Record Keeping, Governance and Accountable People

Lesson concept diagram
Record Keeping, Governance and Accountable People

Effective record keeping is central to demonstrating compliance with the Online Safety Act and AI regulations. Platforms must maintain detailed logs of content moderation decisions, AI-generated content identification, and user complaints. For example, a social media platform must document when AI tools flag content for review, who reviewed the flag, and the final outcome. These records must be retained for at least two years and must be available to regulators upon request. Without proper documentation, platforms cannot prove they have met their duties, even if they have followed correct processes.

Accountability through Governance Structures

Governance frameworks must clearly define roles and responsibilities for AI and content management. A platform’s AI governance committee should include representatives from legal, technical, and compliance teams. For example, a committee might approve AI models used for content moderation or decide on transparency reporting. The committee must meet regularly, with minutes documenting decisions and actions taken. These records must be reviewed by senior leadership to ensure alignment with organisational objectives and regulatory expectations. Where AI systems are used to make decisions affecting users, such as flagging harmful content, these decisions must be traceable to individuals or processes. This makes it easier to identify where errors occurred or where improvements are needed.

  • Assign clear roles for AI oversight, including designated AI officers or data protection officers
  • Ensure decision-making processes are documented and reviewed
  • Train leadership on AI-related responsibilities

Accountable People and AI Readiness

Accountability extends to individuals within an organisation who work with AI systems. Staff must understand their roles in AI governance, including how to identify AI-generated content, respond to user complaints, and maintain records. For example, a content moderator must know how to identify AI-generated posts and apply the correct moderation actions. Regular training ensures staff stay updated on evolving AI regulations. A platform might run quarterly sessions on AI literacy, covering topics such as machine-readable marking or prohibited AI practices. These sessions must be recorded, and attendance must be tracked. Where staff fail to meet these obligations, disciplinary actions must be clearly defined and applied. This reinforces the importance of compliance at all levels of the organisation.

Organisations must also ensure that AI systems are properly monitored and audited. For example, a platform using AI to detect harmful content must conduct regular audits to check for bias or inaccuracies. These audits must be documented, including any corrective actions taken. The audit process must involve both technical specialists and compliance staff. Where AI systems are used to make decisions, such as removing content or suspending accounts, these decisions must be reviewed by human oversight. This is especially important for AI systems that have been placed on the market before 2 August 2026, as they must meet machine-readable marking by 2 December 2026. The platform must ensure these systems are updated or replaced to meet new requirements.

Record keeping must also support transparency efforts. Where platforms publish AI transparency reports, these must be based on accurate data. For example, a platform might report on the number of AI-generated posts identified or the effectiveness of AI moderation tools. These reports must be reviewed by compliance officers to ensure they meet regulatory expectations. The data must be stored securely and accessible to internal and external auditors. Where AI systems are used in high-risk applications, such as those covered by Annex III of the Digital Omnibus, platforms must prepare for new obligations by 2 December 2027. This includes updating records to reflect any new AI models or processes.

ISO/IEC 42001:2023 provides a framework for AI management systems. Organisations must align their governance structures with this standard to ensure consistency and compliance. The standard requires that AI systems are managed through defined processes, including risk assessment, monitoring, and continuous improvement. For example, a platform might develop a risk register for AI tools, listing potential issues such as bias or misuse. Regular reviews of this register must be conducted, and any identified risks must be addressed through policy or technical changes. The platform must also ensure that certification bodies, such as those governed by ISO/IEC 42006:2025, can access records during audits. This helps maintain certification and shows commitment to responsible AI use.