{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-010.json",
  "source": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-010",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DATA-010",
    "profile": "data-admission-and-privacy",
    "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-010",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-010.json",
    "title": "Lineage from Training Runs to Admitted Sources",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Each training run records the admission records and ledger rows (id and version) it read and the hashes of the admitted snapshots, so backward lineage answers \"what trained this model?\" and forward lineage answers \"which models used this source?\".",
    "failureModes": [
      "A licence withdrawal, an erasure request or an order names a source, and nobody can list the models trained on it.",
      "The model card lists datasets by name but not by version or snapshot hash, so the training cannot be reproduced.",
      "Lineage is kept at dataset level only where rights attach to records, so an opt-out cannot be traced to the runs it affects."
    ],
    "scope": "Training and fine-tuning runs and the datasets, snapshots and ledger rows they read. Evaluation runs are covered for the data they read, not for their results.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [
      {
        "kind": "inspect",
        "text": "For a released model version, the run record names the admission records and ledger rows it read, and a forward-lineage query from one of those sources returns the model version."
      }
    ],
    "evidence": [
      {
        "artefact": "Datasets used to train, validate, test or fine-tune the model on the model card, each named by its dataset card id or linked to its data card, with its role",
        "schemaId": "model-card",
        "schema": "https://aigovernanceengineer.com/schemas/model-card.v1.json",
        "layer": 2
      },
      {
        "artefact": "Link to the lineage record (for example an OpenLineage or W3C PROV graph) on the dataset card",
        "schemaId": "dataset-card",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
        "layer": 2
      },
      {
        "artefact": "Training run record with the code commit, the hashes of the admitted snapshots and the admission records and ledger rows read",
        "schemaId": null,
        "schema": null,
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "A training run that does not record the admission records and ledger rows it read has no backward lineage: until it is restored, a withdrawal or an order cannot be traced to that model version. Which response fits the gap is left to technical review."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "training-data-rights-ledger",
        "title": "Training-Data Rights Ledger",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
      },
      {
        "slug": "dataset-admission-gate",
        "title": "Dataset Admission Gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "slug": "aibom",
        "title": "AIBOM",
        "url": "https://aigovernanceengineer.com/patterns/aibom"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "training-data-rights-ledger",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
      },
      {
        "kind": "pattern",
        "ref": "dataset-admission-gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "kind": "schema",
        "ref": "model-card",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-model-card"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART10",
          "name": "EU AI Act Art. 10 data and data governance",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
        },
        {
          "id": "AIGE-OBL-ISO42001-A7",
          "name": "A.7 Data for AI systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7"
        }
      ],
      "iso42001": [
        {
          "id": "A.7.5",
          "title": "Data provenance"
        }
      ],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 28,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Provenance versus lineage\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#provenance-versus-lineage",
        "verified": "primary"
      },
      {
        "n": 29,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
        "verified": "primary"
      },
      {
        "n": 11,
        "title": "Training-Data Rights Ledger",
        "text": "Training-Data Rights Ledger (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): one ledger row per training source, joined to lineage so each model knows its sources). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger",
        "verified": "primary"
      },
      {
        "n": 1,
        "title": "Dataset Admission Gate",
        "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
        "verified": "primary"
      },
      {
        "n": 30,
        "title": "PROV Overview",
        "text": "PROV Overview (PROV-DM and PROV-O W3C Recommendations of 30 April 2013; provenance as information about entities, activities and people involved in producing data). W3C. 2013-04-30.",
        "url": "https://www.w3.org/TR/prov-overview/",
        "verified": "primary"
      },
      {
        "n": 31,
        "title": "OpenLineage: an open platform for collection and analysis of data lineage",
        "text": "OpenLineage: an open platform for collection and analysis of data lineage (standard API for lineage events over datasets, jobs and runs, with facets). OpenLineage project (The Linux Foundation). 2026.",
        "url": "https://openlineage.io/",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "Record provenance in W3C PROV terms (entities, activities and agents) and emit lineage events over datasets, jobs and runs, so each training run names the admission records it read.",
      "Choose granularity by where rights attach: dataset-level provenance by default, record-level where rights attach to records (personal data, per-source licences, opt-outs), feature-level lineage for sensitive derived features that can act as proxies.",
      "List the datasets by version in the AIBOM as well."
    ],
    "openQuestions": [
      "The site publishes no schema for a model training run (the published training-record schema covers AI literacy training): should one be published, or should the model card and AIBOM carry the run fields?",
      "Should a training run with no recorded lineage block the release of the model version it produced, or only raise an alert to its owner?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
