**Article 12**

**Logging Capabilities and System Event Recording**

The Academic Compliance Monitor incorporates logging mechanisms specifically activated upon detection of flagged anomalies in student behavior during monitored examinations. Continuous event recording is deliberately omitted to reduce data volume and protect the privacy of typical user activity. This selective logging strategy ensures that only events identified by the hybrid model—comprising Random Forest classifiers for tabular pattern recognition and sequence-based recurrent neural networks (RNNs) for temporal behavior analysis—are persistently recorded. These triggered log entries capture detailed context, including timestamped feature vectors for keystroke dynamics and corresponding environmental audio cues, alongside the model’s decision scores and anomaly classification labels.

Comprehensive internal testing across a representative dataset of 150,000 exam sessions demonstrated that this approach effectively balances traceability and data minimization. Validation trials showed that approximately 2.3% of sessions triggered the anomaly detector, with a false positive rate controlled below 4%. This approach enables retrospective analysis of confirmed high-risk instances without logging entire exam timelines, accepting deliberate gaps in event coverage where behaviors were deemed normal or borderline. Intermediate decision points preceding anomaly confirmation are not persistently recorded, in line with the provider’s design choice prioritizing focused post-incident investigation over exhaustive continuous monitoring.

**Traceability for Risk Identification and Post-Market Monitoring**

The logging subsystem explicitly supports identification of risk situations as defined under Article 79(1) through structured event records linked to detected anomalies. Each log entry bundles modality-specific indicators—such as deviation scores from baseline keyboard cadence and irregular patterns extracted from audio spectra—with corresponding Random Forest feature importance metrics and RNN state transitions that triggered alerts. This facilitates expert review to verify the nature of suspected violations and assess potential model drift or modification needs. 

In fulfilling requirements supporting post-market monitoring (Article 72), the logs provide a concise and actionable event trail tailored to capture the onset and resolution of high-risk incidents within individual exam sessions. Aggregate anomaly statistics and temporal clustering analytics are exported periodically for continuous performance evaluation of the underlying AI models. This targeted data collection underpins ongoing conformity assessments and adaptive retraining cycles focused on enhancing detection accuracy while minimizing surveillance footprint.

**Monitoring System Operation under Article 26(5)**

Operational monitoring of the high-risk AI system leverages the anomaly-triggered logs to supervise system behavior in deployment without necessitating full event capture. Key operational metrics—such as anomaly detection frequency, false positive ratios, and mode of triggered logging—are aggregated at the system level to observe trends and detect substantial modifications in model functioning or input distribution shifts. The provider’s diagnostic dashboards access these limited but high-relevance logs remotely, supporting timely interventions for model recalibration or software updates. 

This design choice to restrict logs to flagged anomaly cases reflects a balance between technical feasibility, privacy considerations, and provider responsibility to furnish a technically robust mechanism enabling traceability proportional to the intended exam monitoring purpose. It ensures that recorded events are directly pertinent to risk or functionality monitoring while forgoing comprehensive capture of normal or near-threshold behaviors and intermediate scoring outcomes that do not generate alerts.