Skip to main content
Category: Management System Governance

Plan-Do-Check-Act (PDCA)

Also known as: PDCA, Plan-Do-Check-Adjust, PDCA Cycle, Deming Cycle
Simply put

Plan-Do-Check-Act (PDCA) is a four-step cycle for making and testing changes to a process. You plan a change, put it into practice, check the results, and then act on what you learned, repeating the cycle to keep improving over time.

Formal definition

PDCA is an iterative, four-phase improvement and management method based on the scientific approach of proposing a change to a process (Plan), implementing that change (Do), measuring and evaluating the results (Check), and standardizing or adjusting based on the findings (Act). It is used in business for the control and continual improvement of processes, and is applied to problem-solving, change implementation, and ongoing process refinement. Some sources render the final step as 'Adjust' rather than 'Act.' The cycle is repeated iteratively so that each pass informs the next; as such, PDCA describes a general improvement discipline rather than a governance or risk-management control framework in itself.

Why it matters

PDCA matters to AI governance and model risk management professionals because much of the discipline in both fields rests on iterative, evidence-based improvement rather than one-time compliance events. Governance policies, model monitoring routines, and control testing are typically expected to evolve as conditions change, and PDCA provides a widely recognized shorthand for that improvement logic: propose a change, implement it, measure the outcome, and adjust. Many management-system standards and quality frameworks draw on this cycle as their underlying structure, which is why practitioners encounter it when building repeatable processes around model validation, monitoring, and remediation.

Who it's relevant to

Model Risk Managers
PDCA offers a familiar structure for the iterative monitoring, evaluation, and remediation activities that recur across a model's life. It can help frame how monitoring findings feed back into control adjustments. However, it should be treated as a process-improvement discipline layered onto, not a substitute for, the specific validation, independent review, and documentation expectations that a given model risk regime requires.
AI Governance and Policy Specialists
The Plan-Do-Check-Act cycle underlies many management-system standards and quality frameworks, so governance professionals will encounter it when designing repeatable review and refinement processes for policies and oversight mechanisms. It supports the expectation that governance is continual rather than static, but it does not by itself define accountability structures, roles, or risk-tiering.
Auditors and Second-Line Reviewers
PDCA gives reviewers a lens for assessing whether an improvement process actually closes the loop—whether findings from the Check phase lead to documented action and re-measurement. Auditors should note that following the cycle demonstrates a method for improvement, not evidence that any particular control objective or regulatory requirement has been met.
Quality and Process Improvement Practitioners
For those with a quality-management background, PDCA is a foundational four-step model for carrying out change and continuously improving processes, applicable to problem-solving and change implementation. Its familiarity makes it a useful bridge when translating quality-improvement practices into AI governance and model risk workflows.

Inside PDCA

Plan
The stage in which objectives, scope, and processes are established to deliver results aligned with intended outcomes. In an AI governance or management-system context, this typically involves identifying risks, defining controls, assigning responsibilities, and setting measurable objectives before implementation.
Do
The implementation stage, in which the planned processes and controls are put into operation. As commonly applied, this is often carried out on a controlled or pilot basis before full-scale deployment, though the exact approach varies by organization and framework.
Check
The monitoring and measurement stage, in which actual results are compared against the objectives and requirements established in the Plan stage. This typically includes reviewing performance, identifying deviations, and reporting findings to relevant oversight functions.
Act
The stage in which actions are taken to address identified gaps and to improve the process. Depending on the results of the Check stage, this may involve corrective actions, adjustments to controls, or updates that feed back into the next Plan cycle, supporting continual improvement.
Iterative cycle
PDCA is structured as a repeating loop rather than a linear sequence, so that outputs from the Act stage inform subsequent planning. This iterative characteristic is central to how the model supports ongoing rather than one-time management activity.

Common questions

Answers to the questions practitioners most commonly ask about PDCA.

