# AI audit trail for UK regulated firms: what to log

> What an AI audit trail should log in a UK regulated firm, why UK GDPR accountability makes it the practical evidence of review, and how long to keep the logs.

Checklist · Safe AI in regulated firms · By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Canonical: https://vexralabs.com/insights/ai-audit-trail

Short answer

An AI audit trail logs, for each piece of AI-assisted work, **the input, the AI output, the model version, the named reviewer, what they changed and when**. UK GDPR never names it. Article 5(2) makes the firm responsible for demonstrating compliance, and the log is the practical way to show that a person, not the AI, made the decision.

This guide is for partners and compliance leads in UK accountancy, financial advice and immigration firms that use AI to draft, extract or summarise client work. Two changes make the record matter now: Articles 22A to 22D replaced the UK GDPR rule on automated decisions in full on 5 February 2026, and the regulator’s AI guidance is under review as a result. We build Filyst, case management software with its own audit log, and the last section says what writing that log taught us. The sections cover what the trail is, which rules it serves, the fields, retention and access.

**Diagram: The five points an AI audit trail logs.** Each AI-assisted piece of work passes through five logged points: the input and its source document; the AI output with the model and version; the review, in which a named person approves, edits or rejects the output; the change made and the reason; and the final record with a timestamp, kept as long as the client file it belongs to.

*If any of the five points is missing, the record cannot show who decided.*

## What is an AI audit trail?

An AI audit trail, also called an AI audit log, is a record of each step an AI system and its human reviewer take on one piece of client work.

It belongs to the client file, not to the AI tool, so it survives a change of supplier. Three other records sit next to it, and none of them replaces it:

| Record | What it describes | Source |
| --- | --- | --- |
| AI audit trail | Each AI-assisted decision: input, output, reviewer, change, time | No single rule; evidence for the rules below |
| Record of processing activities | Each type of processing: purposes, categories of data and recipients, erasure time limits, security measures | [UK GDPR Article 30(1)](https://www.legislation.gov.uk/eur/2016/679/article/30) |
| Data protection impact assessment (DPIA) | The risks of a planned processing operation, and the degree of human involvement in its decisions | [ICO AI guidance, DPIA section](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/) |
| Attendance note (immigration advisers) | Every dealing with and on behalf of a client | [IAA Code 8.5](https://assets.publishing.service.gov.uk/media/6776b2ef6c34906cc84c9499/IAA_Codes_of_Standards_2024.pdf) |

Article 30(5) exempts organisations with fewer than 250 employees from the Article 30 record, unless their processing is likely to result in a risk to people’s rights, is not occasional, or includes special category or criminal offence data. The audit trail has no such threshold, because no rule creates it on its own.

## Does UK law require an AI audit trail?

No UK statute names an AI audit trail. The full UK GDPR text never uses the phrase. [Article 5(2)](https://www.legislation.gov.uk/eur/2016/679/article/5)says the controller “shall be responsible for, and be able to demonstrate compliance with” the data protection principles, which the regulation calls accountability. A log is how a firm demonstrates it for AI-assisted work.

Three provisions decide what the log needs to show. Each applies to a controller, the firm that decides why and how personal data is used:

- **Meaningful human involvement.** [Article 22A(1)(a)](https://www.legislation.gov.uk/eur/2016/679/article/22A)treats a decision as based solely on automated processing “if there is no meaningful human involvement in the taking of the decision”. The reviewer and change fields are the evidence of that involvement.
- **Safeguards.** Where a significant decision is based solely on automated processing and on personal data, [Article 22C(2)](https://www.legislation.gov.uk/eur/2016/679/article/22C) requires measures that give the person information about the decision, let them make representations, let them obtain human intervention and let them contest it.
- **Access.** [Article 15(1)(h)](https://www.legislation.gov.uk/eur/2016/679/article/15) gives people the right to know about automated decision-making that is subject to the Article 22C safeguards and, at least in those cases, meaningful information about the logic involved.

The regulator’s own guidance goes further. In its section on solely automated decisions, the [ICO’s guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-individual-rights-in-our-ai-systems/)says firms are “required to keep a record of all decisions made by an AI system as part of your accountability and documentation obligations”, including whether the person asked for human intervention, contested the decision, and whether the decision changed. That guidance predates the Data (Use and Access) Act 2025, and [its own page says](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/)it “is under review and may be subject to change”. The Information Commission took over from the Information Commissioner on 30 September 2026, and its [own announcement of the change](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/09/ico-welcomes-transition-to-new-information-commission-and-marks-new-chapter-with-manchester-head-office-opening/) still uses the name ICO.

