{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-006.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-006",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-006",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-006",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-006.json",
    "title": "Pinned versions and a tested path back",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "The registry pins the model, prompt, retrieval corpus and guardrail versions of the baseline and the candidate; an unpinned change detected at runtime is a rollback trigger; a new provider model version runs in shadow and canary against the pinned version before it takes traffic; and the path back, a blue-green switch or a feature flag, is exercised in the shadow stage before anyone depends on it.",
    "failureModes": [
      "A vendor model update that nobody treated as a release reaches users without passing any stage.",
      "The model, prompt, corpus or guardrail version that served a request cannot be told, because the registry did not pin it.",
      "The path back is used for the first time during an incident, untested."
    ],
    "scope": "Deployed AI systems with versioned components, including models reached through a provider's API, whose versions change on the provider's schedule. Verifying a model artefact's signature and provenance before load is AIGE-CTL-ASSURE-010.",
    "enforcementPoints": [
      "deploy",
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Registry diff of the pinned versions of baseline and candidate, and switch events from the exercised path back",
        "schemaId": null,
        "schema": null,
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "An unpinned change detected at runtime triggers a rollback to the pinned baseline; a new vendor version takes no traffic until it has passed shadow and canary."
    },
    "layer": 4,
    "secondaryLayers": [
      2
    ],
    "patterns": [
      {
        "slug": "staged-rollout-rollback-criteria",
        "title": "Staged Rollout with Rollback Criteria",
        "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "staged-rollout-rollback-criteria",
        "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [],
      "iso42001": [
        {
          "id": "A.6.2.5",
          "title": "AI system deployment"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MANAGE 2.4",
          "title": "Mechanisms to supersede, disengage or deactivate AI systems"
        },
        {
          "id": "MANAGE 3.1",
          "title": "AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 18,
        "title": "Pattern: Staged Rollout with Rollback Criteria",
        "text": "Pattern: Staged Rollout with Rollback Criteria (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria",
        "verified": "primary"
      },
      {
        "n": 19,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Progressive delivery as a control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#progressive-delivery-as-a-control",
        "verified": "primary"
      },
      {
        "n": 22,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Monitoring third parties while you run\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#monitoring-third-parties-while-you-run",
        "verified": "primary"
      },
      {
        "n": 23,
        "title": "\"BlueGreenDeployment\"",
        "text": "\"BlueGreenDeployment\" (two identical production environments; switch back on failure). Martin Fowler. 2010-03-01.",
        "url": "https://martinfowler.com/bliki/BlueGreenDeployment.html",
        "verified": "primary"
      },
      {
        "n": 24,
        "title": "\"Feature Toggles (aka Feature Flags)\"",
        "text": "\"Feature Toggles (aka Feature Flags)\" (release, experiment, ops and permissioning toggles; ops kill switches for graceful degradation). Pete Hodgson, martinfowler.com. 2017-10-09.",
        "url": "https://martinfowler.com/articles/feature-toggles.html",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "File every provider change and deprecation notice against the registry entry, and keep an alternative model warm in the eval harness so a forced migration starts from evidence rather than from a standing start.",
      "A retrain, a fine-tune, a prompt change, a corpus refresh and a vendor model update are all releases: each bumps the version in the registry."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "Where a provider changes the model behind a stable name and exposes no version, the pin cannot be checked directly; how to detect such a change beyond the canary awaits review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
