AI Deployment RACI - Intake to Decommission
In the Acme Q1 2026 incident-response war room, the Chief Risk Officer opens the meeting with a single question. "Acme.ServiceAssist v1.0 has been hallucinating policy answers for three weeks because the RAG corpus drifted. Who is Accountable for the post-market monitoring on that system?" The VP of Customer Operations points at the VP of AI Engineering. The VP of AI Engineering points back. The Head of MRM has a different name, and the AI Compliance Officer has a fourth. The intake form lists the business sponsor. The model card lists the data science lead. The CE marking declaration lists the AI Compliance Officer as the signing officer. The Article 71 EU database entry lists the legal entity, not a person. Four artifacts. Four different names. Zero Accountables on the operate-and-monitor stage. The corpus drift incident now becomes a governance incident, because the firm cannot tell the supervisory authority, within the 15-day Article 73 clock, who owns the monitoring failure that produced the harm. This lesson is the L4 leadership-tier framework that prevents that war-room moment: the eight-stage AI deployment lifecycle from intake to decommission, the twelve-role RACI matrix that lives inside the AI Deployment Standard, the tier-1 board-AI-subcommittee routing, the four common 2026 RACI failures, and the Acme worked example showing the full 12x8 matrix walked through the ServiceAssist v1.0 build and the LoanScoreClassic v3 retirement.
The Eight-Stage AI Deployment Lifecycle
The mature 2026 AI Deployment Standard defines eight discrete lifecycle stages, each with named artifacts, named gate criteria, and a single Accountable. The eight stages are not optional; every AI system the firm deploys traverses all eight, even when stages compress (a low-risk internal-only system may complete intake-through-go-live in three weeks; an Annex III consumer-direct system typically runs nine to fifteen months). The lifecycle is the operating spine of ISO 42001 Annex A.4 AI system life cycle and the implementation surface of NIST AI RMF Map and Manage functions.
- Stage 1 - Intake and use-case definition. The business sponsor submits the AI intake form (the lesson 019 schema: business problem, proposed AI capability, data sources, user population, decision authority, expected volume, anticipated benefit, risk hypothesis). The shadow-AI scan (lesson 021) verifies the use case is not already running in stealth. The intake stage triggers the Article 25 status determination: is the firm acting as provider, deployer, importer, distributor, or product manufacturer for this system. Stage exit: AI Intake Form v1.0 accepted by the AI Compliance Officer with the Article 25 status declared.
- Stage 2 - Pre-deployment risk classification. The classification team maps the use case against Article 5 (prohibited, kill the use case), Article 6 + Annex III (high-risk, full FRIA path), Article 50 (limited-risk transparency obligations), and Article 4 (minimal-risk literacy applies). Where a foundation model is in scope, the Article 51 GPAI status of the upstream provider is recorded. Where the firm itself trains a model, the Article 51 GPAI threshold check (the 10^25 FLOPs computational threshold) is run. Stage exit: Risk Classification Memo with the named tier and the cross-references to Annex III §1-§8 (or the explicit non-Annex-III justification).
- Stage 3 - FRIA and DPIA. For high-risk deployer systems, the Article 27 Fundamental Rights Impact Assessment is completed per the lesson 044-048 framework: the eight FRIA elements, the affected-persons consultation, the mitigations register, and the notification to the national supervisory authority. Where personal data is in scope, the GDPR Article 35 Data Protection Impact Assessment runs in parallel (typically a joint FRIA + DPIA document with separable sections so each can be produced to the DPA or the AI authority on demand). Stage exit: Signed FRIA + DPIA with the named mitigations and the notification reference number.
- Stage 4. Build / select, IMV, and red-team. The data science and ML engineering teams build (or select) the model, produce the model card draft, generate the ML Bill of Materials (training data lineage, base-model provenance, library dependencies, fine-tuning datasets), commission the Independent Model Validation report under the SR 11-7 effective challenge principle, and run the red-team campaign (the lessons 050-068 program: OWASP LLM Top 10, MITRE ATLAS, jailbreak suite, fairness disparity test, agentic-system policy-envelope test where in scope). Stage exit: Model Card v1.0 + ML-BoM + IMV report (with the validator's signed sign-off) + Red-Team Findings with the mitigation status of each high-severity finding.
