{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-015.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-015",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-015",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-015",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-015.json",
    "title": "Retirement runbook with access and data removal",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "An AI system is retired through a runbook, not a deletion: dependencies are analysed, users move to the fallback, sunset notices go out before the date, a final evidence snapshot is archived, weights, corpora and logs are kept or destroyed as licence, lawful basis and retention decide, every identity and credential is revoked, the registry entry is set to retired rather than deleted, and discovery confirms no copy still runs.",
    "failureModes": [
      "The registry entry is deleted while a copy keeps serving.",
      "A service account or API key of the retired system stays live.",
      "The evidence that the system was ever governed is lost with it.",
      "Consumers of the outputs learn of the retirement after the date, because nobody analysed dependencies or sent sunset notices."
    ],
    "scope": "Every AI system or agent retired, replaced or withdrawn: at end of life, on replacement, for unacceptable risk, for a regulatory reason, on a vendor exit or after an incident.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Decommissioning runbook: reason, decision reference, dependencies, notifications, steps with owners and evidence, data disposition, evidence archive and sign-off",
        "schemaId": "decommissioning-runbook",
        "schema": "https://aigovernanceengineer.com/schemas/decommissioning-runbook.v1.json",
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "require_approval",
      "text": "The runbook closes only with a final sign-off, once every step is done or skipped with a reason."
    },
    "layer": 4,
    "secondaryLayers": [
      2
    ],
    "patterns": [
      {
        "slug": "deactivation-localisation-retirement-runbook",
        "title": "Deactivation, Localisation & Retirement Runbook",
        "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
      },
      {
        "slug": "shadow-ai-discovery",
        "title": "Shadow-AI Discovery",
        "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "deactivation-localisation-retirement-runbook",
        "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
      },
      {
        "kind": "schema",
        "ref": "decommissioning-runbook",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-decommissioning-runbook"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [],
      "iso42001": [],
      "nistAiRmf": [
        {
          "id": "GOVERN 1.7",
          "title": "Decommissioning and phasing out AI systems safely"
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 50,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Retirement and decommissioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#retirement-and-decommissioning",
        "verified": "primary"
      },
      {
        "n": 44,
        "title": "Pattern: Deactivation, Localisation & Retirement Runbook",
        "text": "Pattern: Deactivation, Localisation & Retirement Runbook (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook",
        "verified": "primary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Design retirement in from the start: the deployment decision record already names the conditions under which the system is retired.",
      "Irregular or indiscriminate termination can itself increase risk, so retirement moves users to a fallback before traffic stops; the downstream use register lists the consumers to warn."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "The source material leaves the length of the evidence archive to the retention schedule and maps retirement to several record-keeping articles; the obligation mapping of this control awaits review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
