{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-008.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-008",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-008.json",
    "title": "Monitoring plan with thresholds, owners and consequences",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "A monitoring plan kept as data names the drift classes that apply to the system and a statistic for each, and gives every metric a threshold, a window, a named owner who can be paged and the action a breach fires; each check writes an evidence record, pass or fail, and the plan and its findings are reviewed on a stated cadence.",
    "failureModes": [
      "A dashboard has no thresholds, or a breach pages no one, so drift is watched by nobody.",
      "A signal has no owner who can be paged for it.",
      "A generative system degrades (more ungrounded answers, more refusals in one language) while every infrastructure metric stays green.",
      "Checks that pass leave no record, so the absence of breaches cannot be shown."
    ],
    "scope": "Every AI system in production, built or procured: providers of high-risk systems keep a post-market monitoring plan, and deployers monitor operation on the basis of the instructions for use. Whether each check is still firing is the live control status of AIGE-CTL-ASSURE-005.",
    "enforcementPoints": [
      "runtime",
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Monitoring plan with data sources, metrics, thresholds, triggers, owner and review cadence",
        "schemaId": "post-market-monitoring-plan",
        "schema": "https://aigovernanceengineer.com/schemas/post-market-monitoring-plan.v1.json",
        "layer": 4
      },
      {
        "artefact": "Evidence record per check, pass or fail, in the assurance store",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "A breach fires the action the plan sets for it (an issue, a retrain, a degraded mode, an incident or a tripped breaker) and pages the named owner."
    },
    "layer": 4,
    "secondaryLayers": [
      5
    ],
    "patterns": [
      {
        "slug": "drift-fairness-monitor",
        "title": "Drift & Fairness Monitor",
        "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "drift-fairness-monitor",
        "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
      },
      {
        "kind": "schema",
        "ref": "post-market-monitoring-plan",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-post-market-monitoring-plan"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART72",
          "name": "EU AI Act Art. 72 post-market monitoring",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART26-5",
          "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART9",
          "name": "EU AI Act Art. 9 risk management system",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.6",
          "title": "AI system operation and monitoring"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MEASURE 2.4",
          "title": "The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production."
        },
        {
          "id": "MEASURE 3.1",
          "title": "Existing, unanticipated and emergent risks are tracked"
        },
        {
          "id": "MANAGE 4.1",
          "title": "Post-deployment monitoring plans are implemented"
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 27,
        "title": "Pattern: Drift & Fairness Monitor",
        "text": "Pattern: Drift & Fairness Monitor (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor",
        "verified": "primary"
      },
      {
        "n": 28,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Drift: what moves and how to see it\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#drift-what-moves-and-how-to-see-it",
        "verified": "primary"
      },
      {
        "n": 29,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Who owns the signal\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#who-owns-the-signal",
        "verified": "primary"
      },
      {
        "n": 30,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 72",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 72 (post-market monitoring system and plan). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_72",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
        "verified": "primary"
      },
      {
        "n": 31,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 9",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 9 (risk management system across the lifecycle of a high-risk system). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Name what can move (data, label, concept, pipeline, vendor model and usage drift) and pick a statistic per class: a stability index or two-sample test against a reference window, predicted against observed positive rate, performance on fresh labels, data contracts, version-pin checks, topic classification of traffic against the negative space.",
      "Labels often arrive late or never: pair input-drift statistics with a delayed performance check, and for generative systems sample outputs for groundedness scoring and human review.",
      "A threshold change is a change to a control: a reviewed diff with an approver, not an edit on a dashboard."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "Provider and deployer each monitor part of the system and see different data; how the deployer's findings reach the provider's post-market monitoring is not settled here."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
