Policies across the AI life cycle, and use case assessment
Policies are how intent becomes something an organization can be held to. Without them a program cannot be audited, cannot be inherited when the people who built it leave, and cannot be enforced against anyone who ignores it.
Why this matters for the exam
Policies are how intent becomes something an organization can be held to. Without them a program cannot be audited, cannot be inherited when the people who built it leave, and cannot be enforced against anyone who ignores it.
What you need to know
The life-cycle topic walked the seven stages of an AI system's life, from planning to decommissioning. This one is about what has to be written down to cover them.
Policies and procedures
The two words name different documents. A policy states what the organization requires and why. It is the document leadership approves and the one an auditor asks for. A procedure states how someone carries that requirement out, step by step.
A policy saying every high-risk system needs human oversight does nothing on its own. The procedure tells a named person what to check, when to check it, and what to do when the check fails.
The nine life-cycle policy areas
Establishing AI governance strategy means creating and implementing policies for oversight and accountability across every stage of an AI system's life. Which areas apply depends on whether the organization develops AI, deploys it, or both. The list the Body of Knowledge gives, in its own wording, is:
- Use case assessment
- Risk management
- Ethics by design
- Data acquisition and use
- Model and system development
- Training and testing
- Deployment and monitoring
- Documentation and reporting
- Incident management
How the areas sit on the stages
Stages say when work happens. Policy areas say what has to be written down for it. Most areas attach to a particular stage. Three are continuous: risk management, documentation and reporting, and incident management. The obligation applies at every point in the system's life. The diagram shows them running the full length of the timeline.
Risk management, documentation and reporting, and incident management apply at every point in a system's life rather than at one stage of it.
| Policy area | Where it applies |
|---|---|
| Use case assessment | Starts before stage 1, and repeats. It decides whether the project begins, and is revisited as the system changes. |
| Risk management | Continuous. The EU AI Act calls it "a continuous iterative process planned and run throughout the entire lifecycle" of a high-risk system. |
| Ethics by design | Embedded from the outset, and revisited before release. |
| Data acquisition and use | Stage 2: the rights, quality and provenance of the data used to build the system. |
| Model and system development | Stage 3: how models are selected, built and documented. |
| Training and testing | Stages 3 and 4: testing for bias, accuracy and fairness. |
| Deployment and monitoring | Stages 5 and 6: release readiness, feedback channels, and tracking performance over time. |
| Documentation and reporting | Continuous. Records that establish compliance at every stage. Where the law requires it, logs are kept for the lifetime of the system: the EU AI Act imposes that on high-risk systems, with a separate retention duty of at least six months. |
| Incident management | Continuous. Detecting, containing, remediating and notifying, at any point in the system's life. |
Nothing in the list is named for decommissioning, the seventh stage, and that stage is still governed. The continuous areas cover it. Records are retained for as long as the retention policy requires, including after the system is switched off.
Ethics by design appears at the outset of the list because that is where the work starts. It continues through data acquisition and is re-reviewed at deployment. Fairness controls belong at those points rather than at a final gate before launch, since by launch the choices that create unfairness have already been made. The responsible-AI principles topic in I.A covers the idea itself.
Use case assessment: the one that comes first
Use case assessment runs before any work on a system begins. It decides whether the project starts at all.
A use case assessment is a structured process for evaluating the viability, risks and ethical implications of applying AI to a specific problem. Its goal is to make sure AI is developed and deployed responsibly, effectively and in line with the regulation that applies. It can end a project as well as approve one.
The assessment recurs at several points:
- Before implementation, to confirm strategic alignment, feasibility and risk.
- Early in the life cycle, because categorizing the use case is what everything else is built on.
- For any new AI initiative, and especially a high-risk or significant-impact one.
- Throughout the life cycle, through ongoing risk reviews and governance checkpoints as risk and performance change.
- Continuously, for regulatory compliance.
The last two entries are what make it recurring rather than a one-off gate before the project starts.
Building a system. Take an AI assisting cancer diagnosis from medical images. Assessment during design would cover:
- False positives and false negatives, which can cost a life here in a way they do not in most systems.
- Bias from training data that underrepresents some patients.
- The security of protected health information.
- Human oversight, since a radiologist makes the final call.
Buying a system. For an off-the-shelf sentiment-analysis tool, assessment before integration would look at the vendor's governance practices, its transparency, how the tool performs on data resembling yours, and the risk of a system whose internal logic you cannot inspect.
Whichever route, the documentation policy area decides what gets handed over. A model card is a short structured summary of a model's intended purpose, performance and known limitations. Together with the instructions for use, it lets the next party operate the system safely. Domain III covers the documentation set in full.
Next up: the policies an organization already has, and what AI adds to each of them.
Remember
- A policy states what is required and why. A procedure states how it is carried out, step by step.
- The nine life-cycle policy areas: use case assessment, risk management, ethics by design, data acquisition and use, model and system development, training and testing, deployment and monitoring, documentation and reporting, and incident management.
- Risk management, documentation and reporting, and incident management are continuous. They apply at every stage rather than attaching to one.
- Ethics by design starts at design and data acquisition, and is re-reviewed at deployment.
- A use case assessment evaluates the viability, risks and ethical implications of applying AI to a problem, and it can end a project as well as approve one.
- It runs before implementation and then continuously as risk and performance change.
Practise this topic
Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.
Previous: The AI development life cycle: from planning to decommissioning
Next: Evaluating and updating existing policies for AI
Back to the AIGP study guide.
AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.