THE BUYER'S FIELD GUIDE

AI Model Lifecycle & Governance Platforms

Products that govern models as controlled assets: registries, approval gates, model risk management and validation, deployment controls, versioning and lifecycle monitoring including drift.

26 related offerings · 12 primary listings · 14 overlapping listings

Product research snapshot September 6, 2026 · Editorial guide September 7, 2026 · Published by DutyGraph

When to explore this layer

Use model lifecycle controls when several teams create, adapt or deploy models and need a reliable record of which version is approved for which purpose. Separate an experiment's promising result from permission to deploy it into a particular business workflow.

ILLUSTRATIVE EVALUATION · NOT A CUSTOMER RESULT

Put a real task in the demonstration.

For a fictional document-classification model, register training and validation references, record its intended use and obtain a release decision. Replace the model version, then simulate worse performance on a new document type. Ask how the affected deployments are located, reviewed and rolled back.

Questions to bring to the demonstration

  1. Can a model version be traced to its data references, evaluation and approval?
  2. Are approved uses and deployment environments explicitly scoped?
  3. Which changes or monitoring thresholds trigger revalidation?
  4. Can operators identify every affected deployment and recover a prior approved version?

Evidence to request

  • A model registry entry with lineage
  • An approval tied to a version and intended use
  • A revalidation or rollback exercise

Record what was demonstrated, what was only described, and what remains unknown. Preserve the product version, environment and date beside each observation.

Use the editable Markdown worksheet →

Where this layer stops

A governed model can still be placed inside a poorly specified or overprivileged agent. Model controls address a component; agent behavior also depends on tools, orchestration, retrieval and the task being performed.

Connect it to the work

Connect a model-dependent workflow to its work owner and output requirement. This gives a model change a business review path and helps explain which downstream handoffs could be affected.

Read our perspective on the demand side of agents →

26 offerings to investigate

Alphabetical, not ranked. Membership includes primary and secondary research categories. These products have different scopes; inspect the evidence profile before comparing capabilities.

Primary category

Amazon SageMaker Model Registry

AWS service for cataloguing production models as versioned model packages in model groups, with metadata, lineage, a staging construct, approval status and CI/CD deployment. Integrated SageMaker Model Cards add intended use, risk rating and evaluation records, versioned immutably on edit.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a model package moving through staging with approval status changes, and show the linked model card version history for the same model.

Read sources and limitations →

Also covers this layer

BSI ISO/IEC 42001 certification

Third-party certification of an organisation's AI management system against ISO/IEC 42001, offered by BSI alongside pre-certification gap assessment and training. BSI states it holds UKAS, RvA and ANAB accreditation for this scheme. Certification covers management-system conformity, not the performance or safety of individual AI models.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the audit stages, sampling approach and evidence you require to certify an AI management system covering generative AI agents in production.

Read sources and limitations →

Also covers this layer

Checkmarx AI Inventory and AI-BOM

Capability inside Checkmarx One that inventories AI components by scanning source code and configuration files in connected repositories, cataloguing models, agents, MCP servers, AI libraries and SDKs on every commit, then emitting an AI-BOM and enforcing policy in pull requests and CI/CD. Scope is the software pipeline, not employee tool usage.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an AI-BOM generated from one of our repositories listing every detected model, agent and MCP server with the file and commit where it was found.

Read sources and limitations →

Also covers this layer

Cisco AI Defense AI BOM

Open-source scanner from Cisco's AI Defense team that inspects codebases, container images and cloud environments to produce an AI bill of materials listing models, agents, tools, MCP servers and clients, datasets, prompts, guardrails and secrets. Detection is static analysis plus catalog matching, with optional LLM-based enrichment.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate running the scanner against one of our Python repositories and a container image, and show the resulting AI-BOM entries for agents, tools and MCP servers.

Read sources and limitations →

Primary category

ClearML Model Registry

Model registry inside the open-source ClearML MLOps toolchain: models are logged automatically or manually from training tasks, catalogued per project with metadata and metrics columns, queryable by name, tag or metadata, with lineage and CI/CD triggers on registry events such as tagging or publishing.

hybrid · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate an automatic model registration from a training task, then trigger a CI/CD pipeline when that model is tagged for production.

Read sources and limitations →

Also covers this layer

Collibra AI Command Center

Collibra's AI governance product, evolved from Collibra AI Governance, registering AI use cases, models, model versions and agents as governed assets with lifecycle stages, compliance assessment templates and a per-system trust score. Fits organisations already using Collibra for data governance.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an AI use case linked to its model versions, agents and datasets, plus how the trust score changes when documentation or lifecycle status degrades.

