{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-002.json",
  "source": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DATA-002",
    "profile": "data-admission-and-privacy",
    "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-002.json",
    "title": "Dataset Card for Every Admitted Version",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Every dataset version that is admitted carries a dataset card that states its owner, purpose, provenance, lawful basis, licence and retention rule, and the admission gate checks the card is complete before it admits the version.",
    "failureModes": [
      "A dataset is admitted with a card that lacks a lawful basis, a provenance, a retention limit or a licence, so the rights and the deletion date cannot be read from it.",
      "The card describes a previous version: its composition, representativeness or quality checks no longer match the snapshot that was admitted.",
      "The card is written from memory after training instead of filled from the admission record and lineage."
    ],
    "scope": "Datasets admitted to training, fine-tuning, validation, testing, evaluation or retrieval-index pipelines, one card per version. The model card and the system card, which describe what was built from the data, are out of scope.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [
      {
        "kind": "inspect",
        "text": "The card of each admitted version validates against dataset-card.v1 (dataset id, version, name, owner, description, provenance, lawful basis, licence and retention rule), and the admission record links to it."
      }
    ],
    "evidence": [
      {
        "artefact": "Dataset card per admitted version",
        "schemaId": "dataset-card",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
        "layer": 2
      },
      {
        "artefact": "Card-completeness check on the admission record",
        "schemaId": "dataset-admission-record",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
        "layer": 1
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A version whose card is missing or incomplete is not admitted; the admission record names the card that was checked."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "dataset-admission-gate",
        "title": "Dataset Admission Gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "slug": "model-card-as-control-evidence",
        "title": "Model Card as Control Evidence",
        "url": "https://aigovernanceengineer.com/patterns/model-card-as-control-evidence"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "dataset-card",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
      },
      {
        "kind": "pattern",
        "ref": "dataset-admission-gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART10",
          "name": "EU AI Act Art. 10 data and data governance",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
        },
        {
          "id": "AIGE-OBL-ISO42001-A7",
          "name": "A.7 Data for AI systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7"
        }
      ],
      "iso42001": [
        {
          "id": "A.7.2",
          "title": "Data for development and enhancement of AI system"
        },
        {
          "id": "A.7.5",
          "title": "Data provenance"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MAP 2.3",
          "title": "Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 2,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Data for training and testing\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#data-for-training-and-testing",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Model cards, system cards and datasheets\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#model-cards-system-cards-and-datasheets",
        "verified": "primary"
      },
      {
        "n": 1,
        "title": "Dataset Admission Gate",
        "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
        "verified": "primary"
      },
      {
        "n": 10,
        "title": "Datasheets for Datasets (Gebru et al.; arXiv 1803.09010)",
        "text": "Datasheets for Datasets (Gebru et al.; arXiv 1803.09010) (motivation, composition, collection, preprocessing, uses, distribution and maintenance). arXiv. 2018-03-23.",
        "url": "https://arxiv.org/abs/1803.09010",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10 (data and data governance: 10(2) practices, including origin, preparation, bias examination and mitigation, and data gaps; 10(3) relevant, sufficiently representative, free of errors and complete; 10(4) specific setting of use). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 8,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Fill the card from the same records the gate reads (the admission record and lineage), so the datasheet travels with the admission record and covers motivation, composition, collection, preprocessing, uses, distribution and maintenance.",
      "Record in the card who the data does and does not represent (populations and known gaps) and the quality and bias checks run against this version, with their results."
    ],
    "openQuestions": [
      "Which optional card fields (composition, representativeness, quality checks, splits) should become mandatory for data admitted to a high-risk system?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
