unified
UC-AI-08 — Log and monitor AI system behavior in operation
Ensure AI systems automatically record event logs that enable traceability of operation over the system's lifetime, including events relevant to identifying risk situations and substantial modification. Retain logs for at least the mandated regulatory minimum, or longer where required. Monitor deployed systems against defined performance and behavior metrics with alerting and escalation for anomalies and drift, and retain logs and monitoring reviews as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- AI Governance
- type
- detective
- category
- technical
Details
- unified_id
- UC-AI-08
- title
- Log and monitor AI system behavior in operation
- statement
- Ensure AI systems automatically record event logs that enable traceability of operation over the system's lifetime, including events relevant to identifying risk situations and substantial modification. Retain logs for at least the mandated regulatory minimum, or longer where required. Monitor deployed systems against defined performance and behavior metrics with alerting and escalation for anomalies and drift, and retain logs and monitoring reviews as evidence.
- domain
- AI Governance
- control_type
- detective
- control_category
- technical
- members
- framework
- iso-42001
- control_id
- A.6.2.6
- coverage
- full
- relationship
- superset_of
- framework
- iso-42001
- control_id
- A.6.2.8
- coverage
- full
- relationship
- superset_of
- framework
- eu-ai-act
- control_id
- AIA-Art12
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- C008
- coverage
- partial
- delta
- monitoring keyed to the AI risk taxonomy categories with per-category alert thresholds and response actions
- relationship
- intersects_with
- framework
- aiuc-1
- control_id
- E015
- coverage
- full
- relationship
- superset_of
- framework
- eu-ai-act
- control_id
- AIA-Art19
- coverage
- full
- relationship
- superset_of
- framework
- eu-ai-act
- control_id
- AIA-Art72
- coverage
- partial
- delta
- a documented post-market monitoring plan, proportionate to the system's risk, that actively collects and analyses lifetime performance data including interaction with other AI systems
- relationship
- intersects_with
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-05
- propositionTitle
- Verifiable agent action logs and authorization traceability
- sourcePages
- Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency
- source
- nist-ai-tevv-athlon
- sourceTitle
- NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
- propositionId
- NIST-TEVV-02
- propositionTitle
- Run evaluations and examine results and limitations
- sourcePages
- NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7
Source
No record-specific source URL is provided.
Connections
- UC-AI-08 — Log and monitor AI system behavior in operation maps_to A.6.2.8 — AI system recording of event logs
- framework
- iso-42001
- control_id
- A.6.2.8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-08 — Log and monitor AI system behavior in operation mitigates AI accountability gaps and organizational liability
- strength
- related
- rationale
- Lifetime event logs provide the traceability/audit trail underpinning accountability for AI operation.
- ISO/IEC 42001 AI Management System Internal Audit tests UC-AI-08 — Log and monitor AI system behavior in operation
- UC-AI-08 — Log and monitor AI system behavior in operation maps_to AIA-Art72 — Post-market monitoring by providers of high-risk AI systems
- framework
- eu-ai-act
- control_id
- AIA-Art72
- coverage
- partial
- delta
- a documented post-market monitoring plan, proportionate to the system's risk, that actively collects and analyses lifetime performance data including interaction with other AI systems
- relationship
- intersects_with
- source_version
- Regulation (EU) 2024/1689
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- AI Governance & Risk/Impact Assessment oversees UC-AI-08 — Log and monitor AI system behavior in operation
- UC-AI-08 — Log and monitor AI system behavior in operation mitigates Inaccurate, unreliable or hallucinated AI outputs
- strength
- related
- rationale
- Performance monitoring detects post-deployment accuracy degradation so wrong outputs are caught in operation.
- UC-AI-08 — Log and monitor AI system behavior in operation mitigates Model/data drift and inadequate post-deployment monitoring
- strength
- primary
- rationale
- Continuous monitoring against performance/behavior metrics with drift and anomaly alerting is the post-deployment detection the risk says is missing.
- UC-AI-08 — Log and monitor AI system behavior in operation maps_to A.6.2.6 — AI system operation and monitoring
- framework
- iso-42001
- control_id
- A.6.2.6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-08 — Log and monitor AI system behavior in operation maps_to AIA-Art12 — Record-keeping / logging (high-risk)
- framework
- eu-ai-act
- control_id
- AIA-Art12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Regulation (EU) 2024/1689
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-08 — Log and monitor AI system behavior in operation mitigates Rights violations from AI in law enforcement
- strength
- primary
- rationale
- Automatic event logging and traceability is the mandated logging control supporting law-enforcement-AI accuracy and oversight requirements.
- UC-AI-08 — Log and monitor AI system behavior in operation mitigates Insufficient AI resilience and fallback mechanisms
- strength
- related
- rationale
- Anomaly alerting and escalation trigger failure response before dependent business processes break.
- UC-AI-08 — Log and monitor AI system behavior in operation mitigates AI safety failures causing physical or psychological harm
- strength
- related
- rationale
- Behavior monitoring with alerting detects unsafe operation for escalation, reducing harm impact.
- AI Operations Monitoring & Incident Response operates UC-AI-08 — Log and monitor AI system behavior in operation
- UC-AI-08 — Log and monitor AI system behavior in operation informed_by NIST-AGI-05 — Verifiable agent action logs and authorization traceability
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-05
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency
- UC-AI-08 — Log and monitor AI system behavior in operation informed_by NIST-TEVV-02 — Run evaluations and examine results and limitations
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-02
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7
- UC-AI-08 — Log and monitor AI system behavior in operation maps_to E015 — Log AI system activity
- framework
- aiuc-1
- control_id
- E015
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-08 — Log and monitor AI system behavior in operation maps_to C008 — Monitor AI risk categories
- framework
- aiuc-1
- control_id
- C008
- coverage
- partial
- delta
- monitoring keyed to the AI risk taxonomy categories with per-category alert thresholds and response actions
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-08 — Log and monitor AI system behavior in operation maps_to AIA-Art19 — Automatically generated logs — provider retention of high-risk system logs (minimum six months)
- framework
- eu-ai-act
- control_id
- AIA-Art19
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Regulation (EU) 2024/1689
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.