Please briefly describe your organization’s decision-making process for deploying an AI model or system including: who has decision authority; what evidence and criteria are required (e.g., performance, safety/security, robustness, fairness, privacy, compliance, independent external testing, evaluation, validation and verification (TEVV) or assurance); contextual caveats or limitations required in interpreting risk evaluation metric results; what approvals/sign-offs are needed; and what safeguards (e.g., mitigations, monitoring, or phased release) must be in place to move into deployment.
Definition of Approval-Process including mandatory information, e.g. Data Flow Diagram, Terms of use, Data Protection Agreement, Description of AI purpose and Data Categories, AI-Subjects (data subjects), Risk Classification based on EU-AI-Act, AI-Impact Assessment. To have information about performance, safety/security, robustness, fairness, privacy, compliance, independent external testing, evaluation, validation and verification (TEVV) or assurance would be valuable, but is currently not available. One receives hardly any information about this from the providers. Safeguards are actually monitoring measures. Definition of clear roles and responsible, e.g. AI-Owner, Approval is part of the management.