How to turn AI governance into evidence at each change to a generative AI product or workflow.
Treat the application as the unit of review
A generative AI application combines a model with prompts, retrieval, tools, data, interfaces, and human workflow. The same underlying model can behave differently when any of those parts change. Define the application boundary and the intended users before selecting tests.
Record the use case in the AI inventory and name the release owner. A release record should identify the version of each important component and the impact of the proposed change.
Design evaluations around the use
Set acceptance criteria for the outcomes that matter: task quality, unsafe output, data leakage, bias or disparate impact where relevant, prompt injection, and failure to defer to a human. Use representative scenarios, including edge cases and adversarial inputs. Keep test data, settings, results, reviewer decisions, and known limits together.
NIST's AI RMF describes mapping context, measuring risk, and managing responses as continuing activities. A benchmark score alone says little about a live workflow with real users, connected tools, and changing content.
Make the release decision explicit
Decide who may approve deployment, what evidence they need, and which defects block release. A conditional approval should state the restriction, owner, and date for re-evaluation. Integrate these decisions with security change management and supplier review rather than running a separate AI ceremony after a release is already scheduled.
ISO/IEC 42001 gives the organizational system for assigning these responsibilities and reviewing whether they work. It does not prescribe one universal test suite for every AI application.
Monitor use and know how to stop it
Set signals for output quality, user complaints, inappropriate use, security events, supplier changes, and drift from the approved purpose. Record who investigates, who can suspend the feature, and how users will be told about a material issue. Review whether monitoring itself creates privacy or retention concerns.
Feed incidents and trends into the next assessment and management review. The evidence trail should show a complete cycle: risk was identified, tested, accepted or treated, observed in operation, and reconsidered when conditions changed.
Put it into practice
- Define the full application boundary, including prompts, tools, and retrieval.
- Build scenario tests around actual use and foreseeable misuse.
- Record go, conditional go, or stop decisions with named approvers.
- Give operators a monitoring and suspension route.
Primary sources
Normstone resources are general information, not legal advice or an independent assessment.