Read sources and limitations →

Also covers this layer

Credo AI Platform

Governance workspace where an enterprise records AI use cases, models, agents and third-party AI vendors, runs questionnaire-driven reviews, and tracks control and risk libraries with task assignment. A Python/TypeScript SDK writes the same objects programmatically. Evidence reviewed covers workflow structure, not independent verification of governance outcomes.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how a new agent use case moves from intake questionnaire through control review to a governance status a regulator-facing auditor could read.

Read sources and limitations →

Primary category

Deeploy

Dutch platform that puts governance in the deployment path: models are registered from Git, MLflow, Databricks, Hugging Face or Azure registries, standardised assessments set a use-case risk score that selects applicable controls, role-based approvals gate deployment, and a gateway handles monitoring, guardrails and logging.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a deployment blocked until the required roles approve, with the risk score, selected control framework and gateway monitoring for the approved version.

Read sources and limitations →

Also covers this layer

Deloitte Algorithm Assurance

Named specialist assurance offering from Deloitte member firms that reviews client algorithms and the controls around them: definition, identification, classification, assessment, code review, stress testing, and monitoring. Aimed at audit committees and risk functions. Pages describe activities and objectives without naming an assurance standard or reporting format.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how you classify an inventory of production algorithms and what your third-party code review report on one high-risk model actually concludes.

Read sources and limitations →

Also covers this layer

Deloitte Trustworthy AI

Deloitte US consulting practice organised around a Trustworthy AI framework, sold as named workstreams covering AI strategy, risk management and governance, regulatory support, model risk management, and AI audit and assurance. The public pages describe offerings and control activities but publish no methodology, deliverable list, or fee information.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the audit-ready evidence package your AI Risk Management and Governance engagement produces for a single high-impact agentic use case, from use-case tiering through monitoring KPIs.

Read sources and limitations →

Also covers this layer

DNV ISO/IEC 42001 certification and AI assurance

DNV offers third-party certification of AI management systems to ISO/IEC 42001 plus an AI vendor capability assessment delivered as an independent third-party audit of an organisation's ability to develop and operate trustworthy AI and data-driven solutions. Neither page names an accreditation body for the AI scheme.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the topic-by-topic findings structure of an AI vendor capability assessment and how it differs from an ISO/IEC 42001 certification audit.

Read sources and limitations →

Primary category

Domino AI Governance

Governance layer of the Domino enterprise data science platform: an MLflow-based model registry with project- and deployment-scoped views, custom model cards, version management, RBAC over registered models and stage transitions, plus documented review steps for validation, ethical review, audit trails and stakeholder sign-off.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me role-based control over stage transitions in the Domino model registry and the self-documenting evidence produced for a model review.

Read sources and limitations →

Primary category

Evidently

Apache-2.0 Python library plus self-hostable platform for evaluating and monitoring data and AI systems, including tabular data quality and drift tests with statistical methods, declarative test suites usable in CI/CD, and dashboards tracking metrics and test results over time for deployed models.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Show me a drift test suite failing in CI for a production model's input data, and how the result appears on the monitoring dashboard over time.

Read sources and limitations →

Also covers this layer

Fiddler

Monitoring platform spanning traditional ML models, LLM applications and multi-agent systems. For LLM applications customers publish prompts, prompt context, responses and retrieved source documents; Fiddler generates trust and safety metrics, embeddings with UMAP visualisation and drift detection to support alerting and root-cause analysis.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me drift and trust-and-safety metrics for a RAG application, including the retrieved source documents behind a flagged response.

Read sources and limitations →

Also covers this layer

GRACE Governance

Governance module of the Danish GRACE AI Platform: register AI projects and systems, define policies and controls, run AI assessments, report on control status and review compliance with audit trails and named role ownership. Sold as part of a wider platform, so standalone scope needs confirmation.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how GRACE Governance is used without the rest of the GRACE platform, and what the control attestation and audit trail output looks like.

Read sources and limitations →

Also covers this layer

IBM watsonx.governance

IBM's AI governance offering combining a tracked model and prompt-template inventory (AI Factsheets) with monitors for fairness, drift, model health and generative-AI output risks. Suited to enterprises already on watsonx; evidence reviewed covers monitoring and inventory mechanics, not regulatory outcomes.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how a deployed model's factsheet, fairness and drift monitors, and alert thresholds appear in the shared model inventory for a risk reviewer.

