Chapter 13. Runtime Operation and Monitoring: S8
The concurrent state where most of an AI system’s life is spent, and where IRGF’s central claim is either realized or quietly abandoned.
13.1 Why S8 is a state, not a stage
S8 begins at deployment and continues until retirement. Monitoring is not a phase that follows operation; the two are the same thing observed from different angles. Modeling them separately would reintroduce the periodic assumption the framework exists to remove.
Practically, this means there is no point at which a system is “through” governance. A production system is permanently in S8, permanently generating assurance evidence, and permanently comparable against its approved state.
13.2 What must be observable
Four questions must be answerable continuously for any production AI system. Each maps to a different evidence source.
Table 36. What must be observable
| Question | Evidence source | Failure signal |
|---|---|---|
| Is deployed architecture still what was approved? | Control Plane comparison against ADR | Structural, configuration, integration drift |
| Is the model behaving as evaluated? | Technical evaluation signals, output monitoring | Behavioral drift |
| Are the mapped controls still effective? | Control testing, security tooling | Control effectiveness decay |
| Is it still delivering value? | Outcome metrics against the S1 baseline | Benefit shortfall |
The fourth is the one organizations most often drop. A system that is technically sound, compliant, and useless continues to consume operating cost, attention, and risk surface. Business Outcome Assurance exists to make that visible, and its absence is why estates accumulate systems nobody would authorize today.
13.3 Monitoring intensity by tier
Table 37.
| Tier | Comparison cadence | Alert routing | Review |
|---|---|---|---|
| Tier 1 | Periodic batch acceptable | Low-urgency digest to owner | Annual light-touch |
| Tier 2 | Near-continuous for structural and configuration | Direct to owner | Annual |
| Tier 3 | Continuous | Owner, with escalation if unresolved in 5 business days | Annual re-score minimum |
| Tier 4 | Continuous | Owner and AI Governance Lead, same-business-day response | Annual re-score, plus review after any material alert |
These intervals are reasoned defaults. Calibrate them against your own alert volumes once you have them, and expect the Tier 3 five-day window in particular to need adjustment in either direction.
13.4 The cumulative exposure gap
One limitation deserves flagging at the point it bites. IRGF has no mechanism for cumulative or structuring exposure: many individually sub-threshold actions by a standing-authority agent accumulating into material exposure between audit cycles.
An agent authorized to make individual payments below a threshold can, over a period, move an amount that would never have been approved as a single transaction. Every action is within boundary. The aggregate is not governed by anything in the framework.
This is a known, unresolved gap. Until it is addressed, the practical mitigation is external: [Practice recommendation] for any standing-authority agent with financial or data-egress capability, define an aggregate limit per period alongside the per-action limit, and monitor it as a control in your existing operational risk tooling instead of expecting the framework to catch it.