workflow
Quarterly Third-Party AI Evaluation Cycle
Each quarterly instance runs against the existing Control item for independent third-party AI evaluation (framework aiuc-1 + iso-42001 + eu-ai-act; domains ai_governance; frequency quarterly; control_owner AI Product Lead) — the run enriches that Control's execution history and is its evidence of operation, it never creates a duplicate Control; the one record it does create is a per-quarter Audit item (audit_type: it_audit) for the evaluator engagement. The decision-aware cycle confirms the quarter's in-scope systems and risk taxonomy, engages an independent evaluator with the test plan, categories, and pass thresholds fixed in advance, provisions contained test access, triages every finding by category and severity against the tested control, routes failed thresholds through remediation and evaluator retest, gates acceptance of the evaluator report, publishes the accepted evidence (trust-portal summary, customer-facing attestation, evidence register), and tunes guardrails from the findings. In scope: every in-scope AI system and agent under the AIUC-1 program and its six mandatory third-party test categories (B001 adversarial robustness, C010 harmful outputs, C011 out-of-scope outputs, C012 agent-specific risk, D002 hallucinations, D004 tool calls). Out of scope: internal red-teaming, pre-release model evaluation, and vendor AI due diligence, which run in their own workflows. It hands off only to the next quarterly run of itself, seeding it with the open carry-forward finding Issues that the publish-evidence-and-tune-guardrails step links to the anchor Control.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- ai-governance
- lineOfDefense
- operate
Details
- teams
- ai-governance
- procurement
- domains
- controls
- standards
- nist-ai-tevv-athlon
- aiuc-1
- iso-42001
- eu-ai-act
- sourceTemplateId
- workflow-library:controls-quarterly-third-party-ai-evaluation-cycle
- releaseId
- sha256:e542a1851c8c176ba2d527bcdd1e574e8c9b9b5ee51fbbb9ca5a86307c7b2d84
- canonicalUrl
- https://workflow-library.com/all/?w=controls-quarterly-third-party-ai-evaluation-cycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-AI-21
- UC-AI-18
- UC-AI-20
- UC-AI-19
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:e542a1851c8c176ba2d527bcdd1e574e8c9b9b5ee51fbbb9ca5a86307c7b2d84
Connections
- Quarterly Third-Party AI Evaluation Cycle operates UC-AI-21 — Commission independent third-party AI evaluations on a quarterly cadence
- Quarterly Third-Party AI Evaluation Cycle tests UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse
- Quarterly Third-Party AI Evaluation Cycle tests UC-AI-20 — Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs
- Quarterly Third-Party AI Evaluation Cycle tests UC-AI-19 — Constrain agent actions and tool use to authorized scope