---
name: framework-financial-services-controls-au-12
title: AU-12 - Audit Record Generation
description: 'Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on _[IBM Assignment: all information system and network components where audit capability is deployed/available]_.'
last-updated: 2026-08-26
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services-controls?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# AU-12 - Audit Record Generation
{: #au-12}

## Control requirements
{: #control-requirements}



### AU-12 (a)
{: #au-12-a}


Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on _[IBM Assignment: all information system and network components where audit capability is deployed/available]_.


### AU-12 (b)
{: #au-12-b}


Allow _[Assignment: organization-defined personnel or roles]_ to select the event types that are to be logged by specific components of the system.


### AU-12 (c)
{: #au-12-c}


Generate audit records for the event types defined in AU-2c that include the audit record content defined in AU-3.












## NIST supplemental guidance
{: #nist-supplemental-guidance}

Audit records can be generated from many different system components. The event types specified in AU-2d are the event types for which audit logs are to be generated and are a subset of all event types for which the system can generate audit records.