9
4. AI Lifecycle Management
Robust controls are a core component of the Management pillar. Controls should be embedded
across the AI lifecycle to ensure safe, transparent, and accountable deployment. The CCRO
recommends a structured approach that includes safeguards at each stage of the model
lifecycle, from initial conception to final usage.
4.1 Selection
AI Risk begins at the selection process. Whether building or buying, companies should have a
structured approach to concept selection with a simple premise at its core: AI should not be
selected purely for the sake of selecting AI. Rather, selection should begin with the three
principles in mind.
1) Decision-Making Capacity. While AI can enhance decision-making through advanced
analytics and enhanced insights, unfettered AI-driven decision-making in high-stakes
environments is extremely risky. Human oversight remains critical.
2) Data Volume, Quality, and Availability. AI’s effectiveness is contingent on the
availability of high-quality datasets with high volume and velocity. Not all markets and
use cases meet the necessary data requirements.
3) AI Is Not Always the Optimal Solution. Many operational efficiencies can be achieved
through simpler automation and rule-based systems. If the objective is to improve
speed and efficiency, alternative solutions may provide results that are faster, safer, and
more cost-effective.
Companies should apply due diligence when selecting third-party AI Tools, including vendor
assessments. Risk teams should be involved early in the selection process, as well as in
categorizing, prioritizing, and approving AI initiatives.
4.2 Development
Development includes both third-party AI Tool configuration and internal builds. Tool
Development should begin with a proof of concept and involve stakeholder engagement to
ensure alignment with business objectives. Clear documentation of assumptions,
methodologies, and intended usage is essential to support transparency and future validation
efforts.
AI Tools in development also have risk. The development phase should be treated with as
much care as the production phase, especially if the tool interacts with outside data sources or
can impact other internal models and systems.
• Development Environment Controls
Development, testing, and production environments should be segregated with
appropriate access controls. Version control systems should be mandatory from project
inception to track changes and enable rollback. All AI code should undergo peer review
before advancing to testing, as should security scanning of third-party libraries and
dependencies. Development documentation should include technical specifications, data
dictionaries, model architecture diagrams, and decision logs.
• Development Team Requirements
4. AI Lifecycle Management
Robust controls are a core component of the Management pillar. Controls should be embedded
across the AI lifecycle to ensure safe, transparent, and accountable deployment. The CCRO
recommends a structured approach that includes safeguards at each stage of the model
lifecycle, from initial conception to final usage.
4.1 Selection
AI Risk begins at the selection process. Whether building or buying, companies should have a
structured approach to concept selection with a simple premise at its core: AI should not be
selected purely for the sake of selecting AI. Rather, selection should begin with the three
principles in mind.
1) Decision-Making Capacity. While AI can enhance decision-making through advanced
analytics and enhanced insights, unfettered AI-driven decision-making in high-stakes
environments is extremely risky. Human oversight remains critical.
2) Data Volume, Quality, and Availability. AI’s effectiveness is contingent on the
availability of high-quality datasets with high volume and velocity. Not all markets and
use cases meet the necessary data requirements.
3) AI Is Not Always the Optimal Solution. Many operational efficiencies can be achieved
through simpler automation and rule-based systems. If the objective is to improve
speed and efficiency, alternative solutions may provide results that are faster, safer, and
more cost-effective.
Companies should apply due diligence when selecting third-party AI Tools, including vendor
assessments. Risk teams should be involved early in the selection process, as well as in
categorizing, prioritizing, and approving AI initiatives.
4.2 Development
Development includes both third-party AI Tool configuration and internal builds. Tool
Development should begin with a proof of concept and involve stakeholder engagement to
ensure alignment with business objectives. Clear documentation of assumptions,
methodologies, and intended usage is essential to support transparency and future validation
efforts.
AI Tools in development also have risk. The development phase should be treated with as
much care as the production phase, especially if the tool interacts with outside data sources or
can impact other internal models and systems.
• Development Environment Controls
Development, testing, and production environments should be segregated with
appropriate access controls. Version control systems should be mandatory from project
inception to track changes and enable rollback. All AI code should undergo peer review
before advancing to testing, as should security scanning of third-party libraries and
dependencies. Development documentation should include technical specifications, data
dictionaries, model architecture diagrams, and decision logs.
• Development Team Requirements

















