Skip to main content
OpenIRB

Review Lifecycle

Review is a lifecycle, not a checkpoint.

Systems that learn, adapt, update, or operate through agents require continuing review. OpenIRB defines the lifecycle from first submission through closure.

A continuous review loop from approval through monitoring, detection, reclassification, and re-review.
Approval begins accountable operation. It does not end review.
  1. Intake

    Capture what is being reviewed and why: object of review, sponsor, owner, intended use, deployment context, affected groups, requested decision, and known constraints. If the boundary is vague, the review cannot be meaningful.
  2. Classification

    Determine the review path from human impact, domain, autonomy level, data sensitivity, affected populations, regulatory relevance, reversibility of harm, scale, novelty, and existing controls. Classification is where review becomes proportional.
  3. Evidence packet

    Provide the record reviewers need: summary, intended use, claims and evidence, data provenance, evaluation, limitations, risk-benefit-impact, consent posture, authority, human oversight, security/privacy controls, monitoring, incident response, and change management.
  4. Deliberation

    Review evidence, ask questions, resolve issues, and document reasoning — producing reviewer questions, findings, risk-benefit-impact and consent/authority determinations, required controls, unresolved issues, and a conflict-of-interest record.
  5. Decision

    Produce a decision artifact: decision type, conditions, rationale, required modifications, monitoring obligations, renewal schedule, incident triggers, version, reviewers, conflicts, and timestamp. A decision without a record is not reviewable.
  6. Receipt and registry

    Make the decision findable, verifiable, and governable. The registry preserves enough metadata to prove a review happened, under which policy, with which outcome — without exposing sensitive evidence.
  7. Continuing review

    Monitor change: model updates, tool-chain changes, new data sources, expanded use, new affected populations, incidents, drift, complaints, consent revocation, authority changes, regulatory changes, and renewal dates. Approval is the beginning of accountable operation.