{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-002.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-002",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-002",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-002",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-002.json",
    "title": "Instructions for use held and followed",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "The deployer holds the provider's instructions for use for the version it runs, records the gaps it finds in them and what it could not verify, and uses the system in line with them: its monitoring hooks, oversight measures, input data and log collection follow what the instructions state, and its maintenance calendar starts from the lifetime and maintenance they declare.",
    "failureModes": [
      "The system runs with no instructions for use on record for the version in production.",
      "The go-live review accepts the provider's own evidence without recording what the deployer could not verify.",
      "A metric the instructions name has no monitoring hook, or the system receives input data the instructions say it must not receive."
    ],
    "scope": "Deployers of AI systems supplied with instructions for use, in particular high-risk systems, whose providers must supply them. Writing the instructions is the provider's side and out of scope, except where the deployer is also the provider.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Instructions for use on record for the running version, referenced from the deployment decision record with the gaps found in them",
        "schemaId": "instructions-for-use",
        "schema": "https://aigovernanceengineer.com/schemas/instructions-for-use.v1.json",
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "require_approval",
      "text": "Gaps in the instructions, and what the deployer could not verify, are recorded and go to the go-live review, which decides on them explicitly."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "instructions-for-use",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-instructions-for-use"
      },
      {
        "kind": "schema",
        "ref": "deployment-decision-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      },
      {
        "kind": "chapter",
        "ref": "incidents",
        "url": "https://aigovernanceengineer.com/bok/incidents"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART26",
          "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART13",
          "name": "EU AI Act Art. 13 transparency and information to deployers",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13"
        }
      ],
      "iso42001": [
        {
          "id": "A.8.2",
          "title": "System documentation and information for users"
        }
      ],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 7,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"What the review reads\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#what-the-review-reads",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Maintenance calendar and retraining governance\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#maintenance-calendar-and-retraining-governance",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "Incidents, issues and root causes",
        "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Deployer duties: inform the provider, suspend use\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/incidents#deployer-duties-inform-the-provider-suspend-use",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
        "verified": "primary"
      },
      {
        "n": 10,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13 (instructions for use: capabilities and limitations of performance; pre-determined changes; human oversight measures; expected lifetime and maintenance; log collection). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_13",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "When the evidence is the provider's own, run the go-live review in review mode: assess the supplier's assessment and record, explicitly, what the deployer could not verify.",
      "Build a monitoring hook, with its threshold as code, for each metric the provider's instructions name (layer 04)."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "Whether a revised version of the instructions re-opens the go-live review, or only the gaps it changes, is not settled by the source material."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
