Article 12 Record-keeping


    1. High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.

    1. In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose means the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation; of the system, logging capabilities shall enable the recording of events relevant for:

      1. identifying situations that may result in the high-risk AI system presenting a risk means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident; within the meaning of Article 79(1) or in a substantial modification means a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed;;

      2. facilitating the post-market monitoring referred to in Article 72; and

      3. monitoring the operation of high-risk AI systems referred to in Article 26(5).

    1. For high-risk AI systems referred to in point 1 (a), of Annex III, the logging capabilities shall provide, at a minimum:

      1. recording of the period of each use of the system (start date and time and end date and time of each use);

      2. the reference database against which input data has been checked by the system;

      3. the input data for which the search has led to a match;

      4. the identification of the natural persons involved in the verification of the results, as referred to in Article 14(5).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod