Records Management
Regulatory Documentation Retention
What this control does
Retain required AI compliance documentation for mandated periods and ensure it remains retrievable.
How to implement
Build a record schedule by record type, legal basis and responsible actor, rather than giving every AI record the same retention period. Identify the applicable start and end triggers, retrieval requirements, access restrictions and any required deletion. Retain necessary compliance evidence while avoiding unnecessary sensitive data. Assign record owners and check that systems enforce the schedule. Where legal holds or competing obligations arise, obtain a documented decision rather than silently overriding a specific deletion duty.
Suggested timing and triggers
Throughout the record lifecycle; at the applicable retention or deletion trigger; after legal or system changes; periodic sampling.
Evidence examples
Record inventory with legal basis, owner and retention triggers Configured access, retention and disposal settings Retrieval tests and retained approval records Deletion confirmations and documented holds or exceptions
How to check this control
Sample different record types, including logs and sensitive data. Check that actual settings match the relevant schedule, records can be retrieved when needed and a due deletion was completed or escalated for a documented reason.
Related EU AI Act obligations
Article 4a(1)(e), 4a(2)(b)
Delete Special-Category Data When Bias Is Corrected or the Retention Period Ends
Sub-obligation of Article 4a: Apply Required Safeguards When Processing Special-Category Data for Bias Detection or Correction
Article 18
Retain Required High-Risk AI Documentation for Ten Years
Article 19
Retain Automatically Generated High-Risk AI Logs
Article 22(3)(b)
Retain Required Provider and Conformity Documentation for Ten Years
Sub-obligation of Article 22(3)-(4): Perform Required High-Risk AI Authorised Representative Duties
Article 23(5)
Retain Required Importer Documentation for Ten Years
Sub-obligation of Article 23: Fulfil Importer Obligations Before and After Placing High-Risk AI on the EU Market
Article 26(6)
Retain High-Risk AI Logs Under the Deployer's Control
Article 26(10), fifth subparagraph
Document Each Post-Remote Biometric Identification Use and Make Records Available on Request
Sub-obligation of Article 26(10): Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
Article 47; Annex V
Draw Up, Maintain and Retain the EU Declaration of Conformity for High-Risk AI
Article 54(3)(b)
Retain GPAI Technical Documentation and Provider Contact Details for Ten Years
Sub-obligation of Article 54(3)-(5): Perform Required GPAI Authorised Representative Duties
Article 33(4)
Retain Subcontractor and Subsidiary Qualification Records for Five Years
Sub-obligation of Article 33: Govern Subsidiaries and Subcontractors Used for AI Conformity Assessment
Article 59(1)(g)-(h)
Protect, Delete and Log Personal Data Processed in the Sandbox
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox