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 1,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"A test plan before the first run\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#a-test-plan-before-the-first-run",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "Pattern: Eval Gate in CI",
        "text": "Pattern: Eval Gate in CI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems",
        "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "The EU AI Act asks for testing against \"prior defined metrics and probabilistic thresholds\" (Art. 9(8)); chapter 14 reads the operative words as prior defined and freezes the plan before evaluation starts.",
      "Build the plan from the chapter's test-type matrix: one suite per test type the system needs (validation, robustness, security and adversarial, bias and fairness, regression and the rest), each behind the eval gate; the schema asks for a reason in the scope for any category left out."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "Which changes to a frozen plan (a new suite, a larger sample, a stricter threshold) may proceed without a new approval, and which reopen the plan?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
