The Documentation You Will Be Asked For
What a regulator, an auditor or a claimant's lawyer asks for, and why most of it cannot be produced retrospectively.
Procedure
The documentation obligations in this field are unusual in that most of them describe decisions, and decisions cannot be documented convincingly after the fact.
What gets asked for
The purpose, stated specifically.
The lawful basis and, for biometric data, the additional condition.
The impact assessment, including the proportionality reasoning.
What less intrusive alternatives were considered and why they were rejected.
Performance evidence: accuracy, error rates, and their distribution across groups.
The notice given to affected people, and when.
The consultation record, where applicable.
Retention periods and evidence of deletion.
Access logs: who looked at what, and under what trigger.
The human oversight arrangement and how someone contests an outcome.
What cannot be reconstructed
The reasoning at the time. An assessment written after a complaint reads as an assessment written after a complaint.
Whether alternatives were genuinely considered.
What performance was known before deployment, as opposed to what was measured after questions were asked.
When notice was given, if there is no dated record.
Which model version was running on a given date, if versions were not recorded.
This is the practical argument for doing it properly: the cost of documenting at the time is hours, and the cost of not having it is that the question cannot be answered at all.
The performance record specifically
The measured error rates, both types, at the operating threshold.
Broken down by subgroup where people are involved, with the composition of the evaluation set stated.
The conditions: cameras, lighting, period.
Confidence intervals, or at least the sample sizes.
Where the vendor supplied the figures rather than your own measurement, say so, and record what you did to verify them.
Where subgroup performance was not measured, record that as an unquantified risk rather than leaving a gap that reads as an oversight.
Versioning
Which model, which threshold, which cameras, from which date.
Every change recorded, including threshold adjustments, which are frequently made informally and change the system's behaviour entirely.
Without this you cannot investigate an incident, because you cannot say what the system was doing at the time.
Access logging
Every retrieval of footage or detection data: who, when, what, and the stated reason.
Reviewed periodically against the stated purposes, with unexplained access treated as a finding.
This is also the control that protects the operators, by making it demonstrable that the system was not misused.
A retention and deletion record
The policy, and evidence that it is enforced by automated deletion rather than by intention.
Including backups, where retained data survives a deletion policy.
With a hold mechanism for incidents, applied before the automation runs and released afterwards.
Tested, by confirming that data past its period is actually gone rather than merely hidden from a report.
The file an auditor opens
Assembling it once is hours; reconstructing it is impossible.
One folder per deployment.
Purpose, basis, assessment, alternatives considered, notice, consultation record.
Performance evidence with dates and conditions.
Configuration history: model version, threshold, cameras, from when.**
Access log reviews.
Retention schedule and deletion evidence.
Review dates and outcomes.
Kept current as a habit rather than assembled before an audit, because the assembly is where the gaps become visible and by then they cannot be filled.
Versioning what is deployed
Without this an incident cannot be investigated and a change cannot be attributed.
Model version, threshold, zone configuration, camera positions, from which date.
Every change recorded, including informal threshold adjustments.
Tied to the monitoring data, so a step in the detection count has an explanation.
Retained as long as the incidents it might explain, which is longer than the footage.
Ask the vendor how you can determine what version was running on a past date; many products cannot answer, and that is worth knowing before it matters.