- Stage 5 - Conformity assessment, CE marking, Article 71 registration. For high-risk Annex III systems where the firm is provider, the Annex IV Technical Documentation File is assembled (the nine elements per lesson 050: system description, design, monitoring, performance, conformity, risk management, lifecycle, post-market, declaration). The Article 47 EU Declaration of Conformity is signed by the named signing officer with the registered authority. The CE marking is affixed. The Article 71 EU AI Database registration is filed with the named legal entity and the system reference. For deployer-only systems, this stage compresses to the Article 26 deployer-obligations checklist and the documentation of the upstream provider's CE marking. Stage exit: CE marking + Article 47 declaration on file + Article 71 registration entry + Article 26 deployer-checklist.
- Stage 6 - Go-live approval. The AI Governance Committee reviews the full lifecycle dossier, intake form, classification memo, FRIA, model card, ML-BoM, IMV report, red-team findings, CE marking, Article 71 registration, and votes go/no-go. For tier-1 systems (any Annex III consumer-direct, any Tier 4 autonomy, any aggregate Article 99 worst-case exposure above the AIRA-named threshold), the AIGC vote is conditional on a subsequent board AI subcommittee approval. The go-live memo names the deployer-side Article 26 obligations (instructions-for-use compliance, human-oversight personnel competence per Article 26(3), accuracy of input data per Article 26(4), monitoring per Article 26(5), retention of automatically-generated logs per Article 26(6)) and confirms the named accountable executive on each. Stage exit: AIGC go-live memo with named conditions and board AI subcommittee ratification where required.
- Stage 7 - Operate and monitor. The deployed system runs under the Article 26(5) monitoring obligation (the deployer monitors the operation of the high-risk system in accordance with the instructions for use), feeds the Article 72 post-market monitoring system (the provider's post-market monitoring plan plus deployer-side telemetry), and is tracked against the drift KPI register (input-drift, output-drift, fairness-disparity drift, accuracy drift, latency drift, abuse-rate drift). Article 73 serious-incident triggers are armed, any serious incident or widespread infringement is reported within 15 days of becoming aware. Quarterly the system goes through the AI Inventory Refresh (lesson 022) with the model card, the ML-BoM, the KPI dashboard, and the open-findings register attached. Stage exit (recurring): each quarterly refresh produces a system-level Operate Report v.Q for the AI Compliance Officer.
- Stage 8 - Substantial-modification trigger / retire / decommission. Article 43(4) defines substantial modification as a change to the system that affects the system's compliance with the requirements of the Act or modifies the intended purpose. Any change that crosses the threshold (model swap from foundation-model A to foundation-model B, training-data refresh that materially shifts distribution, autonomy-tier transition from Tier 3 to Tier 4, scope expansion to a new Annex III category, addition of a consumer-direct decision authority) triggers a re-entry into Stage 2 with the corresponding artifact refresh. Where the modification is large enough to be a new system, the lifecycle restarts at Stage 1. Where the system is retired, the decommission package is assembled: final post-market monitoring report, Article 26(6) log-retention disposition (the deployer keeps automatically-generated logs for at least six months, longer where sectoral retention applies), Article 73 incident-history closeout, Article 71 database deregistration where applicable, customer notification where consumer-facing, internal inventory closeout. The decommission Accountable signs the closeout memo. Stage exit: Decommission Memo with the named Accountable signature, retention-period clock started, inventory record archived (not deleted) for the retention horizon.
Each stage is a discrete gate; no system advances without the prior stage's exit artifact on file. The AI Compliance Officer maintains the stage-status register for every system in the inventory. The regulator-facing demonstration is that the firm can, for any system in production today, produce the Stage 1-7 artifacts and, for any decommissioned system, produce the Stage 1-8 artifacts plus the retention-period record.
