Overview
AI Lifecycle Management requires a structured, auditable approach with support for the full lifecycle of AI systems within the AI Quality Management System. This will ensure that design, development, verification, validation, deployment, and ongoing monitoring activities are conducted in a controlled manner that directly contributes to the protection of health, safety, and fundamental rights of affected persons, achievement of intended purposes and regulatory compliance in alignment with the EU AI Act and EN 18286 requirements.
AI system lifecycle management addresses key AI-specific operational controls by replacing ad-hoc or high-level governance documentation with a dedicated, stage-gated workflow. All stages should be linked to a central AI System Register, risk management processes, and audit programmes, with immutable snapshots taken at critical transition points.
Structured Stages
AI system lifecycle management should be organised into the following sequential, iterative stages. Each stage should comprise defined inputs, activities, outputs, controls, and evidence requirements. Progression between stages should require documented review and approval, with full traceability captured through a universal QMS control feature.
1. Data Preparation
- Purpose: Ensure that training, validation, and test datasets meet quality, relevance, and bias-mitigation standards to support safe and rights-respecting AI system behaviour.
- Key Activities: Data sourcing and provenance documentation (lineage tracking). Data cleaning, labelling, and pre-processing with audit logs. Bias and fairness assessment of datasets. Data quality metrics evaluation.
- Controls: Mandatory data governance sign-off; automated flagging of data drift risks.
- Outputs: Data manifest, quality report, bias assessment, lineage graph.
- Evidence: Snapshot of dataset metadata and quality scores at stage gate.
2. Model Development
- Purpose: Develop AI models in a transparent, version-controlled manner that allows for later verification of design decisions impacting safety and rights.
- Key Activities: Model architecture selection and justification. Training process documentation. Version control of models and associated code. Documentation of design choices.
- Controls: Change management integration; role-based access for development artifacts.
- Outputs: Model version history, training logs, design rationale document.
- Evidence: Immutable snapshot of model state and documentation at key checkpoints.
3. Verification & Validation
- Purpose: Rigorously test the AI system against predefined criteria for accuracy, robustness, fairness, and compliance with health/safety/rights protections before deployment.
- Key Activities: Robustness testing, bias and fairness assessments, performance validation, human oversight simulation, security testing.
- Controls: Independent review; mandatory template completion; linkage to risk management.
- Outputs: Verification/validation reports, model cards, bias/fairness reports, robustness test results.
- Evidence: Full snapshot of test datasets, model versions, and results.
4. Deployment
- Purpose: Ensure controlled rollout of the AI system with monitoring hooks, rollback capabilities, and clear human oversight interfaces.
- Key Activities: Deployment planning, configuration of production monitoring, setup of human oversight interfaces.
- Controls: Pre-deployment approval gate; automated checks.
- Outputs: Deployment manifest, monitoring configuration, oversight procedures, rollback plan.
- Evidence: Snapshot of deployed configuration and associated approvals.
5. Monitoring
- Purpose: Enable continuous oversight of the deployed AI system to detect degradation, drift, or new risks to health, safety, or fundamental rights.
- Key Activities: Real-time and periodic performance monitoring, data and concept drift detection, incident collection, periodic re-validation triggers.
- Controls: Automated alerts; linkage to nonconformity/CAPA processes.
- Outputs: Monitoring reports, drift alerts, incident logs, re-validation recommendations.
- Evidence: Ongoing snapshots of monitoring data and system state.
Integration with Other Platform Capabilities
The lifecycle management module is deeply integrated with Risk Management, Audit Programmes, Change Management, Evidence Generation, and Nonconformity processes - ensuring end-to-end traceability and protection throughout the AI system's life.
Benefits for Protection of Health, Safety, and Fundamental Rights
This structured approach ensures AI systems are not deployed without rigorous validation, provides regulators with clear evidence, enables proactive issue detection, and supports the EU AI Act's emphasis on technical documentation, human oversight, and post-market monitoring.