Sigilbase

ISO/IEC 42001 event logs a certifier can sample.

ISO/IEC 42001 is the certifiable management standard for AI. One of its controls, A.6.2.8, concerns event logs. A certifier will ask to see them.

Checked October 2026. This page describes the rules in plain words and is not legal advice. Dates have moved before and may move again.

The control

A.6.2.8, AI system recording of event logs, requires the organisation to determine at which stages of the AI system's life cycle event logging is enabled, and at minimum to log while the system is in use. The point of the control is traceability: being able to reconstruct what the system did.

What a certifier samples

A certifier does not read every log. They pick a period, ask for the records, and test whether the records are what the organisation says they are. The question underneath every sample is whether the log could have been edited between the event and the audit.

What Sigilbase does: makes that question answerable. The sample comes out of a sealed chain, in signed checkpoints, with a verifier the certifier runs themselves. What it does not do: decide which events your system logs, or satisfy any other control in the standard.

Granting access

Auditor access gives a certifier read access to named streams and a date range, for up to 90 days, through one-time sign-in links rather than an account on your tenant. What they open is itself recorded in your ledger.

What this proves, and what it does not

Sigilbase proves that a record has not been modified, deleted or reordered since we received it, when we received it, and which identity sent it. Any lawful redaction is declared, never silent.

It does not prove that a model produced the output in the record, or ran at all. It does not prove a decision was accurate, fair or lawful. It does not prove that everything which happened was recorded; coverage is the sender's control. It does not prove the sender's claimed time, only ours. And it says nothing about the period before the sender started.

Sigilbase is the evidence layer. The conclusion belongs to the person examining the evidence.

Questions about ISO/IEC 42001

  • Is Sigilbase ISO/IEC 42001 certified?

    No. Sigilbase holds no certification of its own, under ISO/IEC 42001 or any other standard. It is a record-keeping service used by organisations seeking certification.

  • Does A.6.2.8 require a third party to hold the logs?

    No. It requires logs. Custody is what makes them evidence rather than assertion, and that is a choice the organisation makes.

Start recording provable history

Chained, sealed, independently verifiable audit logs, from the first event. Free while Sigilbase is in beta.

Start free Read the auditor guide

Questions first? Write to hello@sigilbase.io.

More in this section

Privacy

This site runs no analytics and no trackers.

The site itself collects nothing. If you create a Sigilbase account, the data that involves is described in the privacy policy.

To have your email removed, contact hello@sigilbase.io.

Read the full privacy policy.

Last updated July 2026.