{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-001.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-001",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-001.json",
    "title": "Deployment decision record before use",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Before an AI system is put to use in a context, a Deployment Decision Record states the objective, what the system is not for (its negative space), the risk tier and obligations, the performance floors including per group, the retirement conditions and the owner, checks the deployer duties one by one, records the decision and who took it, and is referenced from the registry entry.",
    "failureModes": [
      "A system serves in production with no decision record, or with one that no registry entry references.",
      "The record names no negative space, so a new use (the chapter's example: HR queries routed to a customer-service assistant) arrives as a quiet configuration change instead of a new intake.",
      "Performance floors are set after a vendor demonstration, or only as an average, so a good overall figure hides a group the system fails."
    ],
    "scope": "Every AI system an organisation puts to use in a given context, built or procured. A new use of an existing system is a new decision.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Signed Deployment Decision Record, committed next to the system and linked from its registry entry",
        "schemaId": "deployment-decision-record",
        "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "require_approval",
      "text": "A proposed use that the record does not cover, or that falls in its negative space, goes back through intake and classification before it proceeds."
    },
    "layer": 2,
    "secondaryLayers": [
      1
    ],
    "patterns": [],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "deployment-decision-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART26",
          "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.5",
          "title": "AI system deployment"
        },
        {
          "id": "A.9.4",
          "title": "Intended use of the AI system"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MAP 1.1",
          "title": "Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented."
        },
        {
          "id": "MANAGE 1.1",
          "title": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 1,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"The Deployment Decision Record\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#the-deployment-decision-record",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Start from the use case, not the model\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#start-from-the-use-case-not-the-model",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Set performance and explainability requirements first\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#set-performance-and-explainability-requirements-first",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "The record's floors become the thresholds of the eval gate (layer 03) and its negative space becomes the scope the runtime watches (layer 04).",
      "Set the requirements before looking at candidates: metrics that match the harm, a floor per population the system acts on, go/no-go thresholds each traced to the failure mode it stands for, and the explanation the use needs."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "The deployment decision record schema has no dedicated field for the negative space or the retirement conditions the chapter puts in the record; whether they belong in the deployment context, the conditions or extensions awaits review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
