{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-003.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-003",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-003.json",
    "title": "Oversight by trained people with authority to stop",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Oversight of the deployed system is assigned to named people with the competence, training and authority it needs, and the support to use it: role-based training (what the system is for, the limitations its instructions declare, when to override it, how to report a problem) is a condition of access, and an operator who sees the system misbehave may stop it without first asking permission.",
    "failureModes": [
      "The decision record names no oversight roles, or names roles with no training record behind them.",
      "A person gets or keeps access to the system with no current training record for the role.",
      "An operator who sees the system misbehave has to ask for permission before pausing it.",
      "Oversight is undifferentiated: every output waits for review, which destroys the value of the system, or none does, which removes the oversight the risk requires."
    ],
    "scope": "Deployed AI systems whose outputs inform or take decisions that people oversee, in particular high-risk systems. For AI agents, the checkpoint and approval controls of the Agent Runtime profile apply as well, and for an agent with an Annex III purpose AIGE-CTL-AGENT-030 restates the same oversight duty.",
    "enforcementPoints": [
      "deploy",
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Role-based training records whose grants field the access check reads",
        "schemaId": "training-record",
        "schema": "https://aigovernanceengineer.com/schemas/training-record.v1.json",
        "layer": 4
      },
      {
        "artefact": "Oversight roles and the ids of their training records in the deployment decision record",
        "schemaId": "deployment-decision-record",
        "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "Access to the system is refused while the person holds no current training record for the role."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "human-in-the-loop-gate",
        "title": "Human-in-the-loop Gate",
        "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "human-in-the-loop-gate",
        "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
      },
      {
        "kind": "schema",
        "ref": "training-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-training-record"
      },
      {
        "kind": "schema",
        "ref": "deployment-decision-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART26-2",
          "name": "EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-2"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART14",
          "name": "EU AI Act Art. 14 human oversight",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART4",
          "name": "EU AI Act Art. 4 AI literacy",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4"
        }
      ],
      "iso42001": [
        {
          "id": "A.9.2",
          "title": "Processes for responsible use of AI systems"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MAP 3.5",
          "title": "Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 11,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Check the data and the people\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#check-the-data-and-the-people",
        "verified": "primary"
      },
      {
        "n": 12,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Policies at go-live\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#policies-at-go-live",
        "verified": "primary"
      },
      {
        "n": 13,
        "title": "Pattern: Human-in-the-loop Gate",
        "text": "Pattern: Human-in-the-loop Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
        "verified": "primary"
      },
      {
        "n": 14,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 14",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 14 (human oversight of high-risk systems). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_14",
        "verified": "primary"
      },
      {
        "n": 15,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4 (providers and deployers take measures to support the AI literacy of their staff). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Classify outputs or actions by consequence: gate the high-consequence class behind a person with enough context to decide, keep the routine class autonomous under guardrails, and log the approver, the context and the decision as evidence.",
      "Pair the training with interface aids that support judgement rather than replace it: sources shown, confidence where it is meaningful, and a visible way to reach a person."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "The training record carries an expiry, but the source material sets no refresher interval per oversight role."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