Is PDCA an AI-specific governance methodology?
No. PDCA is a general-purpose continual improvement cycle that predates AI governance and is applied across many management disciplines, including quality management. It is not an AI-specific method. It has been adopted as an organizing structure within some management system standards that can cover AI-related processes, but the cycle itself carries no AI-specific requirements. Treating PDCA as if it were designed for AI risk, or as a substitute for AI-specific controls such as model validation or fairness assessment, is a common error.
Does completing a PDCA cycle mean a model's risks have been eliminated?
No. PDCA is a mechanism for iterative improvement and ongoing management of a process, not a means of eliminating risk. Working through the cycle can help an organization identify weaknesses and adjust controls over time, but it reduces or manages risk rather than removing it. Presenting a completed cycle as evidence that risk has been resolved misrepresents both the purpose of PDCA and the nature of residual risk, which typically persists after controls are applied.
How does PDCA map onto the stages of managing an AI system or model?
In practice, organizations often align the Plan phase with defining objectives, scope, and controls; the Do phase with implementation and operation; the Check phase with monitoring, measurement, and review against those objectives; and the Act phase with corrective actions and adjustments. This mapping is a way of organizing activity and does not by itself specify which technical or governance controls are appropriate; those must be defined separately according to the applicable framework and context.
Where does the Check phase fit relative to model monitoring and validation?
The Check phase is typically where ongoing monitoring, measurement, and review activities are situated within a PDCA structure. However, PDCA does not define what to check or how. Practices such as validation and verification, or monitoring for performance degradation, remain distinct activities with their own requirements and, in some settings, their own supervisory expectations. PDCA can provide a cadence for revisiting these activities but does not replace their specific methodologies.
How does PDCA relate to lines-of-defense responsibilities?
PDCA describes a cyclical process and does not itself assign roles. Organizations that use a lines-of-defense model would still need to determine which functions carry out each phase and who reviews the results. The improvement cycle can be run within a given function or across functions, but responsibility, independence, and oversight arrangements are defined by the organization's governance structure rather than by PDCA.
How often should a PDCA cycle be run for an AI system?
PDCA does not prescribe a fixed frequency. Organizations typically set the cadence based on factors such as the risk profile of the system, the rate of change in data or environment, and any applicable governance or supervisory expectations. Higher-risk or rapidly changing systems may warrant more frequent iteration. The appropriate interval is an organizational decision and should be documented and justified rather than assumed from the method itself.

Common misconceptions

PDCA is a compliance requirement mandated by AI regulations such as the EU AI Act or SR 11-7.
PDCA is a general continual-improvement methodology, not a regulatory mandate in itself. While the iterative logic underlying PDCA is reflected in some management-system standards and in the design of certain governance frameworks, it should not be presented as a legally required control. Whether and how it is used depends on the organization and the framework adopted.
PDCA is a one-time project methodology that ends once improvements are implemented.
As commonly defined, PDCA is a cyclical model intended to be repeated so that each completed cycle informs the next. Treating it as a single pass undermines its purpose, which is continual improvement over time rather than a discrete deliverable.
Applying PDCA guarantees that risks in an AI system will be resolved or eliminated.
PDCA is a structured approach for managing and reducing risk through iterative review and correction; it does not eliminate risk. Residual risk typically remains after any cycle, and the effectiveness of the approach depends on the quality of the objectives, measurements, and corrective actions applied at each stage.

Best practices

Define clear, measurable objectives and success criteria during the Plan stage so that the Check stage has an objective baseline for comparison.
Document each stage of the cycle, including planned controls, implementation decisions, monitoring results, and corrective actions, to support auditability and oversight review.
Treat PDCA as a recurring loop by ensuring that findings from the Act stage are explicitly fed back into the next Plan stage rather than closed out permanently.
Assign accountability for each stage to the appropriate functions or roles so that monitoring and corrective actions have clear ownership.
Use the Check stage to compare actual results against the objectives set in Plan, and escalate material deviations to relevant oversight or governance functions.
Where PDCA is used within a broader governance or management-system framework, align its stages with that framework's requirements rather than assuming PDCA alone satisfies them.