GAISSF / D6 / D6-CTL-02

Audit Trail Completeness

Objective

Enable forensic investigation + regulatory compliance.

Control / requirement

Structured logging + SIEM integration + retention enforcement.

Business impact

Incomplete audit trails prevent incident investigation and violate regulatory requirements (DORA 5-year retention, GDPR logging), with potential fines and inability to defend in court.

Validation approach

Test ID: D6-CTL-02-VTS-001 Test Type: Automated Test Design: Request audit log for specific AI decision made within last 30 days Execution Steps: 1. Generate test decision 2. Wait 1 hour 3. Query audit log 4. Verify required fields Pass Criteria: log_returned_with_all_fields = True; retention_meets_policy (min 1yr Fnd, 3yr Op, 7yr Opt) Independent Verification: Auditor queries audit log and verifies completeness.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.