Keeping It Current
Every compliance program has a maintenance requirement. This one is no different.
You have run this before. Controls get tested annually. Vendor reviews come around. Policies get refreshed. The work in this chapter is the same shape, applied to a new subject.
This chapter covers:
- What "current" actually requires
- What changes underneath a deployment
- Setting a review rhythm
- What a maintained record looks like
- Prioritizing when you cannot review everything at once
What "Current" Requires
It does not mean reviewing everything constantly. No program works that way.
It means two things:
- You know when something changed that affects an obligation you documented
- You can show when you last looked
The second matters more than people expect. A review that found nothing is still a review, and recording it is how the file demonstrates ongoing attention.
A snapshot says what was true on one date.
A maintained record says what was true, what changed, when you checked, and what you did about it.
What Changes Underneath a Deployment
Three things move, and they move independently.
The law
Statutes change on legislative calendars, and they change in both directions.
- Colorado's original AI law was repealed and replaced before it took effect
- The EU AI Act's high-risk deployer date moved from August 2026 to December 2027
- The UK revised its automated decision-making provisions in 2025
An analysis that was correct in March may need revisiting in September. That is expected, not a failure of the original work.
The vendor
Product updates rarely announce the parts that matter to you.
What moves:
- Sub-processors added or replaced
- Retention periods changed with a settings update
- Model versions swapped underneath the product
- Terms revised at renewal
- New features enabled by default
The deployment
This one happens inside the building, which makes it easy to miss.
How deployments drift:
- The use case expands beyond what was assessed
- Another team adopts the same tool for a different purpose
- New data sources are connected
- The tool reaches people in a new location
It arrives as ordinary business progress, not as a request for review.
Setting the Review Rhythm
Two kinds of review. You need both.
Calendar-based
Set an interval and hold it. Annual is standard. Shorten it for higher-risk deployments.
What to check each time:
- Has the use case changed
- Has the vendor changed anything material
- Has the law changed in any location in scope
- Are the documented controls still in place
- Is the named owner still in the role
That last one catches more than people expect. Ownership decays quietly when people change jobs.
Event-based
Some things should prompt a review regardless of the calendar.
| Trigger | Why it matters |
|---|---|
| New location in scope | Different law may apply |
| New use case for an existing tool | New deployment, new analysis |
| Vendor contract renewal | Terms may have changed |
| New data category added | May cross a threshold |
| Vendor announces a significant change | Model, hosting, or sub-processor |
| Regulatory change where you operate | Direct impact |
| Incident or complaint involving the tool | Obvious |
A tool reviewed in January and expanded in February should not wait until the following January.
Attach it to what already runs
You have review cycles. Add these questions to them rather than building a separate process.
- Vendor risk reviews — add the AI questions
- Contract renewal — check processing terms
- Access reviews — confirm oversight ownership is current
- New vendor onboarding — capture the intake at the start
The last one is the highest-value change you can make. A deployment captured properly at onboarding never needs reconstructing later.
Watching for Regulatory Change
You are watching the locations your deployments reach.
What you are looking for:
- New laws where your people are
- Amendments to laws you already track
- Effective dates arriving
- Regulator guidance that shifts interpretation
- Enforcement decisions that show how a provision is read
Practical approach:
- Subscribe to updates from the regulators in your main locations
- Follow the law firm alerts covering your sectors
- Set calendar reminders for known effective dates
- Ask counsel what they are watching — they usually have a list
Known dates are the easiest win. December 2027 is on the calendar. Put it there.
What a Maintained Record Looks Like
If someone reviews your file, these are the markers.
Present:
- Assessments dated across a period rather than clustered
- Reviews logged, including ones that found nothing
- Changes recorded when the law moved
- Ownership updated when people changed roles
- Unresolved items still marked unresolved, with what is missing
Record the reviews that found nothing. They are evidence you looked. A gap in the log reads as inattention, whether or not that is what happened.
Keep prior versions
When you update an assessment, keep what it said before.
The question is rarely "what does this document say now." It is "what did you know, and when."
A document that has been overwritten cannot answer that. A versioned one can.
Prioritizing the Work
You will not review everything at the same depth. No program does.
Scope deliberately, and record the reasoning.
Higher attention for deployments that:
- Affect people in consequential domains — employment, lending, healthcare, insurance, housing
- Involve sensitive data categories
- Operate with limited human review
- Reach multiple locations
- Serve vulnerable populations
Lower attention for deployments that:
- Produce internal outputs only
- Touch no personal data
- Have consistent human review before anything reaches a person
The important part is that the reasoning is written down. A deliberate, documented prioritization is a defensible program decision. An undocumented one is indistinguishable from having missed something.
If the volume outgrows the team
That happens, and there are ordinary answers to it.
- Narrow the scope deliberately and record why
- Move the intake earlier so less has to be reconstructed
- Use the reviews already running rather than adding new ones
- Bring in help for the parts that scale badly
What is not an option: describing a monitoring practice you are not actually running. The record has to match what you do.
Where This Leaves You
The four questions are covered.
| Question | Chapter |
|---|---|
| What applies to us? | 3 and 4 |
| What are we obligated to do? | 5 |
| What documents does the law require us to produce? | 6 |
| How do we keep them current? | 7 |
The program does not finish. It runs — and what it produces is a record you can hand to anyone who asks.
That record is built before the question arrives, or it is built under it. The two do not look the same, and the difference is visible to anyone reading the file.
Use and reuse
Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.
LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com
Written by compliance and audit practitioners who spent decades on the other side of the table.
Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.