Authorize a model for production use
Draft
Authorize a model for production use
Layer 4. Control AUTAuthorization
Allocation
| L4-AUT-01 | |
|---|---|
| Decides | Business Accountable Executive |
| Consulted | Model Owner, CISO, DPO and Head of Risk |
| Executes | Platform Owner |
| Evidence | Authorization referencing the validation evidence relied on and each domain acceptance |
In plain terms
Decide the evidence is sufficient and the system may run. Held by someone who did not produce the evidence, which is the whole point.
What is being judged
Not whether the model is good. Whether the evidence that it is good is sufficient for the consequence it carries.
Three questions. Was it validated against thresholds recorded before validation ran, or against thresholds chosen to fit the result? Does the evidence cover the conditions the system will actually meet, rather than the conditions it was tested under? Is every referenced record current, per the evidence currency convention?
What this decision does not cover
It does not re-perform validation. An accountable executive auditing the Model Owner’s work has misunderstood the role and broken the separation the layer depends on. It does not accept the risk, which is L4-RSK-02 and L4-RSK-03, though in practice all three are signed together.
When it fires
On event. Before first production use. On a new model version. On material change to data scope, purpose or population. When a referenced record expires.
On cycle. None directly; inherited from the acceptances it references.
What you need before deciding
Validation, bias and performance reports bound to the version. The model card, current to the running version. Domain acceptances, in date. The classification record. Regulatory applicability and any impact assessment sign-off.
How this goes wrong
The builder who accepts: the Model Owner set the thresholds, ran validation and signed the authorization. Authorizing a version that no longer runs: the authorization names version 1.4 and production serves 1.7. Evidence that expired: the model card describes a version retired months ago, and Layer 4 verified against it and reached a confident wrong conclusion.
Related decisions
Upstream L3-01, L3-02, L4-CLS-04, L4-CLS-06, L4-RSK-02, L4-RSK-03.
Downstream L5-05 production readiness gate, which cannot pass without this.
Reversal L4-AUT-05, L4-AUT-06.
Instrument references
ISO/IEC 42001 clause 8, NIST AI RMF MANAGE 1 and 2 both address deployment decisions without allocating who makes them. The separation from the validating role is AI9GM’s.
Correction
The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.