AIPolicyTracker
Technical measure Owner: AI system owner Continuous

Post-deployment monitoring and drift detection

Watches a live AI system for falling performance, shifting data, emerging bias and unexpected use, and turns what it sees into corrective action, incident reports and documentation updates.

Duties satisfied
3
done properly, does the work
Duties supported
7
contributes; the duty needs more
Jurisdictions
4
Evidence items
3

How is it implemented?

Each deployed system has a monitoring plan that names the indicators to be tracked, the thresholds that trigger review, the feedback channels open to users and deployers, and who looks at the results and how often. Telemetry from logs, sampled human review of outputs, complaint data and periodic re-testing feed a dashboard or report. When an indicator breaches its threshold the owner opens a ticket, decides whether retraining, rollback, extra oversight or an incident report is needed and records the outcome. Monitoring findings are reviewed at governance meetings and feed the annual refresh of the risk and impact assessments.

Which legal duties does it serve?

Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.

European Union 6 duties

Singapore 1 duty

Colorado (United States) 2 duties

United States 1 duty

What evidence shows it is operating?

Evidence this control produces
EvidenceTypeWhat it shows
Post-market monitoring planProcedure or standard operating processIndicators, thresholds, feedback channels, review cadence and responsibilities for one system.
Monitoring dashboard or periodic monitoring reportMonitoring record
Monitoring review decisionApproval or sign-off recordRecorded decision on retraining, rollback or escalation after a threshold breach.

Owner: AI system owner. Frequency: continuous.

Which risks does it address?

Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.

Which standards clauses does it correspond to?

Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.

Framework references
FrameworkReferenceNoteConfidence
ISO/IEC 42001Clause 9.1; Annex A.6.2.6high
NIST AI RMFMEASURE 3.1, 3.3; MANAGE 4.1high
ISO/IEC 23894Clause 6.6Monitoring and review of AI risks.medium

Cite this record

AIPolicyTracker (2026). “Post-deployment monitoring and drift detection”. https://aipolicytracker.org/controls/post-market-monitoring-and-drift-detection (accessed 24 September 2026). Data licensed CC BY 4.0.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Which legal duties does "Post-deployment monitoring and drift detection" satisfy?
It is recorded as satisfying 3 and supporting 7 duties across European Union, Singapore, Colorado (United States) and United States. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
What evidence shows this control is operating?
Post-market monitoring plan, Monitoring dashboard or periodic monitoring report and Monitoring review decision. Owner: AI system owner. Frequency: continuous.