ISO 42001 INFRASTRUCTURE

AI system version control

Part of: Annex A.10: AI System Management

Description

Management of AI system versions including models, training data, code, and configurations with traceability and rollback capability.

Implementation Guidance

Version Control Scope

Version control all AI artifacts: model weights and architecture, training and validation datasets, feature engineering code, hyperparameters and training configurations, serving infrastructure configurations, and pre/post-processing pipelines. Each production deployment must have a fully reproducible version snapshot.

Model Registry

Implement a model registry (MLflow, SageMaker Model Registry, or equivalent) tracking: model versions with metadata, training data version references, performance metrics at registration time, deployment history, and approval status. Enforce promotion workflows (development → staging → production).

Rollback Capability

Maintain rollback capability for all production AI systems: keep previous model versions deployable, document rollback procedures and test them periodically, define rollback triggers (performance degradation, safety incident, fairness violation), and track rollback execution time targets.

Evidence Requirements

  • Version control logs for all AI artifacts
  • Model registry with version history and metadata
  • Rollback procedure documentation and test records
  • Deployment history with version traceability