ISO/IEC 24970 — AI system logging
Scope: the Sannvit Ledger as a runtime AI-logging component.
| Requirement area | How the Ledger meets it | Status |
|---|---|---|
| Log content & required information (Cl. 5.4, 8.1) | Timestamp, source, action type, and payloads on every entry; inputs and outputs stored by reference plus a cryptographic content hash — the standard's own "reference in place of payload" pattern, with a binding it does not require. | Exceeds |
| Traceability & ordering (Cl. 5.6–5.7, 6.2) | Session, trace, and parent lineage on every event; entry order made cryptographically unforgeable by a hash-chained sequence, where the standard asks only that order "correspond." | Exceeds |
| Integrity & anomaly monitoring (Cl. 5.5, 6.4) | Continuous chain verification across a two-plane, externally time-anchored design, with alerting on integrity and capacity conditions. | Met |
| Event selection & human oversight (Cl. 6.1, 7.2–7.4) | Every consequential AI action captured; human-oversight events sealed with the controller's identity, not kept as editable notes. | Met |
| Storage, retention & access (Cl. 5.7.1, 9.1–9.4) | Persistent storage with a write-once plane, a retention floor with lawful-destruction proof, and role-scoped access enforced in the database. | Met |
The complete clause-by-clause review is available to your counsel under NDA.