AI Training Data Provenance Checker
Public open data · source class

Academic or research dataset

Research datasets are often released for research only, whatever the download page looks like.

What to record for it

The paper or publisher, the licence text, the version, and the date downloaded.

Personal data is possible: where your personal data column is blank the checker says it could not determine it.

A line that places here

example

Reviews corpus | public dataset | CC BY 4.0

Check this line

What the checker reads on these lines

7 of the 12 findings

Clauses

5 regimes
RegimeClause
ISO/IEC 42001ISO/IEC 42001 A.7.3 Acquisition of data
ISO/IEC 42001 A.7.5 Data provenance
NIST AI RMFNIST AI RMF MP-4.1 Legal risks of components and third-party data
NIST AI RMF GV-6.1 Third-party and intellectual property risk policy
EU AI ActEU AI Act Art. 10 Data and data governance
GDPRGDPR Art. 14 Information where personal data have not been obtained from the data subject
UK GDPRUK GDPR Art. 14 Information to be provided where personal data have not been obtained from the data subject

The clauses, set out

ISO/IEC 42001 A.7.3Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

What an auditor asks to see: Data acquisition records; Provenance documentation; Consent records; Source identification; Licensing or consent evidence; Selection criteria and rejection rationale
What an auditor will probe: Is data provenance traceable to lawful sources?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.7.5Data provenance

The organization shall document the provenance of data used in AI systems to enable evaluation and traceability.

What an auditor asks to see: Provenance records; Lineage diagrams; End-to-end data lineage from source to model; Transformations documented; Datasheets
What an auditor will probe: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023
NIST AI RMF MP-4.1Legal risks of components and third-party data

Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third-party’s intellectual property or other rights. There is a followed approach for mapping the technology and legal risk carried by each component, including data and software obtained from third parties and the rights position attached to them.

What an auditor asks to see: The documented approach for mapping component technology and legal risk; Component inventory identifying third-party data, models and software; Intellectual property and rights analysis for each third-party component; Evidence the approach was followed for the components actually in use
What an auditor will probe: Approach documented but not applied to components adopted since; Pre-trained models used with no analysis of the provenance of their training data; Rights reviewed for commercial components only, not for freely obtained ones
Source: NIST AI Risk Management Framework
NIST AI RMF GV-6.1Third-party and intellectual property risk policy

Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third party’s intellectual property or other rights. Third-party AI risk is addressed by policy covering data, models, software and services obtained externally, including the rights position on training data and model outputs.

What an auditor asks to see: Third-party AI policy covering data, pre-trained models, software and services; Due diligence records for third-party AI components in use; Contract terms addressing intellectual property, data rights and liability for AI components; The intellectual property position recorded for training data and model outputs
What an auditor will probe: Standard vendor due diligence applied with no AI-specific questions; Open source models adopted with no review of the licence or the training data provenance; Policy addresses suppliers but not freely obtained models and datasets
Source: NIST AI Risk Management Framework
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex III

High-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.

What an auditor asks to see: Data governance procedures; Bias examination records and remediation; Data-quality assessment per dataset
What an auditor will probe: Training data used without bias examination; Datasets not representative of the deployment context
Source: EU AI Act
GDPR Art. 14Information where personal data have not been obtained from the data subject

Where personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.

What an auditor asks to see: A source register showing, per dataset, where the data came from and whether the source was publicly accessible; Evidence of the notification sent with its date, tested against the one month, first communication and first disclosure triggers; The disproportionate effort assessment where the exemption is relied on, showing what was weighed rather than only that a conclusion was reached; The alternative protective measures put in place under that exemption, including where the information was made publicly available; Supplier contract terms requiring the source of the data and the lawfulness of its collection to be disclosed
What an auditor will probe: Purchased or enriched marketing data used with no Article 14 notification at all, which is the most common finding in this area; Disproportionate effort claimed because notifying is inconvenient or costly rather than genuinely disproportionate; The source recorded as a vendor name with no indication of where the vendor itself obtained the data; Notification sent at the first marketing contact months after the data was obtained, missing the one month limit
Source: GDPR
UK GDPR Art. 14Information to be provided where personal data have not been obtained from the data subject

Where data come from elsewhere the controller must give the Article 13 information plus the categories of data and the source (including whether publicly accessible), within a reasonable period and at the latest one month after obtaining the data, or at first communication with the data subject, or when first disclosing to another recipient, and must tell the data subject before further processing for a new purpose. The duty falls away where the data subject already has the information, where obtaining or disclosure is expressly required by domestic law with appropriate protections, where professional secrecy requires confidentiality, where providing the information is impossible or would involve disproportionate effort (judged by the number of data subjects, the age of the data and the safeguards), or where it would render impossible or seriously impair the purposes; a controller relying on the last two must protect the data subject's interests, including by publishing the information.

What an auditor asks to see: Notices sent to data subjects whose data came from third parties, with dates; Disproportionate effort assessments and the published information; Record of data sources per data set
What an auditor will probe: Enriched or purchased data used with no notice to the people concerned; Disproportionate effort claimed without a written assessment; Notice sent later than one month after receipt
Source: UK GDPR

Other sources in public open data