GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-016 Records and Information Governance

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Records required to demonstrate compliance, support operations, and enable audit are identified, protected from unauthorised access, alteration, or loss, and retained for defined periods. Retention and disposal schedules are documented and applied. Each period in the schedule names the obligation it derives from and is set at or above the longest period any obligation binding that record category fixes. Where an obligation measures its period from an event other than creation, the schedule records that measurement point and the storage configuration applies it.

Rationale

Organisations must be able to produce evidence of compliance and operational activity. Records that are lost, altered, or disposed of prematurely undermine auditability and legal defensibility. A period with no obligation behind it cannot be defended, and a period taken from the shortest obligation in the set is the commonest way a schedule goes wrong. The measurement point is the other half: an obligation that runs from the date a document last was in effect keeps a long-lived policy alive for far longer than its stated period suggests, and a lifecycle rule counting from creation quietly deletes it early. Writing one regime's number into this control would make it wrong everywhere else, so the schedule carries the figure and the profile row for each overlay names the instrument it comes from.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.316(b)(2)(i) is now stated by derivation. Each period in the schedule names the obligation it derives from, is set at or above the longest period any obligation binding that category fixes, and carries the measurement point where the obligation counts from something other than creation. For a business associate that obligation is six years from the later of creation and the date the documentation last was in effect, so a policy in force for four years is kept for ten, and it reaches every action, activity and assessment the subpart requires documented: the risk analyses, the determinations, the sanctions applied, the incident records and the evaluations.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (16)

SEF-09Incident Records Managementinformative
SEF-09Incident Records Managementinformative
GDPR-Art.30.1Controller Records of Processing Activities (RoPA)informative
GDPR-Art.30.2Processor Records of Processing Activitiesinformative
COP-S-9.4Retention periodfull
COP-T-1.3Ensuring quality, integrity, and security of informationinformative
HIPAA-164.316.aPolicies and Proceduresinformative
HIPAA-164.316.b.1Documentationfull
HIPAA-164.316.b.2.iTime Limitfull
HIPAA-164.316.b.2.iiAvailabilityinformative
HIPAA-164.316.b.2.iiiUpdatesinformative
5.33Protection of recordsfull
NIS2-CIR-1.1Policy on the Security of Network and Information Systemsinformative
NIS2-CIR-12.2Handling of Assetsinformative
AU-11Audit Record Retentionfull
GV-1.5-003Risk Management Monitoring and Review | GV-1.5-003full

Evidence (2)

policydocumentmanual

Records retention and disposal schedule defining retention periods, storage requirements, and destruction procedures for each category of compliance-relevant record.

Example: Records Retention Schedule (Confluence / legal team document), listing record categories (audit logs, contracts, incident records, training records, etc.), required retention period per category, storage location, and destruction method.

Test: Request the records retention schedule. Verify: (1) all key record categories relevant to the organisation's compliance obligations are listed, (2) a specific retention period is defined for each category, (3) a storage and access control requirement is stated, (4) a destruction method (secure deletion, shredding) is specified, (5) the schedule has been reviewed within the last 12 months. (6) each period names the obligation it derives from and is at or above the longest period any obligation binding that category fixes, checked against the compliance inventory, (7) a category whose obligation measures the period from an event other than creation carries that measurement point in the schedule.

configurationtechnicalautomated

Storage system or logging platform configuration showing automated retention policies are applied in accordance with the retention schedule.

Example: AWS S3 Lifecycle Policy configuration, CloudWatch Logs retention settings, or Google Workspace Vault retention rule export, showing retention periods aligned to the documented retention schedule.

Test: Export or review the retention configuration from the primary storage and logging systems. Verify: (1) automated retention periods are set and match the documented retention schedule for each relevant record category, (2) immutability or write-once settings are enabled for audit log storage, (3) no retention period is shorter than the documented requirement. (4) a category whose period is measured from an event other than creation is configured against that event rather than against the creation date, so a record still in effect is not deleted on the creation clock.

Questions (3)

boolean

Does your organisation have a documented records retention schedule?

The schedule should cover audit logs, contracts, incident records, and training records at minimum, with specific retention periods aligned to legal and regulatory obligations.

select

How are retention policies enforced for your primary storage and logging systems?

Automated retention rules configured in storage / logging platforms (e.g. S3 lifecycle, CloudWatch Logs retention)Scheduled manual processes to archive or delete records per the scheduleRetention is managed informally with no automated or scheduled enforcementNo retention enforcement mechanism is in place

Automated retention configuration (e.g. S3 lifecycle policies, Google Vault rules) aligned to the retention schedule is the strongest evidence. Immutability should be enabled for audit logs.

multi

Which of the following does the retention schedule define for each category of compliance-relevant record?

The retention periodWhere the record is storedHow the record is protected from unauthorised access, alteration or lossThe destruction method applied at the end of the periodThe legal or regulatory obligation the period derives fromThe point the period is measured from, where an obligation measures it from something other than creationNone of the above

Options run from the most commonly defined to the least. A period with no obligation behind it cannot be defended when it is challenged. A schedule with no destruction method leaves records alive past the period it sets. The last item is the one that changes the answer most: an obligation running from the date a document last was in effect keeps a long-lived policy for years past the period its number suggests.