A Methodology for Auditable Trustworthiness Levels in AI Lifecycle Governance
2026-07-17 • Computers and Society
Computers and SocietyArtificial Intelligence
AI summaryⓘ
The authors propose a simple method to help track how trustworthy an AI system is throughout its life. Their approach uses clear rules and decision trees to measure and represent AI trustworthiness in ways that can be monitored and reassessed over time. They also suggest a governance process that documents these trust levels and sets human responsibilities for regular checks. This method aims to support, not replace, expert decisions by providing clear evidence of changes in AI behavior. They demonstrate their idea using made-up examples showing how an AI's trust can change due to updates or problems.
AI governancetrustworthinesslifecycle monitoringdecision treescontext-sensitive protocolconformity documentationreassessmentprofile driftboundary margins
Authors
Andrea Ferrario
Abstract
AI governance increasingly requires judgments about whether an AI system remains adequately trustworthy over time, whether observed changes are tolerable, and how such judgments should be documented in a transparent and contestable way. Yet existing work on AI trustworthiness remains either too high-level to support lifecycle monitoring and reassessment or too narrowly metric-driven to connect with governance needs. We therefore propose a lightweight methodology for auditable trustworthiness levels in AI governance. The methodology has two components: a formal framework for representing and learning trustworthiness levels, and a lightweight AI lifecycle governance procedure for documenting, monitoring, and reassessing them over time. The formal framework models governance-relative trustworthiness through a context-sensitive protocol of measurable dimensions and learns trustworthiness levels as interpretable rules over trustworthiness profiles. Using decision trees as an interpretable proof-of-concept model class, the methodology yields explicit trustworthiness plateaus, readable level transitions, and two simple lifecycle diagnostics: boundary margins and profile drift. The governance procedure embeds these formal objects in a conformity-oriented workflow for design-time labeling, post-deployment monitoring, reassessment, and reporting. It also assigns human responsibilities and control gates for protocol design, validation, monitoring, and reassessment. We illustrate the methodology on synthetic AI lifecycle traces involving degradation, shocks, updates, heterogeneous monitoring cadences, and system comparison. Our methodology does not replace legal or other expert judgment: it supports conformity documentation and lifecycle monitoring by providing an evidential basis for documenting and tracking AI governance-relevant changes over time.