GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-011 AI System Decommissioning

Tier 2+AIProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented decommissioning procedure exists for retiring AI systems. The procedure covers: notification to affected users and operators, data deletion or retention consistent with the organisation's data retention policy, archival of technical documentation and evaluation records for the required retention period, and verification that automated pipelines or downstream integrations have been removed or redirected. Decommissioning is logged and signed off by the system owner.

Rationale

Retired AI systems that remain partially active (orphaned model endpoints, residual data pipelines) create unmonitored risk; decommissioning must be a controlled, auditable process.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (4)

GV-1.7-002AI System Decommissioning Processes | GV-1.7-002partial
MG-2.4-001AI System Deactivation and Override Mechanisms | MG-2.4-001full
GOVERN 1.7AI System Decommissioning Processesfull
MANAGE 4.1Post-Deployment AI System Monitoringpartial

Evidence (3)

recorddocumentmanual

Completed AI system decommissioning record for a recently retired system, documenting user notification, data deletion or retention actions, pipeline removal verification, and system owner sign-off.

Example: Decommissioning Record · Legacy Sentiment Classifier v1 (Confluence), dated 2025-12-15, showing user notification sent, model endpoint terminated, training data retained per data retention schedule, pipeline integrations confirmed removed, signed by AI Product Owner

Test: Request the decommissioning record for the most recently retired AI system. Verify: (1) affected users or operators were notified, (2) data deletion or retention decisions are recorded and consistent with the retention policy, (3) technical documentation and evaluation records are archived for the required period, (4) downstream pipeline integrations are confirmed removed (reference to infrastructure change record), (5) system owner sign-off is present and dated.

policydocumentmanual

AI system decommissioning procedure defining the required steps, notification requirements, data handling obligations, and retention periods for technical documentation of retired AI systems.

Example: AI System Lifecycle Policy · Decommissioning Section v1.0 (Confluence), covering notification timeline, data deletion workflow, documentation archival retention period (minimum 5 years), and owner sign-off requirement

Test: Request the decommissioning procedure. Verify: (1) procedure covers notification, data handling, documentation archival, and pipeline removal steps, (2) retention period for archived documentation is stated and meets regulatory minimums, (3) sign-off requirement is specified, (4) procedure applies to both internally developed and third-party AI systems.

tool_outputtechnicalautomated

Infrastructure and pipeline scan output for a decommissioned AI system showing that its endpoints, jobs and downstream integrations are absent.

Example: Decommission verification scan, AIG-DECOM-2026-03 (churn-scoring v1), 2026-06-30: 0 serving endpoints, 0 scheduled training jobs, 0 inbound integrations, 2 archived model artefacts retained under the retention schedule

Test: Run an infrastructure and pipeline scan scoped to the systems marked decommissioned in the AI system inventory. Verify: (1) no serving endpoint for a decommissioned system answers, (2) no scheduled training, evaluation or feature pipeline for it remains enabled, (3) no downstream service still calls it, (4) artefacts still present resolve to the retention the decommissioning record states rather than to an omission, (5) the scan is dated after the decommissioning date recorded for the system.

Questions (2)

boolean

Does your organisation have a documented procedure for decommissioning AI systems?

Retired AI systems that remain partially active (orphaned model endpoints, residual data pipelines) create unmonitored risk. Decommissioning should be a controlled, auditable process with system owner sign-off.

multi

Which of the following steps does your AI system decommissioning procedure require?

Notification to affected users and operatorsData deletion or retention consistent with the data retention policyArchival of technical documentation and evaluation recordsVerification that automated pipelines and downstream integrations have been removedSystem owner sign-offNone of the above

All five steps should be present. The most commonly missed is verification of downstream pipeline removal. Orphaned integrations calling decommissioned endpoints are a recurring production incident pattern.