# Automatic event logging and record retention

- **Record type**: Control
- **Kind**: Technical measure
- **Owner**: Engineering lead
- **Frequency**: Continuous
- **Duties served**: 8

## What the control achieves

Captures what an AI system did, when and with what inputs, and keeps those records long enough to reconstruct a decision, investigate an incident and demonstrate ongoing monitoring.

## How it is typically implemented

Engineers define a log schema for each system that covers at minimum the time of use, the version of model and configuration, the inputs or their references, the output produced and any human intervention. Logs are written automatically, protected against tampering, access-controlled and retained for a period set by the strictest applicable rule and the organisation's own needs. Deployers confirm that logs generated under their control are retained and can be handed to the provider or an authority. Retention, deletion and access are reviewed periodically and the schema is updated when the system changes.

## Evidence it produces

- AI system event logs (access_log): System-generated records of use, versions, inputs, outputs and interventions, retained for the defined period.
- Log schema and retention standard (procedure)
- Log integrity and retention check (audit_report)

## Legal duties this control serves

- Design high-risk systems to log events automatically — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-record-keeping
- Operate a post-market monitoring system — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-post-market-monitoring
- Report serious incidents to market surveillance authorities — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting
- Providers must keep high-risk AI documentation for ten years — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-18-documentation-keeping
- Providers must retain automatically generated logs under their control — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-19-provider-log-retention
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-26-10-post-remote-biometric-identification-authorisation
- Deployers must explain individual decisions taken with high-risk AI on request — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-86-right-to-explanation

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Annex A.6.2.8 — Recording of event logs.
- ISO/IEC 27001:2022: Annex A 8.15 Logging, 8.16 Monitoring activities
- NIST AI RMF 1.0: MEASURE 2.4; MANAGE 4.1
- MITRE ATLAS: AML.M0024 AI Telemetry Logging

## MIT AI Risk Repository subdomains addressed

7.4, 6.5, 2.2

## Provenance

- **Record page**: https://aipolicytracker.org/controls/record-keeping-and-logging
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
