{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-004.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-004",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-004",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-004",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-004.json",
    "title": "Go-live decision with conditions as code",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "A go-live review reads an evidence pack and records one of three outcomes (approve, approve with conditions, reject) with the approver and the residual risk, accepted by an authority that matches the risk tier; each condition is a check with an owner and a deadline, the approval lapses when a check has not passed in time, and any member of the review can attach named dissent to the decision record.",
    "failureModes": [
      "A condition is granted and forgotten: its deadline passes with no check, and the approval keeps running.",
      "Residual risk is accepted by the team that wants to ship rather than by an authority that matches the risk tier.",
      "A checklist item is marked met with no link to the record that answers it, or a management override is not recorded.",
      "Dissent raised in the review is not attached to the decision, so the incident review cannot tell whether anyone saw the problem coming."
    ],
    "scope": "Every release that takes an AI system, or a new version of it, into use: a new system, a major or minor change, a retrain or a rollback, the change types the go/no-go record distinguishes.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Go/no-go record: checklist items linked to the records that answer them, reviewers' decisions by role, overrides, conditions, residual risk and the rollout plan",
        "schemaId": "go-no-go",
        "schema": "https://aigovernanceengineer.com/schemas/go-no-go.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A rejected release is blocked and its registry status reads rejected; when a condition's check has not passed by its deadline, the approval lapses and the feature flag closes."
    },
    "layer": 5,
    "secondaryLayers": [
      1
    ],
    "patterns": [],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "go-no-go",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-go-no-go"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [],
      "iso42001": [
        {
          "id": "A.6.2.5",
          "title": "AI system deployment"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MANAGE 1.1",
          "title": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 7,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"What the review reads\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#what-the-review-reads",
        "verified": "primary"
      },
      {
        "n": 16,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Three outcomes\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#three-outcomes",
        "verified": "primary"
      },
      {
        "n": 17,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Recorded dissent\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#recorded-dissent",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Make each condition code: a feature flag caps exposure while the condition holds, and the approval carries an expiry.",
      "Review recorded dissent at the first monitoring review after go-live, and close it with the evidence that answered it."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "The go/no-go schema has no field of its own for dissent; whether it belongs in the reviewers list, the overrides or extensions awaits review.",
      "No EU AI Act obligation is mapped: the go-live review is chapter 15 practice rather than a single article, and the mapping awaits review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
