Compliance

    ISO/IEC 5338: What It Means for Enterprise AI Governance

    By Trussed AISeptember 2026

    Most AI governance conversations still start at the approval gate: get the model reviewed, get it signed off, and deploy it. But production AI systems don't stand still. Models get updated, data shifts, prompts change, guardrails get retuned, and increasingly, agents are connected to tools and enterprise systems they can act on directly. Oversight therefore has to continue after deployment, not just happen beforehand.

    ISO/IEC 5338:2023 is designed for that lifecycle. Published in 2023, the standard extends established system and software lifecycle practices to account for AI-specific characteristics, including machine learning, training and production data, and the need to monitor and modify systems after deployment. It covers processes supporting the definition, control, management, execution, and improvement of AI systems, whether an organization develops the system itself or acquires it from a provider. It also complements ISO/IEC 42001, providing more detail on the AI system lifecycle processes discussed in that standard.

    Why It Matters for Regulated Industries

    ISO/IEC 5338 isn't a law that every organization using AI must follow. But its lifecycle approach is particularly relevant for regulated industries such as financial services, insurance, healthcare, and life sciences, where organizations may need to demonstrate not only how an AI system was evaluated before deployment, but how it was managed once in production. The standard applies to both organizations acquiring AI systems and those developing their own, making it relevant to enterprises consuming third-party models and AI applications.

    Is your organization ready for the EU AI Act?

    High-risk AI obligations are now enforceable. Check your compliance status and get a personalized gap checklist in 5 minutes, free.

    Take the EU AI Act Assessment

    Implementing that lifecycle approach means establishing processes around development or acquisition, verification, deployment, operation, monitoring, maintenance, modification, and eventual retirement. Configuration management is an important part of that framework because an AI application's behavior can depend on several moving parts: the model, data, prompts, policies, guardrail configurations, agent permissions, and available tools. ISO/IEC 5338 specifically includes configuration management among its technical management processes.

    Documentation Alone Can't Show What Happened

    The practical challenge comes when those components change independently. Months after an AI interaction occurred, an organization may need to determine which model was running, which policies and guardrails were active, what had changed, and what configuration was in effect. Documentation can establish that the right processes existed. It cannot, by itself, show what was actually happening in production.

    Trussed provides a runtime control layer for enterprise AI. It applies policies and guardrails to AI interactions while capturing evidence of what happened, what AI could see, what it said, and what it did when interacting with tools and enterprise systems. Policy and guardrail versioning preserves changes to those controls over time and associates the applicable version with runtime activity. So months later, a specific AI action can be traced back to the policy and guardrail versions that were in effect when it occurred.

    That distinction becomes more important as AI moves from generating content to taking actions. ISO/IEC 5338 establishes a lifecycle discipline; runtime evidence makes it possible to show how that discipline was applied when the AI was actually operating.

    Stay current on AI regulation deadlines

    Track every AI enforcement date globally, filterable by industry. Updated monthly.

    View the Deadline Tracker