Monitoring should cover the whole system.
That includes:
NIST’s Generative AI Profile treats monitoring, information integrity, human-AI configuration, incident disclosure, cybersecurity, privacy, third-party risk, and content provenance as cross-sector risk-management concerns.2 It is guidance for risk management, not a guarantee that a deployment is safe or compliant.
Monitoring the model alone is not enough when the answer also depends on retrieval, tools, rules, permissions, and human decisions.
“Continuous monitoring” should not be treated as continuous assurance or continuous compliance.