← Public Policy Library

Certification lifecycle

Material Change and Change Notification Policy

Defines which changes to a certified AI system must be reported and how Clause5afe determines whether review, re-assessment, suspension, or another status action is required.

Controlling public principle

The rule an outsider should be able to rely on

A certified organization must notify Clause5afe when a planned or discovered change may affect the validity, scope, controls, or obligations of its certification.

Obligation

When in doubt, notify

The notification obligation applies for the life of the certification. It is prospective when a planned change can be reported before implementation and retrospective when an organization discovers that a reportable change has already occurred.

The Named Custodian, or the designated compliance officer when no Named Custodian is registered, owns the notification obligation.

Critical change

Immediate notice within 48 hours

A Critical change directly affects a safety-critical control, a certification obligation, the underlying model, guardrails, consent or data controls, required disclosures, human oversight, user population, deployment context, or another matter that formed the basis of the certification outcome.

The affected certification scope is placed under review until assessment confirms whether the certification remains valid.

Major change

Notice within 15 business days

A Major change materially alters architecture, training data, third-party integrations, governance, custodianship, user-facing behavior, ownership, deployment, or regulatory scope without directly changing a safety-critical control.

Clause5afe performs a certification-impact assessment to determine whether targeted re-audit or another controlled action is required.

Minor change

Log for scheduled review

Routine maintenance, non-material bug fixes, interface changes that preserve disclosures and consent, and infrastructure changes that do not alter system behavior or data flows may be recorded for the next scheduled review.

If a reported change does not clearly fit one class, it is treated as the higher class until Clause5afe makes a determination.

Determination

What a notification must contain

The organization provides a description, implementation date, affected components, proposed classification, and supporting evidence such as revised architecture, data-flow material, or test results. The source policy targets acknowledgment within 5 business days and a Critical or Major impact assessment within 15 business days after acknowledgment.

  • No action or scheduled review for a confirmed Minor change.
  • Targeted review or re-audit for a Major change when required by impact.
  • Certification hold and focused re-assessment for a Critical change.
  • Updated scope, conditions, status, or Registry record when the evidence requires it.

Non-notification

Late notice and concealment affect certification trust

Consequences scale with the severity and intent of the failure. An unreported Major or Critical change can require immediate assessment, a hold, re-audit, formal warning, or escalation. Intentional concealment may support suspension or revocation review.

Clause5afe may explain the likely certification impact of a proposed change. It does not advise the organization how to design or implement the change.

Authority boundary

What this policy does not authorize

A change notification is not approval of the changed system. Only the resulting evidence review and certification decision can confirm whether scope and status remain valid.

Controlled information

What remains outside the public layer

  • Proprietary methodology thresholds
  • Internal risk-scoring logic
  • Client-confidential system and evidence details

Connected governance

Follow the policy into the institution.