AI Training Data Provenance Checker
Terms family

CC BY

Creative Commons Attribution, with its attribution condition.

Triage status: generally permissive copyright terms. The checker reads the words in your terms column, never the licence itself; the terms themselves decide. This reads copyright permission only. Whether training engages those rights, and whether licence conditions reach a model or its outputs, depends on the jurisdiction and the technical facts; privacy, data protection and contract restrictions are separate.

How the checker reads it

A terms column reading CC BY 4.0 places here, and the checker records the family and raises no terms finding on it; the terms themselves still decide.

Clauses

RegimeClause
ISO/IEC 42001ISO/IEC 42001 A.7.3 Acquisition of data
NIST AI RMFNIST AI RMF MP-4.1 Legal risks of components and third-party data
ISO/IEC 42001 A.7.3Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

What an auditor asks to see: Data acquisition records; Provenance documentation; Consent records; Source identification; Licensing or consent evidence; Selection criteria and rejection rationale
What an auditor will probe: Is data provenance traceable to lawful sources?
Source: ISO/IEC 42001:2023
NIST AI RMF MP-4.1Legal risks of components and third-party data

Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third-party’s intellectual property or other rights. There is a followed approach for mapping the technology and legal risk carried by each component, including data and software obtained from third parties and the rights position attached to them.

What an auditor asks to see: The documented approach for mapping component technology and legal risk; Component inventory identifying third-party data, models and software; Intellectual property and rights analysis for each third-party component; Evidence the approach was followed for the components actually in use
What an auditor will probe: Approach documented but not applied to components adopted since; Pre-trained models used with no analysis of the provenance of their training data; Rights reviewed for commercial components only, not for freely obtained ones
Source: NIST AI Risk Management Framework

Families with the same triage status