**Article 12**

**Automated Event Logging System Design**

The Academic Compliance Monitor incorporates a comprehensive event logging mechanism that records operational data continuously throughout the system’s lifecycle, from initial startup to shutdown. This logging subsystem is implemented as an integral, tamper-resistant component tightly coupled with both the Random Forest and recurrent neural network (RNN) modules. Logs consist of structured records capturing input data snapshots (e.g., encrypted keyboard dynamics feature vectors, aggregated audio cue markers), intermediate inference states, anomaly scores, and output classification decisions. The system generates approximately 2,000 log entries per examination session, reflecting a sampling frequency optimized to balance trace granularity and system performance. All log entries are timestamped using synchronized Network Time Protocol (NTP) servers to ensure consistent sequencing and enable cross-correlation with external events. The design adheres to immutability principles by employing write-once storage backed by cryptographic hashing, preventing alteration or deletion of logs during active system use.

**Traceability of Risk-Relevant Situations and Model Modifications**

To identify and document situations potentially triggering risks defined under Article 79(1), the logging framework selectively signals and records key risk indicators. These include detection of behavioral anomaly thresholds exceeding calibrated sensitivity levels, inconsistencies between real-time event streams and historical baselines, and adaptive model parameter updates. Specifically, when the anomaly score surpasses 0.85 on a normalized 0–1 scale—a threshold empirically validated on a labeled dataset of 150,000 examination records representing typical and aberrant student behavior—an event record captures detailed input features, model confidence intervals, and alert rationale. Additionally, any substantial model modifications, such as the deployment of updated Random Forest hyperparameters or RNN architecture retraining prompted by new institutional policy inputs, trigger logging of version identifiers, modification timestamps, change justifications, and corresponding testing outcomes. Version control is managed via a secure DevOps pipeline maintaining an audit trail aligned with ISO/IEC 27001 standards.

**Support for Post-Market Monitoring**

Logs facilitate ongoing post-market surveillance by providing granular datasets for retrospective analysis and system performance audits. The logging schema aggregates anonymized event counts, false positive/negative instances flagged during manual review, and user feedback summaries from exam supervisors into daily digest reports. This information supports the post-market monitoring process defined in Article 72 by enabling statistical trend evaluations and risk assessments over time. Veritas Learning Systems has established a dedicated data analytics team responsible for monthly log reviews using automated anomaly detection on logs themselves, ensuring early identification of model drift, data distribution shifts, or unforeseen operational issues. These proactive measures assist in maintaining system reliability and compliance through continuous improvement cycles.

**Operational Monitoring of High-Risk AI Functionality**

To monitor the day-to-day operation of the AI system as referenced in Article 26(5), the logging architecture includes health and performance metrics such as CPU and memory utilization, inference latency, and error rates logged per session. These system telemetry logs enable assessment of real-time performance and support fault diagnosis without compromising user privacy or the integrity of behavioral data. The system integrates this telemetry with AI output logs into a consolidated dashboard accessible to authorized personnel with role-based access control (RBAC). Data security measures ensure that operational logs containing sensitive timestamps or behavioral cues are encrypted at rest and during transmission with AES-256 and TLS 1.3 protocols, respectively. Monitoring alerts are configured to notify engineering teams automatically of deviations from preset operational baselines, facilitating timely maintenance and reducing downtime risk.