The Twelve Roles of the RACI
The 2026 mature RACI runs twelve roles. Fewer than ten under-specifies accountability (a single role conflates first-line build and second-line validation, breaching SR 11-7 effective-challenge independence). More than fifteen over-specifies and creates the "two Accountables" failure mode. The twelve roles, with the named first/second/third-line affiliation and the EU AI Act / ISO 42001 / SR 11-7 grounding:
- Model Owner (First Line). The named executive who owns the system end-to-end. Has primary P&L accountability, owns the Article 26 deployer-obligations sign-off where the firm is deployer, owns the Article 16 provider-obligations sign-off where the firm is provider. Typically a Senior Director or VP within the business line that operates the system. The Model Owner is the Accountable on Stage 6 go-live for non-tier-1 systems and remains the Accountable on Stage 7 operate-and-monitor. Maps to NIST AI RMF Govern 2.1 (roles and responsibilities), ISO 42001 A.3 (organizational roles).
- Business Sponsor (First Line). The named executive who originated the use case and funds the program. Owns the business case, the value-realization measurement, and the strategic alignment. Often the Model Owner's superior or a peer-executive in the consuming business unit. The Business Sponsor is Accountable on Stage 1 intake (the use case is theirs) and the Stage 8 retire decision where the system is retired for business reasons rather than risk reasons.
- Data Science Lead (First Line). The senior data scientist who owns model design, training methodology, evaluation methodology, and the model card. Reports into the AI Engineering or Data Science organization. Owns the Stage 4 build artifacts (model card, training notebooks, evaluation suite). The Data Science Lead is the Responsible on Stage 4 build, the Consulted on Stage 3 FRIA (fairness and accuracy modeling inputs), and the Consulted on Stage 7 operate (drift-KPI design).
- ML Engineering (First Line). The senior ML engineer who owns productionization: serving infrastructure, the ML Bill of Materials, the CI/CD pipeline, the monitoring telemetry, the rollback capability. Owns the Stage 4 ML-BoM artifact and the Stage 7 telemetry stack. The ML Engineering role is the Responsible on Stage 4 deployment engineering and Responsible on Stage 7 telemetry.
- AI Compliance Officer (Second Line). The Second Line of Defense role with named regulatory expertise across the EU AI Act, ISO 42001, NIST AI RMF, sectoral overlays, and the firm's AIRA. Owns the AI Intake Form acceptance, the risk classification, the FRIA quality review, the Article 47 declaration sign-off, the Article 71 registration. The AI Compliance Officer is the Accountable on Stage 2 risk classification, Accountable on Stage 5 conformity assessment, and Consulted (never Responsible) on Stage 4 build to preserve the independence required by SR 11-7 and Article 17(1)(b). The AI Compliance Officer reports to the Chief Risk Officer or the Chief Compliance Officer; never into the build organization.
- Data Protection Officer (Second Line). The GDPR Article 37 DPO where designated, plus the equivalent for non-EU regimes. Owns the DPIA acceptance, the lawful-basis determination, the data-subject rights operationalization, the privacy-by-design review. The DPO is the Accountable on the DPIA component of Stage 3 (the FRIA Accountable is the AI Compliance Officer; the DPIA Accountable is the DPO; the two run in parallel and are reconciled in the joint document). The DPO is Consulted across Stages 4, 5, 6, 7, 8 wherever personal data flows.
- CISO (Second Line). The Chief Information Security Officer or named delegate. Owns the security-architecture review, the credential model (Article 15 cybersecurity for high-risk systems), the incident-response integration with the SOC, the OWASP LLM Top 10 + MITRE ATLAS coverage in the red-team scope. The CISO is Consulted on Stage 3 (security risks in the FRIA), Consulted on Stage 4 (red-team scope), Consulted on Stage 6 (go-live security posture), and Consulted on Stage 7 (incident response). Where the system is a Tier 4 autonomy agent with consumer-direct exposure, the CISO escalates to Responsible on Stage 4 red-team.
- MRM Validator (Second Line). The Model Risk Management validator, independent from the build team, conducting the Independent Model Validation per SR 11-7 effective challenge. Owns the IMV report and the signed sign-off. The MRM Validator is the Responsible on Stage 4 validation (a separate Responsible from the Data Science Lead build Responsible) and Consulted on Stage 6 go-live (the MRM Validator's sign-off is a precondition for the AIGC vote on tier-1 systems). The MRM Validator reports into the Model Risk Management function, never into AI Engineering.
