NIST AI RMF APPLICATION GOVERNANCE INFRASTRUCTURE MODEL

TEVV (Test, Evaluation, Verification, and Validation)

Part of: MG: MANAGE — Risk Response & Communication

Description

TEVV processes are implemented and iterated throughout the AI lifecycle to ensure systems function as intended and align with specifications. TEVV is not a one-time gate — it is a continuous process that spans from requirements through retirement.

Suggested Actions

1
Establish a comprehensive TEVV framework spanning development through operation: define what is tested, when, by whom, and what constitutes pass/fail at each stage
2
Conduct pre-deployment validation against requirements and risk thresholds — no AI system deploys to production without documented evidence that it meets minimum performance, fairness, and security standards
3
Perform ongoing verification of system behavior in production environment — production behavior can differ significantly from test behavior due to data distribution differences, scale effects, and user behavior patterns
4
Re-evaluate systems when significant changes occur: model retraining, data pipeline changes, infrastructure changes, user population changes, or regulatory changes
5
Document TEVV results with traceability from requirements through test cases through results — auditors and regulators will ask for evidence that systems were properly validated
6
Integrate TEVV into CI/CD pipelines where possible — automated testing for performance, fairness, and security on every model update reduces the risk of regressions