## What do sector rules require firms to record?

Sector rules already require records of the work an AI tool now touches, so the AI audit trail extends records a firm keeps anyway. The rule depends on who the firm is:

- **Immigration advisers** regulated by the UK Immigration Advice Authority (IAA) follow the [Code of Standards 2024](https://assets.publishing.service.gov.uk/media/6776b2ef6c34906cc84c9499/IAA_Codes_of_Standards_2024.pdf), which applies to anyone giving immigration advice or services in the UK on a relevant matter, apart from exempt persons. Code 8.5 requires “a complete record of all your dealings with and on behalf your clients in the form of attendance notes”.
- **Accountants and tax advisers** within the Money Laundering Regulations 2017 (external accountants and tax advisers are defined in [regulation 11](https://www.legislation.gov.uk/uksi/2017/692/regulation/11)) keep, under [regulation 40(2)](https://www.legislation.gov.uk/uksi/2017/692/regulation/40), their customer due diligence documents and enough supporting records to reconstruct a transaction. Where AI extracts or checks that data, the log shows how the record was produced.
- **Firms within the EU AI Act** that provide or deploy a high-risk AI system meet [Article 12(1)](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12): the system “shall technically allow for the automatic recording of events (logs) over the lifetime of the system”. For Annex III systems this applies from 2 December 2027 under [Article 113(c)(i)](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113).

Most UK firms are outside the EU AI Act. Article 2 decides that, as explained in [whether the EU AI Act applies to UK firms](https://vexralabs.com/insights/eu-ai-act-deadlines-uk-firms).

## What should each log entry contain?

Each entry needs eight fields: the client reference, the input, the output, the model version, the rule checks, the reviewer, the decision and the timestamps. The example column below is a sample, not data from a real firm or client.

| Field | Example (sample) | What it shows |
| --- | --- | --- |
| Case or client reference | Sample client 0001, VAT return Q3 | Ties the entry to the file and its retention period |
| Input and source | Bank statement PDF, uploaded by a named user | What the AI saw |
| AI output | Extracted transactions; draft summary | What the AI proposed |
| Model and version | Supplier, model name and version string | Why behaviour changed over time |
| Rule checks | Statement totals match: pass | What was calculated by rules, not generated |
| Reviewer | Named, qualified member of staff | That a person decided |
| Decision and change | Approved with edits: two dates corrected | That the review changed something when needed |
| Timestamps | Output time and approval time | The order of events and time spent reviewing |

Where a person asks for human intervention, makes representations or contests a decision, add that request and its outcome as a further entry, which the ICO guidance quoted above names.

## How does the log show that review was meaningful?

The log shows meaningful review through the pattern of reviewer decisions, not one entry. The [ICO’s AI guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-individual-rights-in-our-ai-systems/)says the analysis of “why, and how many times, a human reviewer accepted or rejected the AI system’s output is a key part in an effective risk monitoring system”.

The same page warns that reviewers who are “routinely agreeing with the AI system’s outputs, and cannot demonstrate they have genuinely assessed them” risk their decisions being treated as solely automated. A log that records approve, edit and reject, with a reason, gives a firm the data for that analysis. Our guide to [human in the loop AI under Article 22A](https://vexralabs.com/insights/human-in-the-loop-ai-uk-gdpr) explains what counts as meaningful involvement, and a [DPIA for AI tools](https://vexralabs.com/insights/dpia-for-ai-tools) records the degree of human involvement that the log then proves.

## How long should AI logs be kept?

Keep each log entry as long as the record it supports, and no longer. [Article 5(1)(e)](https://www.legislation.gov.uk/eur/2016/679/article/5), the storage limitation principle, applies to logs that identify people. The sector rule then sets the period:

| Who | Period | Start point | Source |
| --- | --- | --- | --- |
| Every controller | No longer than necessary for the purpose | n/a | [UK GDPR Article 5(1)(e)](https://www.legislation.gov.uk/eur/2016/679/article/5) |
| IAA-regulated immigration advisers | At least six years, then secure destruction | Not stated in the Code | [IAA Code 5.10](https://assets.publishing.service.gov.uk/media/6776b2ef6c34906cc84c9499/IAA_Codes_of_Standards_2024.pdf) |
| Accountants and tax advisers under the MLR 2017 | Five years; personal data deleted afterwards unless an exception in 40(5) applies | End of the business relationship, or completion of an occasional transaction | [MLR 2017 regulation 40(3) and (5)](https://www.legislation.gov.uk/uksi/2017/692/regulation/40) |
| Providers and deployers of high-risk AI under the EU AI Act | At least six months, unless other law says otherwise | From generation of the log | [EU AI Act Articles 19(1) and 26(6)](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26) |

The six-year IAA period and its start date are covered in [how long UK immigration advisers must keep client records](https://vexralabs.com/insights/immigration-adviser-file-retention); the five-year rule is in [AML record keeping requirements for UK accountants](https://vexralabs.com/insights/aml-records-accountants); and FCA periods are in [financial adviser record keeping obligations](https://vexralabs.com/insights/record-keeping-financial-advisers).

