{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-006.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-006",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-006.json",
    "title": "Control Observations Filed Against Control Ids",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Each observation of a reference control is filed as a record naming the control id and version, the subject and its kind, what the control expects, what was observed, whether it held and when, and the evidence records it rests on, so a third party can check it without trusting the observer.",
    "failureModes": [
      "An observation lists no evidence, so a third party has to trust the observer.",
      "An observation does not name the control version it was made against, so it cannot be read once the control changes.",
      "The observer is recorded as a person's name rather than a system or a role.",
      "A control that does not apply to a subject is recorded as passing, instead of not applicable with the reason in the notes."
    ],
    "scope": "Observations of the controls of the open control profiles on this site, whether an adapter, a test or a reviewer makes them.",
    "enforcementPoints": [
      "runtime",
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Control observation: control id and version, subject and kind, expected, observed, status, timestamp and the evidence it rests on",
        "schemaId": "control-observation",
        "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified: the source material states no failure response for this control."
    },
    "layer": 5,
    "secondaryLayers": [
      4
    ],
    "patterns": [
      {
        "slug": "continuous-assurance-telemetry",
        "title": "Continuous Assurance Telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      },
      {
        "slug": "machine-readable-evidence-oscal",
        "title": "Machine-Readable Evidence (OSCAL)",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "control-observation",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-control-observation"
      },
      {
        "kind": "pattern",
        "ref": "continuous-assurance-telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART12",
          "name": "EU AI Act Art. 12 record-keeping and logging",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART17",
          "name": "EU AI Act Art. 17 quality management system",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": [
        {
          "framework": "ISO/IEC 42001:2023",
          "ref": "9.1",
          "note": "Performance evaluation: monitoring and measurement (cited by the evidence-record and control-observation schemas)"
        }
      ]
    },
    "references": [
      {
        "n": 11,
        "title": "Pattern: Continuous Assurance Telemetry",
        "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
        "verified": "primary"
      },
      {
        "n": 13,
        "title": "Pattern: Machine-Readable Evidence (OSCAL)",
        "text": "Pattern: Machine-Readable Evidence (OSCAL) (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems",
        "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "Make each piece of evidence checkable: where it is kept, a digest prefixed with the algorithm, and the schema it validates against when it is a structured record (for example evidence-record or eval-result).",
      "Sign the observation with a detached signature so it is tamper-evident in the evidence store; the evaluation environment profile publishes illustrative pass and fail observations of its specified controls."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "Should an observation an adapter emits and one a reviewer records weigh the same when the status of a control is computed from them?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
