GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-010 AI Model Registry and Versioning

Tier 2+AIProviderGPAI Model ProviderManaged Service Provider

Description

A model registry tracks all ML models in development and production. Each registry entry includes: model name, version identifier, framework and library versions, training dataset reference (name and version), training date, evaluation metrics at registration, current deployment status, and owning team. Model artefacts (weights, configs) are stored in version-controlled storage. Promotion from development to production requires a recorded registry entry. Retired models are marked as deprecated, not deleted.

Rationale

Model versioning is not covered at the operational level by NIST AI RMF, ISO 42001, or the EU AI Act. Without a registry, production models cannot be traced to their training data or evaluation results, a prerequisite for debugging, incident response, and audit.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerecommendedsatisfied by provider

The registry is the provider's. The deployer records the model versions in production against the AIG-003 inventory entry and the BCM-010 continuity entry and takes version and change notices under the AIG-032 agreement.

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerecommendedsatisfied by provider

The registry is the provider's. The deployer records the model versions in production against the AIG-003 inventory entry and the BCM-010 continuity entry and takes version and change notices under the AIG-032 agreement.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (20)

DSP-23Data Integrity Checkinformative
MDS-03Model Documentationinformative
MDS-08Model Integrity Checksinformative
MDS-09Model Signing/Ownership Verificationinformative
STA-09Service Bill of Material (BOM)informative
EU-AI-Art.11.1Technical Documentation — Preparation and Maintenanceinformative
A.4.3Data resourcesinformative
A.4.4Tooling resourcesinformative
A.6.2.3Documentation of AI system design and developmentinformative
A.6.2.5AI system deploymentinformative
AML.M0001Limit Model Artifact Releaseinformative
AML.M0005Control Access to AI Models and Data at Restinformative
AML.M0014Verify AI Artifactsinformative
AML.M0023AI Bill of Materialsfull
GV-1.6-003AI System Inventory | GV-1.6-003informative
GV-6.2-005Third-Party Failure Contingency Processes | GV-6.2-005informative
MG-3.2-002Pre-Trained Model Monitoring | MG-3.2-002full
MS-2.5-002AI System Validity and Reliability | MS-2.5-002informative
GOVERN 1.6AI System Inventoryinformative
LLM04Supply Chaininformative

Evidence (2)

tool_outputtechnicalautomated

Model registry export from MLOps platform (e.g. MLflow, Weights & Biases, SageMaker Model Registry) listing all registered models with version identifiers, training dataset references, evaluation metrics at registration, and current deployment status.

Example: MLflow Model Registry API export (JSON, dated 2026-04-20) showing 14 registered models including name, version, training dataset name/version, evaluation metrics, stage (Staging/Production/Archived), and owning team tag

Test: Query the model registry API or export the full registry. Verify: (1) every production model endpoint corresponds to a registry entry, (2) each entry contains model name, version ID, training dataset reference, evaluation metrics at registration time, current stage, and owning team, (3) no production endpoint lacks a registry entry, (4) retired models are marked Archived rather than deleted, (5) model artefact storage path is recorded and accessible.

recorddocumentmanual

Model promotion approval record for a recent model version, confirming that promotion from development/staging to production required a completed registry entry and named approver sign-off.

Example: Model promotion request for fraud-detector v5.2 (Jira AI-1187): registry entry verified by ML Ops lead, metrics reviewed, and Production stage transition approved by Head of ML on 2026-02-14

Test: Request promotion records for the two most recent model version promotions. Verify: (1) registry entry was created before promotion was approved, (2) training dataset reference is included in the registry entry, (3) a named approver signed off promotion, (4) the promotion event is timestamped in the registry audit log.

Questions (3)

boolean

Does your organisation maintain a model registry that tracks all ML models in development and production?

A model registry is the prerequisite for tracing production models to their training data and evaluation results, essential for incident response, audit, and debugging. Net-new control: not addressed at this operational level by NIST AI RMF, ISO 42001, or the EU AI Act.

multi

Which of the following are recorded in your model registry for each entry?

Model name and version identifierFramework and library versionsTraining dataset name and versionEvaluation metrics at registration timeCurrent deployment status (development / staging / production / archived)Owning teamNone of the above

All six fields should be present. Missing training dataset references or evaluation metrics at registration time are the most common gaps: they prevent traceability between production behaviour and training decisions.

boolean

Is a completed model registry entry required before a model can be promoted from staging to production?

A mandatory promotion gate ensures the registry accurately reflects what is running in production. Registries that are populated after deployment rather than as a gate provide much weaker auditability.