SETTING GLOBAL STANDARDS FOR TRUSTED AI CREDENTIALSAI Competence Framework v1.29 · current release
You are reading the current version of the framework, v1.29.Permanent address for this version
D8.L2.06ACTIVESTABLED8 Security · L2 Applied

Document the data an AI workflow reads, retains and transmits.

Type Skill · introduced in version 0.1

Performance indicators

Normative. These state what would be observed in a person who holds the statement.

Records every source read, including retrieved and connected sources
Records what is retained, where, and for how long
Identifies where data crosses an organisational or jurisdictional boundary
Evidence examples

Non-normative. Illustrative of evidence an awarding body might accept; not a required form.

A worked artefact produced in the course of normal duties, with the reasoning recorded at the time
Attestation by a competent supervisor against the indicators above, not against a general impression
Relationships

Assumes

Statements a candidate is taken to hold already. Never at a higher level than this one.

This statement assumes no other statement. It is a starting point within its domain.

Assumed by

Derived inverse. Statements that take this one as given.

No published statement assumes this one at version 1.29.

Related

Cross-domain relationships, stated in both directions and typed in the content model.

D2.L2.01

Check a factual claim in AI output against an authoritative source.

D2.L2.02

Cite the sources used in and produced by AI-assisted work.

D2.L2.03

Apply classification rules to material before using it with an AI system.

D2.L2.04

Establish the licence and permitted use of material supplied to or produced by a system.

D2.L2.05

Prepare source material so that a system can use it reliably.

D2.L2.06

Record the provenance of AI-assisted output, including the material supplied.

D2.L2.07

Recognise output shaped by an unrepresentative or incomplete source set.

D4.L2.01

Operate an automated AI workflow within its stated limits.

D4.L2.02

Configure the handover between an AI step and the step that follows it.

D4.L2.03

Record what an automated run did, on what input, with what result.

D4.L2.04

Identify and report a failure in an unattended step.

D4.L2.05

Apply the organisation’s rules on which actions an automated step may take.

D4.L2.06

Test an automated workflow before it runs on real work.

Referenced by

Entries on the register of conformance claims whose coverage map cites this statement.

No entry on the register cites this statement. This block is populated from the coverage maps of register entries as they are listed.

Provenance
IntroducedVersion 0.1
Last modifiedNot modified since introduction
Statusactive · stable
Version displayedv1.29
Permanent URLaicertificationstandards.org/framework/statements/D8.L2.06
Cite this statement

AI Certification Standards (2026) AICF D8.L2.06, D8 Security, version 1.29. Available at aicertificationstandards.org/framework/v1.29/statements/D8.L2.06 (accessed date).

Propose an amendment

Statements change through the published process, not by correspondence

An amendment to this statement, its indicators or its relationships is proposed through the contribution process. Every submission is answered on the record, and the reasoning for acceptance or rejection is published in the release record for the version that follows.

Propose an amendment to D8.L2.06

Writing rules and the controlled verb list that govern how this statement is worded are published in the methodology.

This page displays version 1.29 · last reviewed 30.08.2026