GAO AI Accountability Framework principle 4: monitoring
Plan continuous or routine monitoring, set the acceptable range of data and model drift, document monitoring results and corrective actions, and reassess the system's utility and the conditions for scaling it
AIGE-OBL-USGAO-MON. Drawn from chapter 08.
Text alternative
- Clause: GAO AI Accountability, principle 4, practices 4.1….
- Duty holder: Federal agencies and other….
- Applies from: 2021-06-30, Voluntary.
- Artefact: Monitoring plan with drift….
- Layers: Layer 04, Layer 05.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 17 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-USGAO-MON- Instrument
- GAO AI Accountability Framework (GAO-21-519SP) framework
- Clause
- principle 4 (monitoring), practices 4.1 to 4.5
- In scope
- Federal agencies and other entities; auditors and third-party assessors
- Authority
- U.S. Government Accountability Office; inspectors general
- Applies from
- Voluntary · Non-binding audit framework; published 2021-06-30
The artefact that evidences it
Monitoring plan with drift thresholds; monitoring log with corrective actions; periodic review record.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Logging and traceability
- EU AI Act Art. 12 Record-keeping (core)
- ISO 42001 A.6 AI system life cycle (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Continuous monitoring and auditing (core)
- TC260 Framework 3.0 TC260 5.3.6 Logs kept and audited (core)
- EU AI Act Art. 26(6) Deployers keep the automatically generated logs (core)
- ISO 42001 A.6.2.8 AI system recording of event logs (core) (clause not verified)
- CSA AICM LOG-09 Log Records (core)
- Korea AI Act Art. 34(1)(5) Documents showing the measures taken (core)
- OECD AI Principles OECD 1.5(b) Traceability of datasets, processes and decisions (core)
- prEN 18229-1 prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft; supports Art. 12) (core) (clause not verified)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place
- China AI Labelling Label Art. 5 Implicit metadata labels
- EU AI Act Art. 19 Automatically generated logs
- CSA AICM LOG-12 Transaction/Activity Logging
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
Incident response and monitoring
- EU AI Act Art. 72 Post-market monitoring by providers and post-market monitoring plan (core)
- EU AI Act Art. 73 Reporting of serious incidents (core)
- ISO 42001 A.8 Information for interested parties (core)
- ISO 42001 10.2 Nonconformity and corrective action (core)
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored (core)
- TC260 Framework 3.0 TC260 5.3.7 Real-time risk monitoring (core)
- TC260 Framework 3.0 TC260 5.3.18 Incident reporting (core)
- China GenAI Measures GenAI Art. 14 Handle and report unlawful content (core)
- China GenAI Measures GenAI Art. 15 Complaint and reporting mechanism (core)
- EU AI Act Art. 26(5) Deployer monitoring, informing the provider and suspending use (core)
- GPAI Code Safety C9 Commitment 9: Serious incident reporting (core)
- GDPR Arts. 33–34 Notification and communication of a personal data breach (core)
- NIST AI RMF MANAGE 4.3 MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented (core)
- CSA AICM SEF-07 Incident Management and Response (core)
- CSA AICM SEF-08 Security Breach Notification (core)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold (core)
- Singapore GenAI GenAI 4 Incident Reporting (core)
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test (core)
- G7 Code G7 Action 2 Identify and mitigate vulnerabilities, incidents and misuse after deployment (core)
- G7 Code G7 Action 4 Responsible information sharing and reporting of incidents (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk
- TC260 Framework 3.0 TC260 App. 2 II.6 Emergency plans
- China Algo. Rec. AlgoRec Art. 7 Security management and emergency response
- EU AI Act Art. 3(49) Definition of serious incident
- EU AI Act Art. 20 Corrective actions and duty of information
- GPAI Code Safety 3.5 Measure 3.5: Post-market monitoring
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use
- NIST AI RMF GOVERN 4.3 GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing
Deployment, change and decommissioning
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems (core)
- ISO 42001 A.6.2.5 AI system deployment (core) (clause not verified)
- ISO 42001 A.6.2.6 AI system operation and monitoring (core) (clause not verified)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- NIST AI RMF MANAGE 4.1 MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management (core)
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness (core)
- CSA AICM AIS-06 Secure Application Deployment (core)
- EU AI Act Art. 25 Responsibilities along the AI value chain
- EU AI Act Art. 43(4) New conformity assessment on substantial modification
- EU AI Act Art. 20 Corrective actions and duty of information
- EU AI Act Art. 79 Procedure at national level for dealing with AI systems presenting a risk
- EU AI Act Art. 86 Right to explanation of individual decision-making
- ISO 42001 A.9 Use of AI systems
- CSA AICM CCC-01 Change Management Policy and Procedures
- CSA AICM DSP-02 Secure Disposal
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified
- OECD AI Principles OECD 1.4 Robustness, security and safety
- TC260 Framework 3.0 TC260 5.3 Operators' safety guidelines
- TC260 Framework 3.0 TC260 5.3.19 Re-assessment on material change
Source
Chapter 08, section Federal audit and oversight, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-usgao-mon.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). GAO AI Accountability Framework principle 4: monitoring (AIGE-OBL-USGAO-MON). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-usgao-mon. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{GAO AI Accountability Framework principle 4: monitoring (AIGE-OBL-USGAO-MON)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-usgao-mon},
note = {Version 0.5.0}
}