- Internal Audit (Third Line). The Third Line of Defense per the IIA Three Lines Model 2020 and the SR 11-7 audit-independence requirement. Owns the audit of the AI Deployment Standard, the audit of the RACI in operation, the audit of the AIMS controls. Internal Audit is Informed across all eight stages (never Consulted, never Responsible, never Accountable - Consulted compromises independence and creates a self-review threat). Internal Audit's role is to verify the operating effectiveness of the lifecycle, not to participate in it. This is the single most-violated independence rule in 2026 RACIs.
- AI Governance Committee (Cross-Line). The chartered cross-functional committee per the lessons 025-028 framework: chaired by the Chief AI Officer or Chief Risk Officer, with named seats for the CISO, the DPO, the Chief Legal Officer, the Head of MRM, the Chief Data Officer, the business-line representatives, and the secretary. Owns the Stage 6 go-live decision (the AIGC vote is the gate). The AIGC is the Accountable on Stage 6 for non-tier-1 systems and Consulted on tier-1 systems where the board AI subcommittee is the Accountable.
- Board AI Subcommittee (Governance). The committee of the board of directors with chartered oversight of AI, typically a subcommittee of the risk committee or the audit committee, with one independent director designated as the AI subcommittee lead. The Board AI Subcommittee is Accountable on Stage 6 for tier-1 systems, Consulted on the annual AIRA ratification, and Informed on every Article 73 serious incident within five business days of reporting.
- External Assurance (Independent Third Party). The ISO 42001 certification body, the external auditor under sectoral attestation (e.g., SOC 2 + AI extensions, the Big Four advisory firms providing AIMS assurance), the notified body where conformity assessment requires it (e.g., Annex VII third-party conformity for certain high-risk systems where self-assessment is not permitted). External Assurance is Consulted at Stage 5 conformity (notified-body engagement where applicable), Informed at Stage 6 go-live, and Consulted at Stage 7 during periodic surveillance audits. External Assurance never sits inside the lifecycle as Responsible or Accountable; the deployer/provider retains those roles.
Each role has a named individual on each system, not a function-level placeholder. "AI Compliance" is not an Accountable; "Maria Santos, AI Compliance Officer" is. The named-individual rule is what distinguishes a defensible 2026 RACI from a paper artifact. When the regulator asks who is Accountable for Stage 7 monitoring on Acme.ServiceAssist v1.0, the AIGC produces the name within 30 minutes.
The 12x8 RACI Matrix
The full matrix below is the operating instrument of the AI Deployment Standard. Each cell holds one of R (Responsible, does the work), A (Accountable, owns the outcome, exactly one per stage column), C (Consulted, provides input before the work completes), or I (Informed, receives the result after). The Accountable singleton rule is non-negotiable; two Accountables on one stage is the first common 2026 failure mode.
| Role \ Stage | S1 Intake | S2 Classify | S3 FRIA+DPIA | S4 Build+IMV+RT | S5 Conformity | S6 Go-Live | S7 Operate | S8 Retire |
|---|---|---|---|---|---|---|---|---|
| Model Owner | R | R | R | C | C | A* | A | R |
| Business Sponsor | A | C | C | I | I | C | C | A** |
| Data Science Lead | C | C | C | R | C | C | C | C |
| ML Engineering | C | C | I | R | C | C | R | R |
| AI Compliance Officer | R | A | A (FRIA) | C | A | R | R | R |
| DPO | C | C | A (DPIA) | C | C | C | C | C |
| CISO | C | C | C | C / R† | C | C | C | C |
| MRM Validator | I | C | C | R | C | C | C | I |
| Internal Audit | I | I | I | I | I | I | I | I |
| AI Governance Committee | I | C | C | C | C | A* (non-T1) | C | C |
| Board AI Subcommittee | I | I | I | R‡ (T1) | R‡ (T1) | A‡ (T1) | I | I |
| External Assurance | I | I | I | I | C | I | C | I |
Notation. A* = AIGC is Accountable on Stage 6 for non-tier-1 systems; for tier-1 systems the Accountable transfers to the Board AI Subcommittee and the Model Owner becomes Responsible. A** = Business Sponsor is Accountable on Stage 8 when retirement is a business-driven sunset; the Model Owner remains Responsible for the closeout artifacts. R† = CISO escalates from Consulted to Responsible on Stage 4 red-team for Tier 4 autonomy or consumer-direct systems with material safety implications. R‡ / A‡ = Board AI Subcommittee inserts as Responsible on Stages 4-5 (build-validation review and conformity ratification) and Accountable on Stage 6 (go-live) for tier-1 systems, defined as any Annex III consumer-direct system, any Tier 4 autonomy system, or any system with aggregate Article 99 worst-case exposure above the AIRA-named threshold.
