RK-003HighProviderPreventive
Log Retention for Minimum 10 Years
Article 18(1) requires that providers retain technical documentation and logs for at least 10 years after the high-risk AI system is placed on the market or put into service, to enable post-market surveillance and authority access.
Articles:Article 12(2)Article 18(1)
Evidence Examples
- 10-year log retention policy
- Archival storage configuration
- Log lifecycle management procedure
Standards
ISO 42001:2023 §7.5ISO/IEC 27001:2022 A.5.33
Related controls
- RK-001Automatic Event Logging CapabilityArticle 12(1) requires that high-risk AI systems are designed and developed with automatic logging capabilities, enabling the reconstruction of events…
- RK-002Log Integrity and Tamper ProtectionProviders must ensure that logs are protected against tampering, unauthorised deletion, or modification, using cryptographic integrity controls,…
- RK-004Log Accessibility for Competent AuthoritiesProviders must ensure that event logs are accessible to competent national authorities and market surveillance authorities upon request, with procedures…
- RK-005Event Traceability and ReconstructionLogs must enable the tracing and reconstruction of decision events to understand the inputs processed, the outputs generated, and the conditions under…
- RK-006Performance and Operational Metrics LoggingProviders must log performance and operational metrics relevant to verifying that the AI system operates within the parameters established in the…
- RK-007Anomaly and Error Detection LoggingThe logging system must capture anomalous behaviour, errors, and unexpected outputs from the AI system in operation, enabling timely detection of…
Related EU AI Act terms
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview