NIST AI RMF APPLICATION GOVERNANCE INFRASTRUCTURE MODEL

Lifecycle monitoring

Part of: MG: MANAGE — Risk Response & Communication

Description

AI systems are monitored throughout their lifecycle to detect performance degradation, drift, emerging risks, and unintended consequences. An AI system that performs well at deployment will not necessarily perform well next month.

Suggested Actions

1
Implement continuous monitoring for model performance metrics (accuracy, precision, recall, latency, error rates) computed on production data with automated alerting on threshold breaches
2
Deploy data drift detection comparing production input distributions against training data distributions — drift is inevitable, the question is when it becomes material and requires action
3
Implement concept drift detection monitoring whether the relationship between inputs and correct outputs has changed — the world changes even when your data doesn't
4
Monitor for emergent risks including adversarial attacks, misuse patterns, prompt injection attempts, and unexpected user behaviors that weren't anticipated during development
5
Track and investigate unexpected system behaviors or outcomes — anomaly detection on model outputs, user complaints, and downstream system metrics
6
Establish monitoring dashboards visible to AI system owners, governance teams, and risk management — monitoring that only engineers see is monitoring that doesn't inform governance decisions

Related Controls

Continuous AI Monitoring