Three structural rules anchor the matrix. First, the Accountable column-singleton holds across every stage, one and only one A per column. Second, the AI Compliance Officer never appears as Responsible on Stage 4 build (independence breach, Second Line cannot do the work it later validates). Third, Internal Audit is Informed across all eight stages, never Consulted, never Responsible, never Accountable, any other assignment violates the IIA Three Lines Model 2020 independence requirement and creates a self-review threat the external auditor will flag.
Tier-1 Routing and Common 2026 Failures
The tier-1 systems get additional governance routing. A tier-1 system is any system that meets one or more of: (a) Annex III high-risk category with consumer-direct decision authority; (b) Tier 4 autonomy per the lesson 049 ladder; (c) aggregate Article 99 worst-case penalty exposure above the AIRA-named threshold (typically €25M for a €10B-turnover firm); (d) any system where the firm is provider (versus deployer-only) of an Annex III category. For tier-1, the lifecycle stages 4-6 insert the Board AI Subcommittee as additional Responsible on Stages 4 + 5 (the subcommittee reviews the IMV report and the Annex IV TDF in its scheduled meeting) and Accountable on Stage 6 (the go-live vote is the subcommittee's, not the AIGC's). The AIGC remains Consulted on tier-1 go-live and retains operational ownership of the lifecycle dossier.
The 2026 common RACI failures fall into four patterns, each with a named root cause and a named fix:
- (1) Two Accountables on the same stage, accountability paralysis. The RACI lists the Model Owner and the AI Compliance Officer both as Accountable on Stage 6 go-live, on the theory that "both have to sign off." When an incident occurs, each points at the other. The fix is the Accountable singleton rule, one A per stage. Cross-sign-offs are recorded as the Responsible (the AI Compliance Officer signs the Article 47 declaration as Responsible on Stage 5; the Model Owner is Responsible on the Article 26 deployer-checklist on Stage 6) with the AIGC or the Board AI Subcommittee carrying the single Accountable.
- (2) AI Compliance Officer as Responsible on Stage 4 build, independence breach. The firm staffs the AI Compliance Officer as the lead on the model-card drafting and the red-team coordination because "they understand the regulatory requirements best." The result is that the Second Line is doing the First Line's work, and the same role then sits as Accountable on Stage 5 conformity validating its own output. This breaches SR 11-7 effective challenge, Article 17(1)(b) QMS independence, and the IIA Three Lines Model. The fix is to staff the build with Data Science + ML Engineering as the Responsibles and keep the AI Compliance Officer as Consulted on Stage 4. The AI Compliance Officer is Accountable on Stage 5 conformity, Responsible on the Stage 5 Article 47 declaration sign-off, and the chain holds.
- (3) Internal Audit listed as Consulted, three-lines independence compromised. The RACI lists Internal Audit as Consulted on Stage 3 FRIA or Stage 6 go-live because "we want their perspective." When Internal Audit later audits the AIMS controls, they have participated in setting them, a self-review threat that violates the IIA Standards and the SR 11-7 audit-independence principle. The fix is the categorical rule: Internal Audit is Informed across all eight stages, full stop. The Third Line audits the operating effectiveness of the lifecycle annually; they do not participate in the lifecycle.
- (4) No Accountable for decommission, orphan models persist. The RACI specifies Stages 1-7 but leaves Stage 8 with no named Accountable, on the assumption that "we'll figure it out when we retire something." Three years later, the firm has fourteen models in production that should have been retired, no closeout memos, no log-retention disposition, and a regulator-facing inventory that includes systems no business unit currently sponsors. The fix is to name the Stage 8 Accountable upfront in the RACI: the Business Sponsor for business-driven retirements, the Model Owner for technical retirements (model-card sunset, foundation-model deprecation), the AI Compliance Officer where retirement is risk-driven (red-team finding cannot be remediated; system must be retired). Every system has a named Stage 8 Accountable from Stage 1.
