Most organizations have AI policies that live in static documents; ethics principles, compliance guidelines, model documentation templates. But in practice, these hard to translate into something actionable at the model level.
Custom Controls enable compliance, risk, and AI governance teams to design, implement, and validate their own governance rules directly in the platform, ensuring consistent, auditable oversight across all AI use cases.
What are controls in Deeploy?

In Deeploy, controls are actionable translations of policy requirements that you can apply to AI use cases and models.
Each control defines what must be done to ensure compliance and accountability, and can be linked to automated checks that verify whether it’s being followed.
For example:
- A policy requiring models to have clear documentation can translate into a control linked to the check “Documentation uploaded.”
- A policy about ongoing model monitoring can become “Alert rule for drift added.”
This creates a direct connection between governance expectations and operational activity.
Default vs. custom controls
Deeploy comes with a library of default controls, predefined elements aligned with common AI governance frameworks (such as ISO/IEC 42001 or the EU AI Act).
But AI governance isn’t one-size-fits-all. That’s where custom controls come in.
Custom controls let you define, name, and structure your own governance requirements, from technical to ethical to operational, and make them verifiable with automated checks.
Building your own custom controls



Creating a custom control is straightforward. In Deeploy, you can define:
- A unique ID and name (e.g. CR-23: Submit quarterly bias assessments).
- A description – what the control enforces or prevents
- Lifecycle stage – in which stage the control applies (exploration, development, validation, production).
- Risk classification – the risk classifications for which the control should apply.
- Checks – automated validations that confirm compliance with the control.
Once saved, your control becomes part of your organization’s governance system, ready to be applied, monitored, and audited.
Applying controls through frameworks

Controls gain power when combined into control frameworks.
A framework groups related controls, for example, all controls relevant to high-risk AI systems or data governance.
Once you’ve created a framework, you can apply it to multiple workspaces. Every model within those workspace automatically inherits the relevant controls and checks for their lifecycle stage and risk classification.
In the case of custom controls, you define the lifecycle stage and risk classification that the control should apply to.
This ensures consistency: models are governed under the same standards, and compliance evidence is collected in a unified way.
Automated validation with checks

Every control can include one or more checks, built-in validation mechanisms that tie governance to actual model operations.
For example:
- Alert rule for drift added → verifies monitoring configuration
- Model card available → ensures transparency documentation
- Version control maintained → tracks model lifecycle traceability
- Evaluations submitted → confirms validation data is continuously reported
When a model meets these conditions, Deeploy registers the control as satisfied, giving governance teams a live, verifiable overview of compliance.


