AI9GM
Type to search documentation.

Authorize a model for production use

Draft

Allocation

L4-AUT-01
DecidesBusiness Accountable Executive
ConsultedModel Owner, CISO, DPO and Head of Risk
ExecutesPlatform Owner
EvidenceAuthorization referencing the validation evidence relied on and each domain acceptance

In plain terms

Decide the evidence is sufficient and the system may run. Held by someone who did not produce the evidence, which is the whole point.

What is being judged

Not whether the model is good. Whether the evidence that it is good is sufficient for the consequence it carries.

Three questions. Was it validated against thresholds recorded before validation ran, or against thresholds chosen to fit the result? Does the evidence cover the conditions the system will actually meet, rather than the conditions it was tested under? Is every referenced record current, per the evidence currency convention?

What this decision does not cover

It does not re-perform validation. An accountable executive auditing the Model Owner’s work has misunderstood the role and broken the separation the layer depends on. It does not accept the risk, which is L4-RSK-02 and L4-RSK-03, though in practice all three are signed together.

When it fires

On event. Before first production use. On a new model version. On material change to data scope, purpose or population. When a referenced record expires.

On cycle. None directly; inherited from the acceptances it references.

What you need before deciding

Validation, bias and performance reports bound to the version. The model card, current to the running version. Domain acceptances, in date. The classification record. Regulatory applicability and any impact assessment sign-off.

How this goes wrong

The builder who accepts: the Model Owner set the thresholds, ran validation and signed the authorization. Authorizing a version that no longer runs: the authorization names version 1.4 and production serves 1.7. Evidence that expired: the model card describes a version retired months ago, and Layer 4 verified against it and reached a confident wrong conclusion.

Upstream L3-01, L3-02, L4-CLS-04, L4-CLS-06, L4-RSK-02, L4-RSK-03.

Downstream L5-05 production readiness gate, which cannot pass without this.

Reversal L4-AUT-05, L4-AUT-06.

Instrument references

ISO/IEC 42001 clause 8, NIST AI RMF MANAGE 1 and 2 both address deployment decisions without allocating who makes them. The separation from the validating role is AI9GM’s.

Correction

Correct L4-AUT-01

The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.

Attribution