The 2026 supervisory expectation is operational: the AIGC can produce the RACI matrix for any system in the inventory on demand within 30 minutes of a supervisory authority request. This drill is tested by the ISO 42001 Stage 2 auditor (the auditor selects three systems at random and asks for the RACI; if any system takes longer than 30 minutes, a non-conformity is raised against Annex A.3) and by the EU AI Act competent authority in market-surveillance engagements. A 30-minute target sounds generous; in practice it requires that the RACI is held in the AI inventory record alongside the model card, not in a separate document under a separate filing system.
The Six-Section AI Deployment Standard
The RACI lives inside an operating standard, the AI Deployment Standard, which is the firm-level document that the AIMS Manual (lesson 029) references as the implementation surface of Annex A.4 AI system life cycle. The mature 2026 AI Deployment Standard is six sections:
- Section 1 - Purpose. The standard's statement of intent: to define the mandatory eight-stage lifecycle every AI system traverses, the named roles and their accountability boundaries, the gate criteria at each stage, the exception process for compressed lifecycles, and the regulatory grounding (EU AI Act Articles 9, 11, 17, 25, 26, 27, 43, 47, 50, 71, 72, 73; NIST AI RMF Govern + Map + Manage; ISO 42001 A.3 + A.4 + A.5 + A.6; SR 11-7 governance pillar; IIA Three Lines Model 2020).
- Section 2 - Scope. The systems in scope (every AI system in the inventory, regardless of tier; every internally-developed model, every procured third-party AI service, every embedded AI feature in an enterprise application), the systems out of scope (statistical analytics not meeting the AI Act definition; deterministic rule engines without learned components), the entity scope (all legal entities), the geographic scope (all jurisdictions where the firm deploys), and the temporal scope (effective date, transitional arrangements for systems already in production at the standard's adoption).
- Section 3 - Stage definitions. The eight stages defined above with named entry criteria, exit criteria, mandatory artifacts, and target durations. Each stage definition references the underlying article-by-article regulatory grounding (Stage 5 conformity references Article 11 + Annex IV + Article 47 + Article 71; Stage 7 operate references Article 26(5) + Article 72; Stage 8 retire references Article 43(4) substantial modification).
- Section 4 - Role definitions. The twelve roles defined above with named position-level (VP, Senior Director, Officer), line-of-defense affiliation, reporting relationships (the AI Compliance Officer reports to the CRO; the MRM Validator reports to the Head of MRM; the Internal Audit AI lead reports to the CAE), authority boundaries, and independence requirements. The role definitions include the named-individual rule: each role on each system has a named individual, not a function placeholder.
- Section 5 - RACI matrix. The 12x8 matrix above with the tier-1 overlay, the four common-failure rules embedded as standard text, and the named exceptions process for proposing deviations.
- Section 6 - Exception process. The procedure for proposing a RACI deviation on a specific system (e.g., a Stage 4 build where the firm has no internal Data Science Lead because the system is fully vendor-built, the Vendor Account Manager becomes Responsible with the AI Compliance Officer reviewing the vendor's IMV equivalent). Every exception is documented, time-bound, and reviewed at the AIGC; no exception persists more than one quarterly review cycle without renewal. The exception log is part of the AIMS evidence file.
The AI Deployment Standard is signed by the Chief AI Officer (or CRO where AI sits under risk) annually, with the AIGC ratifying each change. The standard is the artifact ISO 42001 Stage 2 auditors and EU AI Act competent authority drills demand first, before the model cards, before the FRIA samples, before the red-team reports, because the standard is the entry point for every other AIMS document.
Acme Worked Example - ServiceAssist v1.0 and LoanScoreClassic v3 Retirement
Acme Inc.'s AI Deployment Standard v2026.Q2 was adopted on April 1, 2026, with the 12x8 RACI as Section 5. Two systems anchor the worked example: Acme.ServiceAssist v1.0 (the customer-service triage agent introduced in lesson 003) and Acme.LoanScoreClassic v3 (a credit-scoring decisioning system retired in Q4 2025 under the new standard).
