The pilot ends. The checking should not.
- For
- Agency · MGA
- Evidence
- Authored editorial guidance — what this label means
- Sources reviewed
- 2026-09-17
- Review cycle
- Every 90 days, or sooner when a source changes
- Published
- 2026-09-17T14:18-05:00
An adoption decision applies to a particular task, configuration, and set of observed conditions. Keep that decision visible after launch so the team can recognize when the workflow has moved beyond what was approved.
NIST's AI Risk Management Framework calls for monitoring production behavior, tracking emerging risks, and maintaining post-deployment plans that include incident response, recovery, and change management (NIST AI RMF Core). The operating routine below is a proposed adaptation for an agency or MGA, not a prescribed regulatory schedule.
Record the approved task, product or model version where available, settings, connected systems, allowed users, and review requirements. Capture relevant vendor notices rather than relying on staff to remember what changed.
For each review period, record processed units, reviewed units, identified defects, critical defects, manual fallbacks, and unresolved issues. State how the reviewed work was selected. Do not present a handpicked exception sample as the error rate for all production.
A new line of business, carrier document layout, account type, integration, prompt, or model version should prompt a review of the approved boundary. The appropriate response may be a limited retest, additional review, or a pause.
The central question is whether the existing evidence still supports the intended use. Do not assume a vendor release makes the workflow better for every task, and do not assume every minor change requires an entirely new evaluation.
Name the person who can stop use and the person who can authorize restart. Keep a manual process available for essential work, with clear handling of outputs already in progress.
For an incident, preserve the relevant evidence in the approved restricted system, identify affected outputs, and follow the organization's existing security, client-service, legal, and insurance escalation processes as applicable. NIST recommends recording errors, near misses, and negative impacts and conducting after-action assessments (NIST Generative AI Profile).
Record the cause as confirmed, suspected, or unknown. Document the change made, the retest performed, and the authority for restart. A corrected individual file is not necessarily a corrected workflow.
Choose a review cadence proportionate to the task and its consequences, and revisit it when volume, staffing, or scope changes. The checklist is a reminder to make a decision, not a substitute for the decision itself.
Next: Use the incident and change log and keep the approved AI use register current.
Make the next AI decision with better evidence.
Join the weekly Renewal Report for source-backed developments, practical checks, and clear limits on what is known.
Get the weekly reportOne email a week. Unsubscribe at any time.