OWASP Top 10 for LLM Applications 2025
Governance and Change Management

OWASP Top 10 for LLM Applications 2025 OWASPLLM-7: LLM Governance, Inventory, Risk and Change Management

Operate LLM governance + inventory + risk + change management. Requirements include (a) maintain inventory of LLM systems + models + datasets + tools + agents + integrations + (b) maintain risk assessment + classification per LLM system aligned to applicable regulation (EU AI Act + NIST AI RMF + ISO 42001 + similar) + (c) implement governance structures + roles + responsibilities + accountability for LLM systems + (d) implement change management for models + prompts + tools including approval + testing + rollout + rollback + (e) implement model lifecycle management including evaluation + retirement + (f) integrate LLM systems with broader AI governance + risk management + (g) maintain documentation including model cards + system cards + risk assessments + responsible AI commitments.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.