GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

MON-003 Log Retention

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Audit logs are retained for a minimum period that meets regulatory and contractual requirements, typically 12 months online and up to 24 months in cold storage. Retention periods are documented and enforced through automated policy. Logs are accessible for investigation throughout the retention window.

Rationale

Many incidents and compliance reviews require evidence from months prior to discovery. Insufficient retention windows destroy forensic capability.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore

Includes the Art.26.5 minimum of six months for the automatically generated logs of a high-risk system under the deployer's control (AIG-020).

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

Art.16(e) makes the provider keep the automatically generated logs of its high-risk systems where they are under its control and routes the period to Art.19, whose floor is six months. That is a floor and not a retention schedule: the control's documented periods stand and what the article adds is that a shorter period cannot be contracted or configured away and that the logs in question are the Art.12(1) AI event logs AIG-020 produces, which have to stay retrievable for the access Art.21 lets a competent authority demand.

Public Body Deployer (EU)stablerequiredrole duty

Art.26(6) sets a floor rather than a period and binds both seats: at least six months for the automatically generated logs of a high-risk system under the deployer's control, longer where Union or national law requires it. At a public body the longer period is the usual case, because public record-keeping and archiving rules commonly reach the same records, so the retention schedule names the rule that sets the period for each system rather than defaulting to six months. The Art.12(3) fields a remote biometric identification log has to carry are stated on AIG-020.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (8)

LOG-02Audit Logs Protectionpartial
LOG-02Audit Logs Protectionpartial
EU-AI-Art.16.4Provider Obligations — Log Retentionpartial
EU-AI-Art.19Provider Obligations — Automatically Generated Logs and Their Retentionpartial
EU-AI-Art.26.5Deployer Obligations — Log Retentionfull
HIPAA-164.316.b.2.iTime Limitinformative
NIS2-CIR-3.2Monitoring and Logginginformative
AU-11Audit Record Retentionfull

Evidence (2)

configurationtechnicalautomated

Log retention policy configuration showing automated enforcement of minimum retention periods and tiered storage (online and cold storage) for audit logs.

Example: AWS S3 lifecycle policy for log buckets showing transition to Glacier and expiry dates; CloudWatch Logs retention setting; or equivalent automated retention policy configuration with retention duration visible

Test: Review log retention configuration for all log storage locations. Verify: (1) online retention is at least 12 months; (2) total retention (including cold storage) meets the documented policy and any applicable regulatory requirement (e.g., 24 months); (3) lifecycle policies are automated, not manual; (4) logs are queryable throughout the online retention window.

policydocumentmanual

Log retention policy defining minimum retention durations by log type, storage tiers, and regulatory basis for retention periods.

Example: Log Retention Policy or Data Retention Schedule (version-controlled, approved within last 12 months) showing retention periods by log category and alignment to regulatory requirements

Test: Request the log retention policy. Verify: (1) minimum retention periods are specified for each log category; (2) the policy references applicable regulatory requirements (e.g., GDPR, contractual SLAs); (3) tiered storage approach is described; (4) the policy is approved by a named owner and reviewed within the last 12 months.

Questions (3)

boolean

Are audit logs retained for a documented minimum period?

The minimum expected retention is 12 months online and up to 24 months in cold storage. Retention policies should be automated, not dependent on manual archiving.

select

What is the current minimum retention period for audit logs in your environment?

24 months or more (online or tiered storage)12 months online, with additional cold storage beyond 12 months12 months online only6 monthsLess than 6 months or no defined retention period

12 months online with extended cold storage is the standard expectation. For organisations subject to the EU AI Act or GDPR enforcement, ensure retention aligns to applicable regulatory timelines.

boolean

Is the retention period enforced by an automated policy on the log store rather than by a manual archiving process?

Answer yes only where the lifecycle or retention rule is set on the store itself, so a log ages out or is preserved without anyone acting. A calendar reminder to archive is not enforcement.