Acme.ServiceAssist v1.0, Stage-by-stage Accountable trace.
- Stage 1 Intake (Q1 2024). Accountable: Helena Ozdemir, VP Customer Operations (Business Sponsor). Responsible: Maria Santos, AI Compliance Officer (intake form acceptance) + Helena Ozdemir (use case submission). Artifact: AI Intake Form v1.0 with Article 25 status declared deployer-only (foundation model from upstream provider).
- Stage 2 Classification (Q1 2024). Accountable: Maria Santos. Outcome: limited-risk Article 50 transparency obligations (customer interacts with an AI system; disclosure required) + Article 4 literacy applies to agents handling the system. Not high-risk Annex III (informational triage only; no decision authority on credit, employment, or other Annex III categories).
- Stage 3 FRIA/DPIA (Q1-Q2 2024). FRIA not required (not Annex III high-risk). DPIA Accountable: Liam Khoury, DPO. The DPIA covered customer-data flows, transcript retention, and lawful-basis (legitimate interest + opt-out). Signed Q2 2024.
- Stage 4 Build (Q2-Q3 2024). Responsible: Aisha Banerjee, Data Science Lead (model card + evaluation suite) + Carlos Reyes, ML Engineering (ML-BoM + production stack) + Sven Eriksson, MRM Validator (IMV report). Consulted: Maria Santos (regulatory review), Liam Khoury (privacy review), Naveen Patel, CISO (red-team scope review). Artifacts: Model Card v1.0, ML-BoM v1.0, IMV Report (Sven's signed sign-off), Red-Team Findings (12 medium, 0 high, all closed before go-live).
- Stage 5 Conformity (Q3 2024). Accountable: Maria Santos. Article 47 declaration not applicable (limited-risk; no CE marking required for Article 50). Article 50(1) transparency disclosure validated. Article 26 deployer-checklist completed on the upstream provider's CE marking. Article 71 registration not applicable.
- Stage 6 Go-Live (Q4 2024). Accountable: AI Governance Committee (Maria Santos as AIGC secretary recording the vote; chair vote: Priya Anand, Chief AI Officer). Not tier-1 (limited-risk; no Tier 4 autonomy; aggregate exposure below threshold). AIGC vote 8-0 go. Conditions: quarterly KPI review; semi-annual fairness disparity test; six-monthly Article 4 literacy refresh for handling agents.
- Stage 7 Operate (Q4 2024-present). Accountable: Helena Ozdemir (Model Owner, promoted from Stage 1 Business Sponsor role to Stage 7 Model Owner role on go-live). Responsible: Carlos Reyes (telemetry stack), Maria Santos (compliance monitoring). Quarterly Operate Reports v.Q1-Q5 produced. The Q1 2026 RAG-corpus drift incident is the operative example: drift detected in the input-drift KPI on Feb 14, 2026, escalated to Helena Ozdemir as Stage 7 Accountable. The named Accountable is unambiguous; the war-room question "who owns this" has a one-sentence answer.
- Stage 8 Retire (not yet triggered). Designated Accountable for retirement: Helena Ozdemir (business-driven sunset) or Maria Santos (risk-driven retirement). Decommission protocol drafted; not exercised. The Stage 8 Accountable name is recorded in the AI inventory record from Stage 1 onwards, not deferred to retirement day.
Acme.LoanScoreClassic v3, Q4 2025 retirement. LoanScoreClassic v3 was a rule-augmented logistic-regression credit-scoring model launched 2018, transitioned into the AI Deployment Standard scope in 2025 when the firm formalized AI governance. The Q3 2025 review identified that the model's accuracy had degraded materially against the modern challenger model (LoanScoreNeural v1) and the upstream training pipeline used a deprecated feature engineering library that the firm's security team had flagged for end-of-support.
- Stage 8 Accountable. Helena Ozdemir was originally listed as Business Sponsor of LoanScoreClassic, but business ownership had transferred in 2024 to David Park, VP Consumer Credit. David Park is the Stage 8 Accountable on retirement (business-driven sunset, the challenger model has superseded the operational use).
