Model Versioning & Release Controls — Evaluation & Documentation
Model Versioning & Release Controls
EU AI Act Compliance Evaluation & Documentation EU/UK aligned
+ On this page
Key takeaways
- Every model release must be reproducible, auditable, and reversible.
Versioning scheme
- Semantic versioning MAJOR.MINOR.PATCH; tie to dataset/index versions and guardrail configs.
Artifacts & lineage
- Store model binaries, prompts, guardrails, retrieval index, configs, and checksums; immutable manifests.
Environments & gates
- Dev→Test→Staging→Prod with CI/CD gates: unit tests, eval suite pass, security scan, sign-offs.
Change controls
- Change tickets; risk assessment; waiver policy; SoD between author, reviewer, and releaser.
Rollouts & rollback
- Canary and percentage rollouts; real-time metrics; auto-rollback on threshold breach; blue/green indices.
Secrets & keys
- Short-lived tokens; rotation on release; environment-scoped credentials; no secrets in prompts.
Documentation links
- Release notes; model card; eval report; risk register deltas; operator instructions; rollback runbook.
PMM thresholds
- Define KPI deltas allowed; alert routes; freeze on repeated alerts; board visibility for major regressions.
Incidents & CAPA
- Auto-bundle release context; RCA; CAPA actions; learning fed to templates and guardrails.
Retirement & EoL
- Rule to deprecate models; user migration; data deletion; vaulting of artifacts; compliance archive.
Access & SoD
- Role-based access; emergency access with logging; periodic access review; approvals in-tool.
Release checklist
- Artifacts stored; evals passed; approvals signed; rollout plan set; metrics & rollback ready.
© Zen AI Governance UK Ltd • Regulatory Knowledge • v1 05 Nov 2025 • This page is general guidance, not legal advice.