{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-005.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-005",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-005.json",
    "title": "Live Control Status from the Assurance Store",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "The status of each control is a live query over the records it emits to the assurance store, not a point-in-time attestation, so a control that stops firing or starts failing is visible as it happens, not at the next audit.",
    "failureModes": [
      "A control's status rests on an attestation made when someone looked, although the model has since been retrained or an agent has gained a tool.",
      "A control stops firing and its status still shows it working until the next audit.",
      "The post-market monitoring plan of a high-risk system is a document, not the versioned configuration of the telemetry that collects the data."
    ],
    "scope": "Controls of AI systems in production whose decisions reach the assurance store, and, for high-risk systems, the post-market monitoring their provider runs under Art. 72. What a control decides, and the monitoring of model performance itself, are out of scope: the monitoring plan with its thresholds, owners and consequences is AIGE-CTL-DEPLOY-008.",
    "enforcementPoints": [
      "runtime",
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Evidence records each control emits to the assurance store, which the live status query of that control reads",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "A control that stops firing shows as failing within minutes (the pattern's illustrative dashboard tile goes red), not at the next audit."
    },
    "layer": 5,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "continuous-assurance-telemetry",
        "title": "Continuous Assurance Telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "continuous-assurance-telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      },
      {
        "kind": "schema",
        "ref": "evidence-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
      },
      {
        "kind": "chapter",
        "ref": "eu-ai-act",
        "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART72",
          "name": "EU AI Act Art. 72 post-market monitoring",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
        },
        {
          "id": "AIGE-OBL-NISTRMF-MANAGE",
          "name": "MANAGE",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
        },
        {
          "id": "AIGE-OBL-NISTRMF-GOVERN",
          "name": "GOVERN",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern"
        },
        {
          "id": "AIGE-OBL-CSA-AICM",
          "name": "AICM v1.1: 247 control objectives across 18 domains",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [
        {
          "id": "MANAGE 4.1",
          "title": "Post-deployment monitoring plans are implemented"
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 11,
        "title": "Pattern: Continuous Assurance Telemetry",
        "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
        "verified": "primary"
      },
      {
        "n": 12,
        "title": "The EU AI Act in one pass",
        "text": "The EU AI Act in one pass (AI Governance Engineering Body of Knowledge v0.5.0, chapter 18, section \"Post-market monitoring and serious incidents (Articles 72 and 73)\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/eu-ai-act#post-market-monitoring-and-serious-incidents-articles-72-and-73",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Expose the current status of each control as a query over the store, for example a dashboard tile backed by a live query over the decisions the control emitted.",
      "For a high-risk system, chapter 18 treats Continuous Assurance Telemetry as the post-market monitoring system and the plan as its versioned configuration; the Commission's guidance and template for the plan are due by 2 Sep 2027 (Art. 72(3))."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "How long may a control go without emitting a record before its status turns to failing, and should that window differ by control?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
