Skip to main content

CCC.GenAI.C07: Model Version Pinning

Control ID:CCC.GenAI.C07
Title:Model Version Pinning
Objective:Mandate that applications are locked ("pinned") to a specific, tested version of a foundational model to prevent unexpected behaviour changes introduced by provider-side updates.
Control Family:
Configuration Management

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.GenAI.TH10Model Version DriftAn update to a managed GenAI model may cause unpredictable and breaking changes in its outputs, alignment, and performance. Systems built and tested against the previous version's specific behavior can suddenly fail or become insecure, as their functional and safety assumptions are no longer valid.
1
1
0

Related Capabilities

IDTitleDescription
CCC.Core.F18Resource VersioningThe service automatically assigns versions to child resources which can be used to preserve, retrieve, and restore past iterations.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
FINOS-AIGF
AIR-PREV-010
0
AI Model Version Pinning

Assessment Requirements

IDDescriptionApplicability
CCC.GenAI.C07.TR01When an application makes an API call to a foundational model in a production environment, then it MUST specify an explicit version identifier.
tlp-clear
tlp-green
tlp-amber
tlp-red