{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-010.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-010",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-010",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-010",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-010.json",
    "title": "Deployer log retention",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Logs a high-risk system generates automatically, to the extent they are under the deployer's control, are kept for at least six months unless other law says otherwise, and longer while an incident is open; retention is code: a schedule per record type, tamper-evident storage, a legal hold that overrides deletion, and the ceiling data protection law sets for the personal data inside them.",
    "failureModes": [
      "Logs under the deployer's control are deleted before six months, or while an incident they bear on is still open.",
      "Logs are overwritten while the decision to stop the system is still being taken.",
      "Everything is kept indefinitely, so the personal data in the logs outlives the storage-limitation ceiling."
    ],
    "scope": "Deployers of high-risk AI systems, for the logs under their control; the same schedule covers the deployer's decision records (decision record, go-live decision, conditions and dissent), kept for the life of the system plus the limitation period counsel sets. For an agent with an Annex III purpose AIGE-CTL-AGENT-030 carries the same six-month floor, and the provider's retention of documentation and logs is AIGE-CTL-ASSURE-008.",
    "enforcementPoints": [
      "runtime",
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Retention schedule per record type, and the log retention period in days in the deployment decision record",
        "schemaId": "deployment-decision-record",
        "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A legal hold overrides deletion: logs under hold, or tied to an open incident, cannot be deleted."
    },
    "layer": 5,
    "secondaryLayers": [
      4
    ],
    "patterns": [
      {
        "slug": "incident-pipeline",
        "title": "Incident Pipeline",
        "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "incident-pipeline",
        "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
      },
      {
        "kind": "schema",
        "ref": "deployment-decision-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
      },
      {
        "kind": "chapter",
        "ref": "governing-deployment",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART26-6",
          "name": "EU AI Act Art. 26(6) deployer retention of automatically generated logs",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-6"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.8",
          "title": "AI system recording of event logs"
        }
      ],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [
        "E015"
      ],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 36,
        "title": "Governing deployment and use",
        "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Records retention\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-deployment#records-retention",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "Incidents, issues and root causes",
        "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Deployer duties: inform the provider, suspend use\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/incidents#deployer-duties-inform-the-provider-suspend-use",
        "verified": "primary"
      },
      {
        "n": 37,
        "title": "Pattern: Incident Pipeline",
        "text": "Pattern: Incident Pipeline (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/incident-pipeline",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 38,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Reconcile the six-month floor for logs with the data protection ceiling per data type, not by keeping everything; keep archive formats someone can still read in ten years.",
      "Where the provider holds the logs, its own six-month floor applies (Art. 19(1)); record who holds which logs."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "How long past the six-month floor logs should be kept for a given intended purpose is left to the deployer; the source material gives no default."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
