Domain 12Introduced in v1.0

Auditability and Transparency

L1L2L326 ACRs (26 defined in current release)

Summary#

Decision logs, audit replay, and compliance reporting

Applicability#

Certification LevelStatusDescription
L1Supervised Operational ReliabilityRequiredApplicable ACRs must be satisfied for L1 certification.
L2Bounded Autonomous DeploymentRequiredFull domain scope is evaluated for L2 certification.
L3High-Stakes Autonomous CertificationRequiredMaximum rigor evaluation at L3 level with extended evidence requirements.

Risk Rationale#

Linked ACR Controls#

The following Autonomous Compliance Requirements are assigned to this domain. Each ACR defines a specific, testable control with its own evaluation method, classification, and evidence requirements.

ACR-12.01

The system SHALL maintain decision logs for all autonomous decisions with sufficient detail for post

The system SHALL maintain decision logs for all autonomous decisions with sufficient detail for post-hoc reconstruction.

AT+EI|Risk weight: 5/10|
L1L2L3
ACR-12.02

Exportable audit artifacts SHALL be provided in standardized formats accessible to third-party audit

Exportable audit artifacts SHALL be provided in standardized formats accessible to third-party auditors.

EI+AT|Risk weight: 4/10|
L1L2L3
ACR-12.03

Version control SHALL be maintained for all system components, configurations, and policies with ful

Version control SHALL be maintained for all system components, configurations, and policies with full change history.

EIEvidence Inspection|Risk weight: 4/10|
L1L2L3
ACR-12.04

Third-party audit replay SHALL be supported enabling independent assessors to reproduce and evaluate

Third-party audit replay SHALL be supported enabling independent assessors to reproduce and evaluate system behavior.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-12.05

The system SHALL support third-party audit replay from logged data.

The system SHALL support third-party audit replay from logged data.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-12.06

Retention policies SHALL ensure audit data is preserved for a period appropriate to the system's ris

Retention policies SHALL ensure audit data is preserved for a period appropriate to the system's risk classification.

EIEvidence Inspection|Risk weight: 3/10|
L1L2L3
ACR-12.07

Compliance evidence generation capabilities SHALL map system records to specific ACR requirements.

Compliance evidence generation capabilities SHALL map system records to specific ACR requirements.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-12.08

Chain of custody SHALL be maintained for all evidence artifacts used in certification and ongoing co

Chain of custody SHALL be maintained for all evidence artifacts used in certification and ongoing compliance.

EIEvidence Inspection|Risk weight: 4/10|
L1L2L3
ACR-12.09

Automated compliance reporting against the ARA Standard's requirements SHALL be supported.

Automated compliance reporting against the ARA Standard's requirements SHALL be supported.

AT+EI|Risk weight: 3/10|
L1L2L3
ACR-12.10

Audit mechanisms SHALL NOT introduce performance degradation that affects system reliability.

Audit mechanisms SHALL NOT introduce performance degradation that affects system reliability.

ATAutomated Testing|Risk weight: 3/10|
L1L2L3
ACR-12.11

Access controls for audit data SHALL prevent unauthorized access while enabling legitimate review.

Access controls for audit data SHALL prevent unauthorized access while enabling legitimate review.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-12.12

The system SHALL provide transparency reports documenting system behavior trends, incident summaries

The system SHALL provide transparency reports documenting system behavior trends, incident summaries, and compliance status.

EIEvidence Inspection|Risk weight: 3/10|
L1L2L3
ACR-12.13

Audit log immutability SHALL be enforced through cryptographic or append-only storage mechanisms.

Audit log immutability SHALL be enforced through cryptographic or append-only storage mechanisms.

AT+EI|Risk weight: 5/10|
L1L2L3
ACR-12.14

The system SHALL support granular audit queries by time range, action type, decision outcome, and en

The system SHALL support granular audit queries by time range, action type, decision outcome, and entity.

ATAutomated Testing|Risk weight: 3/10|
L1L2L3
ACR-12.15

Audit data SHALL include sufficient metadata for correlation with external compliance and regulatory

Audit data SHALL include sufficient metadata for correlation with external compliance and regulatory records.

EI+AT|Risk weight: 3/10|
L1L2L3
ACR-12.16

The system SHALL log all access to audit data itself, creating an audit trail of audit trail access.

The system SHALL log all access to audit data itself, creating an audit trail of audit trail access.

ATAutomated Testing|Risk weight: 3/10|
L1L2L3
ACR-12.17

System documentation SHALL be maintained at a level of detail sufficient for independent technical r

System documentation SHALL be maintained at a level of detail sufficient for independent technical review.

EIEvidence Inspection|Risk weight: 4/10|
L1L2L3
ACR-12.18

The system SHALL support evidence artifact linking that traces from certification decisions back to

The system SHALL support evidence artifact linking that traces from certification decisions back to source data.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-12.19

Audit capabilities SHALL cover the full lifecycle from input receipt through decision to action exec

Audit capabilities SHALL cover the full lifecycle from input receipt through decision to action execution and outcome.

AT+EI|Risk weight: 4/10|
L1L2L3
ACR-12.20

The system SHALL preserve audit trail integrity during system failures and recovery procedures.

The system SHALL preserve audit trail integrity during system failures and recovery procedures.

ATAutomated Testing|Risk weight: 4/10|
L1L2L3
ACR-12.21

Multi-party audit support SHALL be available for systems operating across organizational boundaries.

Multi-party audit support SHALL be available for systems operating across organizational boundaries.

EI+AT|Risk weight: 3/10|
L1L2L3
ACR-12.22

The system SHALL generate human-readable explanations of autonomous decisions upon authorized reques

The system SHALL generate human-readable explanations of autonomous decisions upon authorized request.

AT+HS|Risk weight: 4/10|
L1L2L3
ACR-12.23

Audit data schema changes SHALL be backward-compatible to maintain historical audit query capability

Audit data schema changes SHALL be backward-compatible to maintain historical audit query capability.

EI+AT|Risk weight: 3/10|
L1L2L3
ACR-12.24

Compliance status dashboards SHALL provide real-time visibility into ACR compliance across all domai

Compliance status dashboards SHALL provide real-time visibility into ACR compliance across all domains.

EI+AT|Risk weight: 3/10|
L1L2L3
ACR-12.25

The AVB SHALL produce a documented Risk Classification Report as part of every Deployment Certificat

The AVB SHALL produce a documented Risk Classification Report as part of every Deployment Certification evaluation. The report SHALL address all seven classification factors (degree of autonomy, consequence severity, reversibility, breadth of impact, regulatory context, dependency criticality, operational continuity), state the resulting Assurance Class, and provide justification for the determination.

EI+TP|Risk weight: 4/10|
L1L2L3
ACR-12.26

The Risk Classification Report SHALL be delivered to the deploying organization and to ARAF as part

The Risk Classification Report SHALL be delivered to the deploying organization and to ARAF as part of the certification evidence package. The organization SHALL sign acknowledgment of the assigned Assurance Class before certification is granted.

EI+OP|Risk weight: 4/10|
L1L2L3