Incomplete Audit Trail
稽核軌跡不完整
Operation & Monitoring
Risk Description
When after a dispute arises, the organization attempts to reconstruct the basis of the original judgment but finds only the final result was retained; due to unmitigated control gaps, it can neither explain the decision process nor demonstrate that the system operated correctly, leaving the dispute unresolvable, triggering compliance exposure and operational reputational costs.
Framework Mappings
ISO/IEC 42001Annex A.6.2.8
NIST AI RMFMANAGE 4.1
ISO/IEC 23894§6.7
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 6
Risk Treatment & Implementation Guidance
Implement tamper-evident audit logs retaining each decision's inputs, basis, model version and timestamps, not merely the final outcome; Define retention scope and periods for each decision type and periodically drill reconstructing decisions from records; Include record completeness in system acceptance and audit scopes