Skip to main content

What a receipt records, and what it leaves with you

Legal review pending — these mappings are the author's reading of the text, dated 2026-10-01.

A receipt can support the record for a specific evaluated change set. It is one line inside a process you already run. It does not run that process.

The fields

Field What it means
input_fingerprint Which evaluated change set. The hash of the evaluated input, not a readable description. The consumer matches it to the change set they hold.
operation The caller declares it, and the signature binds that declaration. The receipt proves what the authorization was for, not that the step that ran was that.
decision, execution_action decision is ALLOW, WARN, REQUIRE_APPROVAL or BLOCK. execution_action is CONTINUE, CONTINUE_WITH_MONITORING, REQUEST_APPROVAL or STOP.
expires_at Hard validity bound, UTC Z.
receipt.key_id Offline verify. The key id the local verifier uses.

A local VERIFIED does not establish that the signing key is still trusted — REVOCATION and the issuer's clock are not visible to any local verifier, including this one. A key compromised a minute ago still verifies here

DORA, Article 9(4)(e)

Article 9(4) addresses financial entities under Article 2(2) of Regulation (EU) 2022/2554; Article 2(1)(u) also lists ICT third-party service providers, and Article 30(1) puts their rights and obligations in the written contract. Can help: of the six verbs in Article 9(4)(e) of Regulation (EU) 2022/2554 (recorded, tested, assessed, approved, implemented and verified), the receipt can give evidence for recorded. Does not prove: A receipt alone does not satisfy Article 9(4)(e); it is one record inside a process that does. A GitHub review can name a reviewer; it does not by itself show that the reviewer was authorised to approve or that the organisation's protocol was followed.

implement documented policies, procedures and controls for ICT change management, including changes to software, hardware, firmware components, systems or security parameters, that are based on a risk assessment approach and are an integral part of the financial entity’s overall change management process, in order to ensure that all changes to ICT systems are recorded, tested, assessed, approved, implemented and verified in a controlled manner;

For the purposes of the first subparagraph, point (e), the ICT change management process shall be approved by appropriate lines of management and shall have specific protocols in place.

Article 9(4)(e), Regulation (EU) 2022/2554. ELI. English OJ text read for this page: 32022R2554.ENG.xhtml#art_9.

AI Act, Article 12 and Article 26

Articles 12 and 26 of Regulation (EU) 2024/1689 address high-risk AI systems: Article 6(2) treats Annex III systems as high-risk, Article 6(3) derogates where there is no significant risk of harm, and Article 6(1) is a separate product route under Annex I. Can help: a receipt can be an attachment or decision line in a change record. Does not prove: A receipt can be an attachment or decision line in a change record; it is not the event log the system generates automatically, and it does not provide the deployer's retention of at least six months. It does not assign or evidence human oversight.

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.

Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.

Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data.

Article 12(1), Article 26(2) and Article 26(6), Regulation (EU) 2024/1689. ELI. English OJ text read for this page: L_202401689.ENG.xhtml#art_12, #art_26.

NIS2, Article 21(2)(e)

Article 21(1) of Directive (EU) 2022/2555 is addressed to essential and important entities. Can help: possible supporting evidence. Does not prove: A receipt is possible supporting evidence, not a direct record-keeping mapping — the provision does not name change recording.

The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:

(e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;

Article 21(2), chapeau and point (e), Directive (EU) 2022/2555. ELI. English OJ text read for this page: 32022L2555.ENG.xhtml#art_21.

Legal review pending — these mappings are the author's reading of the text, dated 2026-10-01.

The honesty table is what each proof proves. The trust statement is the trust center. The proof-run index, which this page does not replace, is /docs/evidence/.

The long reading: What a signed receipt can and cannot evidence under DORA, NIS2 and the AI Act.