{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-008.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-008",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-008.json",
    "title": "Evidence Retention as Code",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Each evidence class carries a retention rule keyed to its obligation (for a high-risk system, the technical documentation, QMS documentation and EU declaration for 10 years after placing on the market, and logs under the provider's control for at least six months, set by intended purpose); signed records go to write-once storage and a legal hold overrides deletion.",
    "failureModes": [
      "An evidence class has no retention rule, or its rule is not keyed to the obligation it evidences.",
      "Automatically generated logs are deleted before six months, or the six-month floor is applied as a default whatever the intended purpose.",
      "A signed record sits on storage where it can be overwritten, or is deleted while a legal hold applies.",
      "Personal data in the logs is kept without reconciling the log retention rule with the GDPR's storage limitation."
    ],
    "scope": "Evidence records, logs and documentation of AI systems, above all high-risk systems whose provider keeps documentation under Art. 18 and logs under Art. 19. The deployer's parallel log duty (Art. 26(6), chapter 15) is AIGE-CTL-DEPLOY-010.",
    "enforcementPoints": [
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Retention rule per evidence class, keyed to its obligation, with its storage and any legal hold",
        "schemaId": null,
        "schema": null,
        "layer": 5
      },
      {
        "artefact": "Signed evidence records kept on write-once storage",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A legal hold overrides deletion: a record under hold is not deleted when its retention period ends."
    },
    "layer": 5,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "machine-readable-evidence-oscal",
        "title": "Machine-Readable Evidence (OSCAL)",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "evidence-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      },
      {
        "kind": "chapter",
        "ref": "eu-ai-act",
        "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART18",
          "name": "EU AI Act Art. 18 documentation keeping",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art18"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART19",
          "name": "EU AI Act Art. 19 automatically generated logs kept by the provider",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art19"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART12",
          "name": "EU AI Act Art. 12 record-keeping and logging",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [
        "E015"
      ],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 16,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Record keeping\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#record-keeping",
        "verified": "primary"
      },
      {
        "n": 17,
        "title": "The EU AI Act in one pass",
        "text": "The EU AI Act in one pass (AI Governance Engineering Body of Knowledge v0.5.0, chapter 18, section \"Conformity assessment, declaration, marking and registration\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/eu-ai-act#conformity-assessment-declaration-marking-and-registration",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Keep evidence in open formats (JSON, OSCAL): a 10-year horizon outlives most tools.",
      "Financial institutions keep the logs within their financial-services documentation (Art. 19); other law can set a period other than six months."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "How should a write-once evidence store honour an erasure request for personal data inside a signed record without breaking the record's signature?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
