{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-004.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-004",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-004.json",
    "title": "Common Signed Evidence Record",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Every control writes a timestamped, signed record on one common schema (control id; subject as registry id and version; decision; metric, value and threshold; failure mode or obligation; input hash; actor; timestamp; signature) to one assurance store keyed on the registry id, and other tools' outputs are normalised into that shape on ingest.",
    "failureModes": [
      "A control's decision leaves no record in the assurance store, or its record lacks the control id, the subject's registry id and version, the decision, the actor, the timestamp or the signature.",
      "Records from different tools keep their own shapes and cannot be joined on the registry id.",
      "A record cannot be shown to be unchanged, because it carries no signature, or to come from a given input, because it carries no input hash."
    ],
    "scope": "Every control of an AI system that decides something (policy verdicts, eval results, guardrail actions, identity events, admissions, go/no-go decisions), whatever tool runs it. What each control decides is set by the control itself.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Evidence record of each control decision, signed and filed in the assurance store under the registry id",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified: the source material states no failure response for this control."
    },
    "layer": 5,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "continuous-assurance-telemetry",
        "title": "Continuous Assurance Telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "continuous-assurance-telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      },
      {
        "kind": "schema",
        "ref": "evidence-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
      },
      {
        "kind": "chapter",
        "ref": "patterns",
        "url": "https://aigovernanceengineer.com/bok/patterns"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART12",
          "name": "EU AI Act Art. 12 record-keeping and logging",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART17",
          "name": "EU AI Act Art. 17 quality management system",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART72",
          "name": "EU AI Act Art. 72 post-market monitoring",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
        },
        {
          "id": "AIGE-OBL-NISTRMF-MANAGE",
          "name": "MANAGE",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": [
        {
          "framework": "ISO/IEC 42001:2023",
          "ref": "9.1",
          "note": "Performance evaluation: monitoring and measurement (cited by the evidence-record and control-observation schemas)"
        }
      ]
    },
    "references": [
      {
        "n": 11,
        "title": "Pattern: Continuous Assurance Telemetry",
        "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems",
        "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "Fix the schema first, then normalise every tool's output into it on ingest, so heterogeneous sources compose into one store queryable by registry id.",
      "Where a record is a normalised copy of a fuller one (an eval result, a go/no-go record, an incident record), link the original with record_ref; keep evidence-bearing fields in the core record, not in extensions."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "Which key signs a record that a third-party tool produced and the ingest pipeline normalised: the tool's, the pipeline's or both?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
