Yes. Once AI systems are in production, the question becomes who or what is acting, under what authority, and whether those actions can be attributed and reviewed. That is an identity and access problem as much as a compliance problem, especially when multiple systems and operators share responsibility.
How Post-Market Monitoring Becomes Identity Governance
Post-market monitoring should be treated as part of identity governance when production behaviour depends on who or what is allowed to act, what they can reach, and whether those permissions still match the intended use. Once a system is live, governance shifts from design-time approval to ongoing review of authority, ownership, and reviewability across people, services, and operators.
That is why post-market monitoring belongs alongside access review, entitlement management, and lifecycle control. If production actions cannot be tied back to a governed identity or delegated authority, you do not just have an assurance gap, you have a control gap in how the system is allowed to operate.
What Monitoring Has To Prove After Go-Live
In production, monitoring is not only about observing performance or model quality. It also has to show whether the actors involved still have the right access, whether that access is being used as approved, and whether shared responsibility is creating blind spots. The relevant question is not just “did the system work?” but “did the right actor perform the right action under the right authority?”
For identity governance, that means monitoring should surface changes in role, privilege, delegation, ownership, and exception handling. A review process that never sees post-launch drift will miss stale access, unnecessary standing privilege, and informal operator workarounds that slowly become normal operating practice.
Where multiple teams or systems can influence the same production outcome, monitoring should also preserve attribution. If you cannot distinguish automated actions from human overrides, or one service account from another, then recertification and accountability become guesswork rather than governance.
Why Governance Breaks If Monitoring Stays Purely Operational
Post-market monitoring often fails when it is treated as a product analytics activity rather than an access governance activity. Operational dashboards can show errors, latency, or adoption, but still miss whether the underlying authority model is drifting out of control. That is especially dangerous when production access is broad, long-lived, or shared.
Identity governance depends on evidence that access remains appropriate after deployment. A useful baseline is the IAM and IGA Basics view of lifecycle and review, then extending it into live monitoring so that access decisions are not frozen at launch. In practice, monitoring should detect changes in permissions, ownership, and exception paths before those changes become accepted behavior.
At scale, this matters because the number of actors grows faster than the ability of teams to review them manually. The more systems participate in a shared outcome, the more important it becomes to monitor standing access, delegated authority, and recertification triggers as part of the production control plane.
Risk and Threat Considerations
When post-market monitoring is outside identity governance, organisations can lose track of who can act in production, which increases the chance of excessive privilege, unauthorised changes, and weak accountability. The risk is not limited to malicious abuse, it also includes routine drift where temporary access, emergency access, and shared credentials remain in place long after they are needed.
Failure mechanism: Production systems accumulate unreviewed roles, delegated rights, and machine access that no longer match the approved operating model, so later actions are still allowed but no longer justified.
Impact: Organisations lose the ability to attribute actions, contain blast radius, and prove that access decisions are current, which weakens both security oversight and audit readiness.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Post-market monitoring depends on logging production actions for review and attribution. |
| AU-6 — Audit Review, Analysis, and Reporting | The question is about reviewing live production behaviour for governance evidence. | |
| AC-6 — Least Privilege | Monitoring must watch for standing or excessive privilege in production authority. | |
| Recommendation — Log production identity and action events needed to review authority drift and investigate exceptions. Review audit data for access drift, exception use, and accountability gaps after release. Continuously validate that production access remains limited to the minimum required authority. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Treating monitoring as governance requires control over who can act in production. |
| A.5.18 — Access rights | Post-market monitoring must support ongoing review of permissions and their appropriateness. | |
| Recommendation — Tie production monitoring to access decisions so authority stays current and reviewable. Review and adjust access rights based on live production behaviour and role drift. | ||
Practitioner Guidance
What to verify: Confirm that post-market monitoring produces identity-relevant signals, not just service health metrics. You should be able to trace material production actions back to an actor, an owner, and a current approval state.
Decision rule: If a production action can change customer, financial, or safety outcomes, treat the actor’s authority as a monitored control, not a static deployment detail. If that authority cannot be reviewed after release, the governance model is incomplete.
What good looks like: Access review, exception handling, and production telemetry are linked so that drift in privilege or ownership triggers a governance response, not only an ops ticket. That is the point at which monitoring becomes identity governance in practice.
Practitioner takeaway: Post-market monitoring belongs in identity governance whenever production authority can drift, because the real control objective is not only to observe system behaviour, but to keep that behaviour attributable, reviewable, and within current permission boundaries.
Related resources from NHI Mgmt Group
- Should organisations treat browser extensions as part of identity governance?
- When should organisations treat agent intent as part of identity governance?
- Should organisations treat semantic governance as part of identity governance?
- Should organisations treat workload communication policy as part of identity governance?