Skip to content
arrow_back
Annex A 6.2.8psychologyISO/IEC 42001:2023

AI System Recording of Event Logs

Your organisation decides, and writes down, at which stages of an AI system's life its event logs (automatic records of what the system did and when) are switched on, and they must be on at least while the system is in use.

record_voice_over

Plain language

An event log is an automatic record an AI system keeps of what it did and when, for example which inputs it received, what it produced, who used it, and any errors or warnings. This control asks your organisation to make a deliberate decision about when those logs are turned on across the AI system's whole life, from building and training it, through testing, into everyday use, and on to retraining, major changes and eventually shutting it down. You do not have to log at every single stage, but you must consciously choose which stages need logging and record that choice. The one stage you cannot skip is when the AI system is in use: logging must be enabled at the minimum during live operation. Picture an AI chatbot that tells a customer something that is not true. If logging was switched on during use, you can look back at exactly what the customer asked, what the system answered, and what data it drew on, so you can work out what went wrong. Without that record, you are guessing.

Framework

ISO/IEC 42001:2023

Control effect

Detective

Classifications

N/A

Official last update

01 Dec 2023

Control Stack last updated

19 June 2026

Official control statement

The organisation shall determine at which phases of the AI system life cycle, record keeping of event logs should be enabled, but at the minimum when the AI system is in use.
psychologyISO/IEC 42001:2023Annex A 6.2.8
priority_high

Why it matters

If logging was never turned on during live use, and an AI loan tool wrongly declines a cohort of applicants, you have no record of the inputs or decisions and cannot reconstruct what happened, so you cannot prove fairness, fix the fault, or answer an OAIC complaint. The organisation may have to suspend the system rather than defend it, because there is nothing to investigate. Failing to even decide which life-cycle phases need logging is itself an audit finding against this control.

settings

Operational notes

Capture the phase-determination decision in a short written record that names each life-cycle stage (development, training, testing, in-use operation, retraining or major change, and decommissioning) and states whether logging is on or off for each, with in-use always on. Revisit that decision whenever you add a new AI system, change how an existing one is used, or move it to a new phase, so the logging stays matched to what the system is actually doing. Keep enough detail in the logs to reconstruct an event, but record the reasoning for any phase where you chose not to log.

build

Implementation tips

  • The AI lead writes a short phase-determination record that walks through each stage of the AI system's life, development, training, testing, in-use operation, retraining or major change, and decommissioning, and marks for each stage whether event logging is switched on, making sure the in-use stage is always on.
  • When deciding what the in-use logs should hold, the AI lead specifies the detail needed to reconstruct an event later, for example the inputs received, the output produced, a timestamp, the user or system involved, and any errors or warnings the AI raised.
  • For any life-cycle phase where the team decides not to log, the AI lead records the reason in the same document, so a reviewer can see the gap was a conscious choice rather than an oversight.
  • The AI lead assigns one named owner for this decision and links it to the AI system inventory, so whenever a new AI system is introduced its logging phases are decided up front rather than after a problem appears.
  • Whoever owns an AI system revisits the phase-determination record when the system moves to a new phase, such as going live, being retrained, or being decommissioned, and updates which phases are logged so the record keeps matching what the system is actually doing.
fact_check

Audit / evidence tips

  • AskAsk for the written record that determines at which AI system life-cycle phases event logging is enabled.GoodA documented decision names each life-cycle phase and states whether event logging is enabled at that phase, rather than leaving it unstated.
  • AskAsk which phases were chosen for logging and confirm the in-use phase is included.GoodEvent logging is enabled at least while the AI system is in use, and this is stated in the phase-determination record.
  • AskRequest a sample of actual event logs captured from an AI system while it was in use.GoodThe logs show real recorded events from the in-use phase, matching the phases the organisation said it would log.
  • AskAsk who owns the decision on which phases are logged and how it is kept current.GoodA named owner maintains the phase-determination decision and updates it when AI systems are added or move to a new life-cycle phase.
  • AskAsk to see the reasoning for any life-cycle phase where logging was deliberately switched off.GoodEach non-logged phase has a recorded reason, showing the choice was deliberate rather than an unconsidered gap.
link

Cross-framework mappings

How Annex A 6.2.8 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 8.15Annex A 6.2.8 requires the organisation to determine at which AI system life cycle phases event logging should be enabled, at minimum whe...

E8

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
E8-AC-ML2.6Annex A 6.2.8 requires the organisation to enable event logging for AI systems during defined life cycle phases, at minimum when the AI s...

ASD ISM

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
ISM-0585Annex A 6.2.8 requires enabling event logs for AI systems at defined life cycle phases, at minimum during operational use
handshakeSupports(1)expand_less
ISM-0580Annex A 6.2.8 requires the organisation to decide during which AI system life cycle phases event logging is enabled (at minimum during use)

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all A.6 AI system life cycle controls, or browse the full ISO/IEC 42001:2023 library.

psychology

Want to implement this AI control?

Mindset Cyber runs PECB-accredited ISO/IEC 42001 training that maps directly to the AI controls in this library.

Mapping detail

Mapping

Direction

Controls