Skip to content
arrow_back
Annex A 6.2.5psychologyISO/IEC 42001:2023

AI System Deployment

Before an AI system goes live, write down how it will be deployed and confirm that the conditions for a safe go-live have actually been met.

record_voice_over

Plain language

Deployment means moving an AI system out of testing and into real use where it affects real people. This control says you need two things first: a written plan for how the go-live will happen (steps, who does what, how to roll back if it goes wrong) and a check that the prerequisites set earlier in the project, such as accuracy targets, sign-offs and access controls, are genuinely in place. Going live without these is how an AI system ends up making live decisions it was never cleared to make.

Framework

ISO/IEC 42001:2023

Control effect

Preventative

Classifications

N/A

Official last update

01 Dec 2023

Control Stack last updated

19 June 2026

Official control statement

The organisation shall document a deployment plan and ensure that appropriate requirements are met prior to deployment.
psychologyISO/IEC 42001:2023Annex A 6.2.5
priority_high

Why it matters

If an AI system goes live without a documented plan and a check that its prerequisites are met, it can start making real decisions it was never validated for, for example a credit or eligibility model running in production on the wrong configuration and wrongly declining a cohort of applicants. The organisation may then have no rollback path and no record of who authorised the go-live, leaving it exposed to an OAIC complaint and forced to withdraw the system mid-operation. Affected people experience the harm before anyone notices the deployment skipped its checks.

settings

Operational notes

Treat the deployment plan as a living document tied to each release, not a one-off written at the start of the project; refresh it whenever the system, its configuration, the data it uses or its operating environment changes materially. Keep the pre-deployment requirements as an explicit checklist so the go-live decision is a recorded yes/no against named conditions rather than a verbal nod. Hold the dated sign-off and the completed checklist together so that for any version running in production you can show what was confirmed and by whom before it went live.

build

Implementation tips

  • Have the person leading the AI project write a short deployment plan before go-live that lists the steps in order, names who carries out each one, and spells out how to back the system out if it misbehaves. Keep it specific to this system rather than reusing a generic template.
  • Turn the requirements set earlier in the project into an explicit pre-deployment checklist, for example accuracy and bias thresholds met, access controls configured, and monitoring switched on, and have someone tick each item off against evidence rather than from memory before anyone presses go.
  • Aska named accountable owner to date and sign off the deployment only once the checklist is complete, so there is always a record of who authorised the system to run on real users
  • Release into production in a controlled way where you can, such as a pilot, a limited user group or a staged rollout, and watch that the system behaves as it did in testing before opening it up fully.
  • Before flipping the switch, confirm the production environment actually matches what was tested by checking the model version, configuration settings and the data sources it connects to, so the live system is the one that was approved and not a drifted copy.
fact_check

Audit / evidence tips

  • AskRequest the documented deployment plan for a named AI system that has gone live.GoodThe deployment plan lists ordered go-live steps with named owners and a clear rollback procedure for the system that was deployed.
  • AskAsk for the completed pre-deployment requirements checklist for that system.GoodEvery listed prerequisite is recorded as met, with evidence, and dated before the system went into production.
  • AskRequest the deployment authorisation or sign-off record for the go-live.GoodA named authoriser signed and dated the approval to deploy, on or before the go-live date.
  • AskSpeak with the person who ran the deployment about how they confirmed the system was ready.GoodThe deployer describes following the written plan and confirming each checklist item before releasing the system.
  • AskCompare the production configuration against what was tested and approved.GoodThe production configuration matches the tested and approved baseline, with any differences documented and authorised.
link

Cross-framework mappings

How Annex A 6.2.5 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(2)expand_less
Annex A 8.8Annex A 6.2.5 requires a deployment plan and verification that appropriate requirements are met prior to deploying an AI system
Annex A 8.9Annex A 6.2.5 requires a documented AI deployment plan and confirmation that required conditions are satisfied before deploying an AI system

ASD ISM

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
ISM-0912Annex A 6.2.5 requires the organisation to document an AI system deployment plan and verify prerequisites are met before deployment

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all A.6 AI system life cycle controls, or browse the full ISO/IEC 42001:2023 library.

psychology

Want to implement this AI control?

Mindset Cyber runs PECB-accredited ISO/IEC 42001 training that maps directly to the AI controls in this library.

Mapping detail

Mapping

Direction

Controls