AI Training Data Provenance Checker
Internal operational · source class

ERP and finance system

Finance data is usually about transactions, not people, but supplier and employee names ride along in it.

What to record for it

The system, the ledgers and period extracted, and whether names were removed.

Personal data is possible: where your personal data column is blank the checker says it could not determine it.

A line that places here

example

Repair invoices | ERP finance system | internal

Check this line

What the checker reads on these lines

9 of the 12 findings

Clauses

5 regimes
RegimeClause
ISO/IEC 42001ISO/IEC 42001 A.7.3 Acquisition of data
ISO/IEC 42001 A.7.5 Data provenance
ISO/IEC 42001 A.4.3 Data resources
NIST AI RMFNIST AI RMF MS-2.10 Privacy risk examined
EU AI ActEU AI Act Art. 10 Data and data governance
GDPRGDPR Art. 5 Principles relating to processing of personal data
GDPR Art. 6 Lawfulness of processing
GDPR Art. 30 Records of processing activities
UK GDPRUK GDPR Art. 5 Principles relating to processing of personal data
UK GDPR Art. 8A Purpose limitation: further processing
UK GDPR Art. 30 Records of processing activities

The clauses, set out

ISO/IEC 42001 A.7.3Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

What an auditor asks to see: Data acquisition records; Provenance documentation; Consent records; Source identification; Licensing or consent evidence; Selection criteria and rejection rationale
What an auditor will probe: Is data provenance traceable to lawful sources?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.7.5Data provenance

The organization shall document the provenance of data used in AI systems to enable evaluation and traceability.

What an auditor asks to see: Provenance records; Lineage diagrams; End-to-end data lineage from source to model; Transformations documented; Datasheets
What an auditor will probe: Is lineage maintained automatically or relies on manual updates?
Source: ISO/IEC 42001:2023
ISO/IEC 42001 A.4.3Data resources

As part of identifying resources, the organization shall document information about the data resources utilized for the AI system.

What an auditor asks to see: Data inventory; Data lineage records; Datasheets; Data sources, types, volumes, sensitivity; Provenance and licensing; Data quality metadata
What an auditor will probe: Is data lineage maintained from source to model?
Source: ISO/IEC 42001:2023
NIST AI RMF MS-2.10Privacy risk examined

Privacy risk of the AI system – as identified in the MAP function – is examined and documented. Privacy examination covers what the AI system makes possible, inference and re-identification from training data and outputs, not only the lawfulness of the input data.

What an auditor asks to see: Privacy risk examination covering training data, inference and outputs; Assessment of re-identification and memorisation risk; Privacy-enhancing measures applied and their assessed effect; Documentation traced to the privacy risks mapping identified
What an auditor will probe: Privacy assessed as lawful basis for input data only; Memorisation and training data extraction not considered; Assessment completed for the original data set and not repeated after retraining
Source: NIST AI Risk Management Framework
EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex III

High-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.

What an auditor asks to see: Data governance procedures; Bias examination records and remediation; Data-quality assessment per dataset
What an auditor will probe: Training data used without bias examination; Datasets not representative of the deployment context
Source: EU AI Act
GDPR Art. 5Principles relating to processing of personal data

Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.

What an auditor asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay; The compatibility assessment for any further processing carried out for a new purpose; Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
What an auditor will probe: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them; Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely; Accountability treated as holding the documents rather than being able to show the principles were applied; Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Source: GDPR
GDPR Art. 6Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

What an auditor asks to see: A lawful basis recorded per processing activity, not per system or per department; Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights; The Union or Member State provision cited where the basis is legal obligation or public task; Compatibility assessments for each secondary use, covering the five factors Article 6(4) names; Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
What an auditor will probe: Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis; Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity; One lawful basis applied to a whole system that covers several distinct processing purposes; The basis switched after the fact when the first one fails, rather than settled before processing began
Source: GDPR
GDPR Art. 30Records of processing activities

Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of processing carried out on behalf of each controller. Make the record available to the supervisory authority on request. The obligation does not apply to an organisation employing fewer than 250 persons unless the processing is likely to result in a risk to the rights and freedoms of data subjects, is not occasional, or includes special category or criminal offence data.

What an auditor asks to see: The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists; Version history showing when each entry was last reviewed and by whom; Reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well; The transfer entries with the third country identified and the safeguard documentation referenced; Where the fewer than 250 persons exemption is claimed, the assessment against all three disqualifying conditions
What an auditor will probe: Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since; Entries written at the level of a department or a system rather than a processing activity, which loses the purpose that everything else hangs off; Erasure time limits left blank throughout on the where possible qualifier, while a retention schedule exists elsewhere in the organisation; The small organisation exemption claimed on headcount alone, ignoring that regular non-occasional processing disqualifies it
Source: GDPR
UK GDPR Art. 5Principles relating to processing of personal data

Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What an auditor asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
What an auditor will probe: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR
UK GDPR Art. 8APurpose limitation: further processing

Whether processing for a new purpose is compatible with the purpose of collection is decided by weighing, among other things, the link between the purposes, the context of collection and the relationship with the data subject, the nature of the data (special category or criminal offence data), the possible consequences, and safeguards such as encryption or pseudonymisation. Further processing is treated as compatible where the data subject consents to a specified, explicit and legitimate new purpose; where it is research, archiving or statistics under Article 84B; where it ensures or demonstrates compliance with Article 5(1); where an Annex 2 condition is met (disclosure on request for a public task, archiving disclosures of consent-based data, public security, emergencies, crime, vital interests, safeguarding vulnerable individuals, tax, legal obligations); or where it is necessary for an Article 23(1)(c) to (j) objective and authorised by law. Data collected on consent may be reused only with fresh consent or for compliance, or under Annex 2 or an authorised objective where consent cannot reasonably be sought.

What an auditor asks to see: Compatibility assessments for each new use of existing data; Annex 2 condition recorded for reuse relying on it; Evidence that consent-based data was not reused beyond Article 8A(4)
What an auditor will probe: Reuse of consent-based data for analytics without fresh consent; No documented compatibility test before repurposing data; Relying on Annex 2 without the request or legal duty it requires
Source: UK GDPR
UK GDPR Art. 30Records of processing activities

Each controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.

What an auditor asks to see: Record of processing activities covering every required field; Processor record per controller; Evidence of periodic review of the records
What an auditor will probe: Records not updated as systems change; Small organisations claiming the exemption despite regular processing; Security measures described only generically
Source: UK GDPR

Other sources in internal operational