UBC — AI Solutions

Audit — Dynamic Documentation Platform

Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.

Back to library
Standard
Fresh

AI-DLC Master Standard

UBC's AI Development Life Cycle Standard, covering intake, data, model & prompt engineering, evaluation, HITL, deployment, monitoring, and retirement.

Owner: AI Platform DirectorApprover: B. HuseltonVersion: 2.0Updated: 12/12/1969

1. Purpose

Define a repeatable, auditable lifecycle for building and operating AI systems at UBC — voice agents, LLM applications, RAG systems, and classical ML models — with explicit guardrails for patient safety, PHI handling, and model risk.

2. Applicability

All AI systems used by UBC internally or delivered to clients, including third-party foundation models called via API.

3. Alignment

AI-DLC extends SDLC. Every AI project also follows SDLC governance where applicable (change control, secure coding, CI/CD). AI-DLC adds:

  • Ethical review
  • Data provenance & consent
  • Bias & fairness assessment
  • Evaluation (safety, hallucination, guardrails)
  • Human-in-the-Loop (HITL) sign-off
  • Model registry and drift monitoring
  • Model retirement

4. Lifecycle Phases

#PhaseGoverning SOP
1Use-Case Intake & Ethical ReviewSOP-AIDLC-01
2Data Sourcing, Lineage & PHI HandlingSOP-AIDLC-02
3Dataset Curation, Labeling & Bias AssessmentSOP-AIDLC-03
4Model / Prompt Design & GuardrailsSOP-AIDLC-04
5Evaluation (accuracy, hallucination, safety, red-team)SOP-AIDLC-05
6Human-in-the-Loop Review & Sign-offSOP-AIDLC-06
7Deployment, Canary & Model RegistrySOP-AIDLC-07
8Monitoring, Drift & Feedback LoopSOP-AIDLC-08
9Incident, Rollback & RetirementSOP-AIDLC-09

5. Model Risk Tiers

TierDescriptionGovernance
Tier 1Patient-facing, autonomous decisionsExecutive approval, quarterly review
Tier 2Assists human decisions on PHIHITL required, monthly review
Tier 3Internal productivity, no PHIStandard review

6. Records

Model cards, evaluation reports, HITL sign-offs, and drift dashboards are controlled documents.

7. Alignment

Maps to NIST AI RMF, EU AI Act (limited-risk category), and ISO/IEC 42001:2023 AIMS.

Suggested by AI
Prepare ISO/IEC 42001 pre-assessment
Ready-state review recommended in Q1 2027.
Frameworks
AI Governance
ISO 9001
CMMI-DEV
HIPAA
GDPR