ISO/IEC 42001 event logs a certifier can sample.
ISO/IEC 42001 is the certifiable management standard for AI. One of its controls, A.6.2.8, concerns event logs. A certifier will ask to see them.
Checked October 2026. This page describes the rules in plain words and is not legal advice. Dates have moved before and may move again.
The control
A.6.2.8, AI system recording of event logs, requires the organisation to determine at which stages of the AI system's life cycle event logging is enabled, and at minimum to log while the system is in use. The point of the control is traceability: being able to reconstruct what the system did.
What a certifier samples
A certifier does not read every log. They pick a period, ask for the records, and test whether the records are what the organisation says they are. The question underneath every sample is whether the log could have been edited between the event and the audit.
What Sigilbase does: makes that question answerable. The sample comes out of a sealed chain, in signed checkpoints, with a verifier the certifier runs themselves. What it does not do: decide which events your system logs, or satisfy any other control in the standard.
Granting access
Auditor access gives a certifier read access to named streams and a date range, for up to 90 days, through one-time sign-in links rather than an account on your tenant. What they open is itself recorded in your ledger.
What this proves, and what it does not
Sigilbase proves that a record has not been modified, deleted or reordered since we received it, when we received it, and which identity sent it. Any lawful redaction is declared, never silent.
It does not prove that a model produced the output in the record, or ran at all. It does not prove a decision was accurate, fair or lawful. It does not prove that everything which happened was recorded; coverage is the sender's control. It does not prove the sender's claimed time, only ours. And it says nothing about the period before the sender started.
Sigilbase is the evidence layer. The conclusion belongs to the person examining the evidence.
Questions about ISO/IEC 42001
-
Is Sigilbase ISO/IEC 42001 certified?
No. Sigilbase holds no certification of its own, under ISO/IEC 42001 or any other standard. It is a record-keeping service used by organisations seeking certification.
-
Does A.6.2.8 require a third party to hold the logs?
No. It requires logs. Custody is what makes them evidence rather than assertion, and that is a choice the organisation makes.
Start recording provable history
Chained, sealed, independently verifiable audit logs, from the first event. Free while Sigilbase is in beta.
Start free Read the auditor guide
Questions first? Write to hello@sigilbase.io.
More in this section
- AI audit records. Why an AI decision log needs a custodian, and the rules that ask for one.
- AI decision logging. One event per decision, what to put in it, and what it proves.
- Records of what an AI agent did. Agents as actors, tool calls as events, credentials on loan.
- EU AI Act record-keeping, plainly. Articles 12, 19 and 26 in plain words, and where Sigilbase fits.
- UK automated decisions. The 2025 Act's safeguards, and the record a contested decision needs.
- For AI assurance providers. The verifier, auditor grants and how to request evidence.