Which NIST 800-53 controls cover AI audit logging?

The Audit and Accountability (AU) control family governs audit logging — AU-2 (event selection), AU-3 (record content), AU-6 (review/analysis), AU-9 (protection of audit information), and AU-10 (non-repudiation) are the load-bearing ones for an AI evidence…

register 09 · Compliance pins· NIST 800-53 · AU
01 ·

Answer.

Risk-management framework · NIST 800-53 · AU.

The Audit and Accountability (AU) control family governs audit logging — AU-2 (event selection), AU-3 (record content), AU-6 (review/analysis), AU-9 (protection of audit information), and AU-10 (non-repudiation) are the load-bearing ones for an AI evidence trail. The Assessment/Authorization/Monitoring (CA) family covers the recurring re-assessment cadence. Planisphere's sha-256-pinned, Merkle-rooted record gives AU-9/AU-10-style tamper-evidence and non-repudiation for the measurement record; it complements, not replaces, the system's own audit logging.

02 ·

The mark behind the answer.

NIST 800-53 · AU is a process framework, not a pass/fail line: it names functions, categories and controls an organisati…

Audit & Accountability control family · maps to the evidence record.

→ Full reference for NIST 800-53 · AU

Try NIST 800-53 · AU with a free test key.

Start with the free sandbox. Planisphere measures model behaviour and emits a reproducible, sha-pinned record — it does not certify, file, or give legal advice.

API ·

When NIST 800-53 · AU asks for proof, hand over records — not assurances.

record the duty · seal the receipt · verify offline

Planisphere records each duty event — an output marked, a disclosure shown, a review made — and seals it into a receipt that verifies offline against our published keys. You send hashes, never content. A record is evidence a third party can check; it is not a certification and not a legal determination.

See how a record is checked