Read sources and limitations →

Primary category

MLflow Model Registry

Open-source component of MLflow providing a central model store with named registered models, versions, aliases, tags and lineage back to the producing run, used by ML teams as the promotion and rollback backbone. It provides mechanics for staging, not policy, risk assessment or regulatory mapping.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate promoting a model version via alias with lineage back to its run, and show what audit information the registry retains after rollback.

Read sources and limitations →

Primary category

ModelOp Center

Model and AI lifecycle governance software that maintains a searchable inventory of ML models, generative AI, agents, vendor tools and embedded SaaS AI, routes intake through policy-driven workflows, and maps controls to regulations including SR 11-7, the EU AI Act, NIST AI RMF and ISO 42001.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a policy-driven workflow blocking a non-compliant model promotion, with the control mapping and captured sign-off evidence.

Read sources and limitations →

Primary category

NannyML

Open-source Python library for post-deployment monitoring that estimates a model's performance when ground-truth labels are delayed or missing, using confidence-based estimation for classification and direct loss estimation for regression, and links univariate and multivariate drift alerts to performance impact.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate estimated versus realised ROC AUC on a tabular classifier with delayed labels, and show which drift alerts were linked to the performance change.

Read sources and limitations →

Primary category

OpenSSF Model Signing (OMS) / model-transparency

OpenSSF-backed specification with an Apache-2.0 library and CLI that signs and verifies machine learning model artifacts using Sigstore, self-signed certificates, public keys or PKCS#11 devices, producing signature bundles that let consumers check model integrity and provenance before deployment or reuse.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate signing a multi-gigabyte model with Sigstore and verifying the signature in a deployment pipeline gate, including what the bundle attests to.

Read sources and limitations →

Also covers this layer

Saidot

Finnish AI governance platform that links registered systems, models, agents and datasets to an expert-curated graph of risks, controls and policy requirements, so recommendations and risk inheritance propagate to connected assets. Curated content speeds setup but reflects the vendor's interpretation of obligations.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate risk inheritance: register a system on a new foundation model and show which risks, controls and policy requirements are auto-recommended and why.

Read sources and limitations →

Also covers this layer

ServiceNow AI Control Tower

ServiceNow application that inventories AI agents, models and MCP servers as configuration items tied to the CMDB, with persona-based views for AI stewards, owners and risk/compliance users, and lifecycle plus risk and compliance oversight for platform customers already using ServiceNow.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how a discovered third-party AI agent becomes a CMDB configuration item with owner, lineage and a risk assessment task for the AI steward.

Read sources and limitations →

Primary category

ValidMind

Model risk management and AI governance platform pairing a Python library that runs tests and generates model documentation with a review platform for validators, covering statistical, ML, LLM and agentic records with inventory, versioning and approval workflows aimed at regulated financial institutions.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate the developer-to-validator handoff: library-generated documentation and test results entering a validation workflow with approvals and version control.

Read sources and limitations →

Primary category

W&B Registry

Weights & Biases registry that curates versioned artifacts — models and datasets — into organisation-level collections with aliases, lineage tracking and access control, giving ML teams a single record of what is in production. Governance here means access and provenance, not risk or regulatory workflow.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how a model artifact is linked into a production collection, who can access it, and how lineage lets us reproduce that exact version.

Read sources and limitations →

Also covers this layer

W&B Weave

Weights & Biases product for tracking LLM calls and application logic with automatic tracing and cost tracking, scorer-based evaluation and comparison tools, plus pre- and post-response safeguards. Platform controls include role-based access at team or project level, SSO via OIDC, SCIM provisioning and scoped service accounts.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a traced LLM application with cost tracking, and demonstrate restricting project access to a named team using SSO-provisioned users.

Read sources and limitations →

Primary category

Yields Model Risk Management

Belgian model risk management software providing a configurable inventory of models, AI systems, agents, use cases, vendors and data sources with risk tiers, a workflow engine for validation and change control, automated validation reporting and monitoring, targeted at financial institutions with formal MRM functions.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an automated validation report generated from the inventory record, including versioning history and the audit trail for a model change.

Read sources and limitations →

About this guide

The evaluation questions and fictional scenario are DutyGraph's editorial guidance. Product listings use the supplied source-linked research snapshot. We have not independently tested these offerings. Listing is not an endorsement, certification or working integration.

Read the directory methodology · Suggest a correction