Artificial Intelligence (AI) and Generative AI Across the Systems Development Lifecycle (SDLC) - Systems Development Lifecycle (SDLC) Best Practices
Artificial Intelligence (AI) and Generative AI Across the Systems Development Lifecycle (SDLC)
(Chapter 95 of Systems Development Lifecycle (SDLC) Best Practices)
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Governing Principle | AI-enabled Solutions require the complete Enterprise SDLC plus additional controls for variable behavior, data and Model provenance, evaluation, human accountability, monitoring, and change. |
| Lifecycle Accountability | Enduring ownership and Release-specific coordination remain explicit. |
| Evidence | Claims and decisions are supported by attributable, current, relevant, and sufficient evidence. |
| Risk-Based Tailoring | Depth changes with context; minimum outcomes and accountability remain. |
Quick Q&A
Question: How do AI-enabled Solutions change SDLC governance?
Question: Why distinguish AI from generative AI?
Question: Does an AI model remain validated after deployment?
Read More Below
Defines lifecycle governance for Artificial Intelligence and generative AI capabilities, including Models, data, prompts, agents, tools, human oversight, evidence, monitoring, and supplier dependencies.
Governing Principle
AI-enabled Solutions require the complete Enterprise SDLC plus additional controls for variable behavior, data and Model provenance, evaluation, human accountability, monitoring, and change.
Required Lifecycle Treatment
| Area | Required treatment |
|---|---|
| AI system boundary | Identify Models, prompts, grounding, retrieval, data, tools, permissions, memory, agents, orchestration, suppliers, interfaces, and human decision points. |
| Risk and intended use | Define permitted and prohibited uses, affected populations, consequence, autonomy, reversibility, human oversight, and escalation. |
| Requirements and evidence | Specify performance ranges, quality, safety, bias, Privacy, Security, explainability, traceability, accessibility, resilience, monitoring, and fallback requirements with validation methods. |
| Variable behavior | Use representative, adverse, boundary, misuse, and drift scenarios rather than relying solely on deterministic acceptance tests. |
| Operations | Monitor quality, harmful outcomes, drift, data changes, prompt changes, Model changes, tool use, incidents, supplier behavior, and continuing suitability. |
Application Through the SDLC
This discipline spans the complete lifecycle. Planning establishes ownership and evidence needs; Design and Build turn it into testable requirements; SIT, UAT, and Staging generate representative evidence; Production and Operations verify and monitor compliance; Retirement closes it out with evidence of completion.
Governance and Evidence
Assign enduring ownership across the Solution, Release, and applicable discipline, plus evidence producers, reviewers, and a Risk Owner, scaling rigor to criticality and reversibility. Track Risks, exceptions, and Technical Debt authoritatively rather than informally. Automation and generative AI can support the work but should not make accountable decisions on their own.
Connections to Related IF4IT Practices and Inventories
Use the Data and Information Inventory and Attributes and the Integrations Inventory and Attributes to connect the decisions and responsibilities addressed in this chapter to authoritative information, semantic meaning, interface dependencies, lineage, and lifecycle records.
Apply Enterprise AI Governance Best Practices and, where AI Agents are involved, the AI Agents Inventory and Attributes to govern approved use, ownership, data access, autonomy, validation, monitoring, supplier exposure, and human accountability for generative AI and AI-enabled solutions.
Use the Non-Functional Requirements (NFRs) Framework for Software Systems to tie quality expectations to validation methods, test evidence, acceptance criteria, readiness gates, and Production assurance.
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Artificial Intelligence (AI) and Generative AI Across the Systems Development Lifecycle (SDLC) | Systems Development Lifecycle (SDLC) Best Practices. https://if4it.org/best-practices/systems-development-lifecycle-sdlc/artificial-intelligence-ai-and-generative-ai-across-the-systems-development-lifecycle-sdlc/ (accessed 2026-08-24).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers