Chapter 7 · Keeping It CurrentThe Handbook
07Chapter 7 of 7

Keeping It Current

Every compliance program has a maintenance requirement. This one is no different.

You have run this before. Controls get tested annually. Vendor reviews come around. Policies get refreshed. The work in this chapter is the same shape, applied to a new subject.

This chapter covers:

  • What "current" actually requires
  • What changes underneath a deployment
  • Setting a review rhythm
  • What a maintained record looks like
  • Prioritizing when you cannot review everything at once

What "Current" Requires

It does not mean reviewing everything constantly. No program works that way.

It means two things:

  1. You know when something changed that affects an obligation you documented
  2. You can show when you last looked

The second matters more than people expect. A review that found nothing is still a review, and recording it is how the file demonstrates ongoing attention.

A snapshot says what was true on one date.

A maintained record says what was true, what changed, when you checked, and what you did about it.


What Changes Underneath a Deployment

Three things move, and they move independently.

The law

Statutes change on legislative calendars, and they change in both directions.

  • Colorado's original AI law was repealed and replaced before it took effect
  • The EU AI Act's high-risk deployer date moved from August 2026 to December 2027
  • The UK revised its automated decision-making provisions in 2025

An analysis that was correct in March may need revisiting in September. That is expected, not a failure of the original work.

The vendor

Product updates rarely announce the parts that matter to you.

What moves:

  • Sub-processors added or replaced
  • Retention periods changed with a settings update
  • Model versions swapped underneath the product
  • Terms revised at renewal
  • New features enabled by default

The deployment

This one happens inside the building, which makes it easy to miss.

How deployments drift:

  • The use case expands beyond what was assessed
  • Another team adopts the same tool for a different purpose
  • New data sources are connected
  • The tool reaches people in a new location

It arrives as ordinary business progress, not as a request for review.


Setting the Review Rhythm

Two kinds of review. You need both.

Calendar-based

Set an interval and hold it. Annual is standard. Shorten it for higher-risk deployments.

What to check each time:

  • Has the use case changed
  • Has the vendor changed anything material
  • Has the law changed in any location in scope
  • Are the documented controls still in place
  • Is the named owner still in the role

That last one catches more than people expect. Ownership decays quietly when people change jobs.

Event-based

Some things should prompt a review regardless of the calendar.

TriggerWhy it matters
New location in scopeDifferent law may apply
New use case for an existing toolNew deployment, new analysis
Vendor contract renewalTerms may have changed
New data category addedMay cross a threshold
Vendor announces a significant changeModel, hosting, or sub-processor
Regulatory change where you operateDirect impact
Incident or complaint involving the toolObvious

A tool reviewed in January and expanded in February should not wait until the following January.

Attach it to what already runs

You have review cycles. Add these questions to them rather than building a separate process.

  • Vendor risk reviews — add the AI questions
  • Contract renewal — check processing terms
  • Access reviews — confirm oversight ownership is current
  • New vendor onboarding — capture the intake at the start

The last one is the highest-value change you can make. A deployment captured properly at onboarding never needs reconstructing later.


Watching for Regulatory Change

You are watching the locations your deployments reach.

What you are looking for:

  • New laws where your people are
  • Amendments to laws you already track
  • Effective dates arriving
  • Regulator guidance that shifts interpretation
  • Enforcement decisions that show how a provision is read

Practical approach:

  • Subscribe to updates from the regulators in your main locations
  • Follow the law firm alerts covering your sectors
  • Set calendar reminders for known effective dates
  • Ask counsel what they are watching — they usually have a list

Known dates are the easiest win. December 2027 is on the calendar. Put it there.


What a Maintained Record Looks Like

If someone reviews your file, these are the markers.

Present:

  • Assessments dated across a period rather than clustered
  • Reviews logged, including ones that found nothing
  • Changes recorded when the law moved
  • Ownership updated when people changed roles
  • Unresolved items still marked unresolved, with what is missing

Record the reviews that found nothing. They are evidence you looked. A gap in the log reads as inattention, whether or not that is what happened.

Keep prior versions

When you update an assessment, keep what it said before.

The question is rarely "what does this document say now." It is "what did you know, and when."

A document that has been overwritten cannot answer that. A versioned one can.


Prioritizing the Work

You will not review everything at the same depth. No program does.

Scope deliberately, and record the reasoning.

Higher attention for deployments that:

  • Affect people in consequential domains — employment, lending, healthcare, insurance, housing
  • Involve sensitive data categories
  • Operate with limited human review
  • Reach multiple locations
  • Serve vulnerable populations

Lower attention for deployments that:

  • Produce internal outputs only
  • Touch no personal data
  • Have consistent human review before anything reaches a person

The important part is that the reasoning is written down. A deliberate, documented prioritization is a defensible program decision. An undocumented one is indistinguishable from having missed something.

If the volume outgrows the team

That happens, and there are ordinary answers to it.

  • Narrow the scope deliberately and record why
  • Move the intake earlier so less has to be reconstructed
  • Use the reviews already running rather than adding new ones
  • Bring in help for the parts that scale badly

What is not an option: describing a monitoring practice you are not actually running. The record has to match what you do.


Where This Leaves You

The four questions are covered.

QuestionChapter
What applies to us?3 and 4
What are we obligated to do?5
What documents does the law require us to produce?6
How do we keep them current?7

The program does not finish. It runs — and what it produces is a record you can hand to anyone who asks.

That record is built before the question arrives, or it is built under it. The two do not look the same, and the difference is visible to anyone reading the file.


Use and reuse

Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.

LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com

Written by compliance and audit practitioners who spent decades on the other side of the table.

Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.

Contents
Talk to usWe're here to help
Keeping an AI Obligations Program Current | LegisGate