MON-003 Log Retention
Description
Audit logs are retained for a minimum period that meets regulatory and contractual requirements, typically 12 months online and up to 24 months in cold storage. Retention periods are documented and enforced through automated policy. Logs are accessible for investigation throughout the retention window.
Rationale
Many incidents and compliance reviews require evidence from months prior to discovery. Insufficient retention windows destroy forensic capability.
Applicability (9 profiles)
Includes the Art.26.5 minimum of six months for the automatically generated logs of a high-risk system under the deployer's control (AIG-020).
Art.16(e) makes the provider keep the automatically generated logs of its high-risk systems where they are under its control and routes the period to Art.19, whose floor is six months. That is a floor and not a retention schedule: the control's documented periods stand and what the article adds is that a shorter period cannot be contracted or configured away and that the logs in question are the Art.12(1) AI event logs AIG-020 produces, which have to stay retrievable for the access Art.21 lets a competent authority demand.
Art.26(6) sets a floor rather than a period and binds both seats: at least six months for the automatically generated logs of a high-risk system under the deployer's control, longer where Union or national law requires it. At a public body the longer period is the usual case, because public record-keeping and archiving rules commonly reach the same records, so the retention schedule names the rule that sets the period for each system rather than defaulting to six months. The Art.12(3) fields a remote biometric identification log has to carry are stated on AIG-020.
Framework Mappings (8)
| LOG-02 | Audit Logs Protection | partial |
| LOG-02 | Audit Logs Protection | partial |
| EU-AI-Art.16.4 | Provider Obligations — Log Retention | partial |
| EU-AI-Art.19 | Provider Obligations — Automatically Generated Logs and Their Retention | partial |
| EU-AI-Art.26.5 | Deployer Obligations — Log Retention | full |
| HIPAA-164.316.b.2.i | Time Limit | informative |
| NIS2-CIR-3.2 | Monitoring and Logging | informative |
| AU-11 | Audit Record Retention | full |
Evidence (2)
Log retention policy configuration showing automated enforcement of minimum retention periods and tiered storage (online and cold storage) for audit logs.
Example: AWS S3 lifecycle policy for log buckets showing transition to Glacier and expiry dates; CloudWatch Logs retention setting; or equivalent automated retention policy configuration with retention duration visible
Test: Review log retention configuration for all log storage locations. Verify: (1) online retention is at least 12 months; (2) total retention (including cold storage) meets the documented policy and any applicable regulatory requirement (e.g., 24 months); (3) lifecycle policies are automated, not manual; (4) logs are queryable throughout the online retention window.
Log retention policy defining minimum retention durations by log type, storage tiers, and regulatory basis for retention periods.
Example: Log Retention Policy or Data Retention Schedule (version-controlled, approved within last 12 months) showing retention periods by log category and alignment to regulatory requirements
Test: Request the log retention policy. Verify: (1) minimum retention periods are specified for each log category; (2) the policy references applicable regulatory requirements (e.g., GDPR, contractual SLAs); (3) tiered storage approach is described; (4) the policy is approved by a named owner and reviewed within the last 12 months.
Questions (3)
Are audit logs retained for a documented minimum period?
The minimum expected retention is 12 months online and up to 24 months in cold storage. Retention policies should be automated, not dependent on manual archiving.
What is the current minimum retention period for audit logs in your environment?
12 months online with extended cold storage is the standard expectation. For organisations subject to the EU AI Act or GDPR enforcement, ensure retention aligns to applicable regulatory timelines.
Is the retention period enforced by an automated policy on the log store rather than by a manual archiving process?
Answer yes only where the lifecycle or retention rule is set on the store itself, so a log ages out or is preserved without anyone acting. A calendar reminder to archive is not enforcement.