- Decommission protocol. Final post-market monitoring report (Q3 2025 fairness + accuracy + drift summary) signed by Maria Santos. Article 26(6) log retention: automatically-generated logs preserved for six months (the AI Act floor) plus the firm's internal eight-year financial-decisions retention layered on top, net retention to Q4 2033. Article 73 incident-history closeout: zero serious incidents reported across the system's lifetime. Article 71 registration: did not apply (pre-Annex-III period; no registration was filed). Customer notification: not consumer-direct (output reached underwriters who made the decision). Internal inventory closeout: AI inventory record marked Retired-Q4-2025 with the retention horizon set.
- Closeout signature. David Park signed the Stage 8 closeout memo on December 15, 2025. Maria Santos co-signed as Responsible for the conformity-retention disposition. The memo is filed in the AI Deployment Evidence file under the system's retired-systems folder, retrievable on supervisory request through 2033.
- External assurance positive finding. The Q1 2026 ISO 42001 surveillance audit selected LoanScoreClassic v3 as one of two retired-systems samples. The auditor produced the Stage 1-8 artifacts within 22 minutes of request, under the 30-minute target. The audit report cited the closeout as evidence of operating effectiveness of Annex A.4 AI system life cycle, specifically the Stage 8 decommission control.
The two systems together demonstrate the standard's coverage, a live limited-risk system with the Stage 7 Accountable unambiguously named when an incident occurs, and a retired traditional model with the Stage 8 Accountable unambiguously named and the retention clock running on the auditable timeline.
Key Takeaways
- The AI deployment lifecycle is eight stages: intake → classification → FRIA/DPIA → build/IMV/red-team → conformity/CE/Article 71 → AIGC go-live → operate/monitor → substantial-modification or decommission. Every AI system in the inventory traverses all eight, even when stages compress for low-risk systems.
- The 2026 RACI runs twelve roles: Model Owner, Business Sponsor, Data Science Lead, ML Engineering, AI Compliance Officer, DPO, CISO, MRM Validator, Internal Audit, AI Governance Committee, Board AI Subcommittee, External Assurance, with named line-of-defense affiliation and named-individual assignments per system (no function placeholders).
- The Accountable singleton rule is non-negotiable, exactly one A per stage column. The Business Sponsor is A on Stage 1 (and Stage 8 on business-driven retirement); the AI Compliance Officer is A on Stages 2 + 3-FRIA + 5; the DPO is A on Stage 3-DPIA; the AIGC is A on Stage 6 for non-tier-1; the Board AI Subcommittee is A on Stage 6 for tier-1; the Model Owner is A on Stage 7.
- Tier-1 systems (Annex III consumer-direct, Tier 4 autonomy, aggregate Article 99 exposure above AIRA threshold, provider-role on Annex III) insert Board AI Subcommittee as R on Stages 4-5 and A on Stage 6, the AIGC retains operational ownership and becomes C on tier-1 go-live.
- Four common 2026 RACI failures: two Accountables on the same stage (paralysis); AI Compliance Officer Responsible for both build and conformity (Second Line independence breach against SR 11-7 and Article 17); Internal Audit listed as Consulted (Third Line independence breach against the IIA Three Lines Model); no Accountable for decommission (orphan models persist).
- The RACI lives inside the six-section AI Deployment Standard (purpose, scope, stage definitions, role definitions, RACI matrix, exception process), signed by the Chief AI Officer annually and ratified by the AIGC on each change. The standard is the first artifact ISO 42001 Stage 2 auditors and EU AI Act competent authorities request.
- The 2026 supervisory expectation is that the AIGC can produce the RACI for any system on demand within 30 minutes, tested by ISO 42001 surveillance audits and EU AI Act market-surveillance drills. The 30-minute target requires the RACI to be held in the AI inventory record alongside the model card, not in a separate filing system.
- Penalty exposure for RACI failure: Article 99(3) at €15M / 3% of global turnover where ambiguous accountability surfaces in incident response and Article 73 reporting is late or incomplete; the absent or paper RACI is the leadership-failure evidence that escalates the regulator's view of the QMS and increases the penalty multiplier.
Skill.re