## Who can see and change the log?

Staff read entries for their own files, and nobody edits or deletes an entry, administrators included. Corrections are new entries that reference the original. That design is our recommendation, not a rule, and it makes the log evidence rather than a note anyone can rewrite.

Two outsiders can ask to see entries:

- the person the work is about, who has a right of access to their personal data under [UK GDPR Article 15(1)](https://www.legislation.gov.uk/eur/2016/679/article/15); and
- for immigration advisers, the Commissioner, because [IAA Code 8.6](https://assets.publishing.service.gov.uk/media/6776b2ef6c34906cc84c9499/IAA_Codes_of_Standards_2024.pdf)requires records to be “accessible to the client at any time and available to the Commissioner upon request”.

## How do you build an audit trail into a workflow?

Build the log into the workflow rather than adding it afterwards: the system writes each entry as the AI produces output and as the reviewer acts, so no one has to remember to record it. The AI drafts and a person signs off, and the log records both steps.

Filyst, our case management software for immigration firms, keeps an audit log of who did and approved what, and when, and it rejects a case stage approval from the person who asked for it. Writing that log taught us that a log table is not tamper-resistant by default. Nothing in Filyst’s database makes its audit log append-only today, so we call it an audit log and not an immutable record. A firm asking a supplier about its AI audit trail can ask the same question: what stops an administrator editing an entry?

The audit trail is one part of the design set out in [AI in regulated industries: UK rules and human review](https://vexralabs.com/insights/ai-in-regulated-firms), which places the log alongside the review step, the DPIA and the supplier contract. Every post on the topic is collected under [safe AI in regulated firms](https://vexralabs.com/insights/topics/safe-ai).

Not legal advice

This guide reflects UK GDPR as amended by the Data (Use and Access) Act 2025, the IAA Code of Standards 2024, the Money Laundering Regulations 2017 and the EU AI Act as consolidated on the European Commission’s AI Act Service Desk, as at the date checked. The ICO’s AI guidance is under review following the Data (Use and Access) Act 2025. The fields and access design are our suggestions. Ask your compliance lead or a lawyer how the rules apply to your firm.

## Frequently asked questions

### Is an AI audit trail a legal requirement in the UK?

No UK law names it. UK GDPR Article 5(2) requires a firm to be able to demonstrate compliance, and the log is the practical evidence that a person reviewed the AI's output.

### How is an AI audit log different from an Article 30 record?

An Article 30 record of processing activities describes each type of processing, such as its purposes and recipients. An AI audit log records each individual AI-assisted decision and who reviewed it.

### How long should AI audit logs be kept?

As long as the record they support and no longer. That is at least six years for an IAA client file under Code 5.10, and five years from the end of the business relationship for AML records under MLR 2017 regulation 40.

### Does the EU AI Act require UK firms to keep AI logs?

Only where the Act applies to the firm under Article 2 and the system is high-risk. Deployers then keep the system's logs for at least six months under Article 26(6), from 2 December 2027 for Annex III systems.

## Sources

1. [UK GDPR Article 5 (principles and accountability), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/5)
2. [UK GDPR Article 15 (right of access), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/15)
3. [UK GDPR Article 22A (automated decisions), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22A)
4. [UK GDPR Article 22C (safeguards), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22C)
5. [UK GDPR Article 30 (records of processing activities), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/30)
6. [ICO, Guidance on AI and data protection: about this guidance (under review)](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/)
7. [ICO, How do we ensure individual rights in our AI systems?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-individual-rights-in-our-ai-systems/)
8. [ICO, What are the accountability and governance implications of AI?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/)
9. [ICO, transition to the Information Commission, 30 September 2026](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/09/ico-welcomes-transition-to-new-information-commission-and-marks-new-chapter-with-manchester-head-office-opening/)
10. [IAA, Code of Standards 2024](https://assets.publishing.service.gov.uk/media/6776b2ef6c34906cc84c9499/IAA_Codes_of_Standards_2024.pdf)
11. [Money Laundering Regulations 2017, regulation 40, legislation.gov.uk](https://www.legislation.gov.uk/uksi/2017/692/regulation/40)
12. [Money Laundering Regulations 2017, regulation 11, legislation.gov.uk](https://www.legislation.gov.uk/uksi/2017/692/regulation/11)
13. [EU AI Act Article 12 (record-keeping), AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12)
14. [EU AI Act Article 19 (automatically generated logs), AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-19)
15. [EU AI Act Article 26 (deployer obligations), AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26)
16. [EU AI Act Article 113 (application dates), AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113)
