Skip to content

Evidence request lists

Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022)

Evidence request list. 48 controls, 48 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Algorithm Recommendation

CN-ALG-A10
No Illegal Keywords in User Profiles

Providers must not record illegal or undesirable keywords into user interest profiles or use them as criteria for recommending content to users.

Artefacts an auditor will ask for
  • User-tagging rules excluding illegal/harmful keywords
Where this commonly fails
  • Recommending content based on illegal-content interest tags
CN-ALG-A11
Feed Ecology and Mainstream Value Orientation

Providers must strengthen the ecological management of recommendation feeds, establish manual intervention and user self-selection mechanisms, and actively present information consistent with mainstream value orientation in key sections such as front pages, hot-search and selected topics.

Artefacts an auditor will ask for
  • Manual-intervention and user self-selection mechanisms
Where this commonly fails
  • No human oversight of recommendation feeds
CN-ALG-A12
Ranking and Transparency Practices

Providers are encouraged to optimise transparency and explainability of search, ranking, selection, push and display rules, and to avoid adverse effects on users and to prevent or reduce controversy and disputes.

Artefacts an auditor will ask for
  • Documentation of ranking/filtering rules and transparency measures
Where this commonly fails
  • Opaque ranking rules causing user harm
CN-ALG-A14
Prohibition on Algorithmic Manipulation

Providers must not use algorithms to falsely register accounts, manipulate accounts, fabricate transactions/likes, manipulate rankings, or control trending topics, comments and other activities that interfere with online information presentation.

Artefacts an auditor will ask for
  • Controls preventing fake-account and ranking manipulation
Where this commonly fails
  • Algorithmic manipulation of rankings or trending content
CN-ALG-A15
No Unfair Restriction of Competitors

Providers must not use algorithms to unreasonably restrict other internet information service providers, or to impede or sabotage the lawful operation of their services, monopolise or engage in unfair competition.

Artefacts an auditor will ask for
  • Policy against anti-competitive algorithmic practices
Where this commonly fails
  • Algorithms used to block or degrade competitors
CN-ALG-A16
Algorithm Transparency Disclosure to Users

Providers must inform users in a conspicuous manner that they provide algorithmic recommendation services and publicise the basic principles, purpose/intent and main operating mechanisms in an appropriate way.

Artefacts an auditor will ask for
  • Conspicuous disclosure that recommendation is used
  • Published description of recommendation logic
Where this commonly fails
  • Users not told that content is algorithmically recommended
CN-ALG-A17
User Choice and Opt-Out

Providers must offer users options not targeted at their personal characteristics or a convenient way to switch off algorithmic recommendation, and must let users select or delete user tags used for recommendation; where a user objects, the provider must stop the service.

Artefacts an auditor will ask for
  • Opt-out / non-personalised toggle
  • Tag selection and deletion function
Where this commonly fails
  • No opt-out from personalised recommendation
  • No ability to delete recommendation tags
CN-ALG-A18
Protection of Minors

Providers serving minors must fulfil minor-protection duties, facilitate minors' healthy use through suitable service modes, and must not push information that may induce minors to imitate unsafe behaviour, commit acts contrary to social morality, or develop harmful habits or addiction.

Artefacts an auditor will ask for
  • Minor mode / age-appropriate recommendation controls
Where this commonly fails
  • Recommending addictive or harmful content to minors
CN-ALG-A19
Protection of Elderly Users

Providers serving the elderly must protect their lawful interests, account for their travel, medical, consumption and other needs, provide intelligent and accessible adaptations per state rules, and support fraud detection and prevention.

Artefacts an auditor will ask for
  • Accessibility adaptations for elderly users
  • Anti-fraud features
Where this commonly fails
  • No accessibility or fraud safeguards for elderly users
CN-ALG-A20
Worker Protection (Gig Economy)

Providers offering work-scheduling services to workers must protect their lawful interests in remuneration, rest and working hours, and establish and refine platform-order distribution, remuneration composition/payment, working hours, rewards/penalties and other algorithms.

Artefacts an auditor will ask for
  • Fair work-scheduling and pay algorithms
  • Worker-impact assessment
Where this commonly fails
  • Exploitative gig-work scheduling algorithms
CN-ALG-A21
Consumer Protection (No Price Discrimination)

Providers selling goods or services to consumers must protect consumers' fair-trading rights and must not use algorithms to commit unreasonable differential treatment on price or trading conditions based on consumer preferences or trading habits.

Artefacts an auditor will ask for
  • Pricing-fairness controls preventing algorithmic discrimination
Where this commonly fails
  • Algorithmic price discrimination ('big-data price gouging')
CN-ALG-A22
Complaint and Reporting Mechanism

Providers must establish convenient complaint and public-reporting entry points, disclose the handling process and timeframes, and promptly accept, handle and give feedback on complaints.

Artefacts an auditor will ask for
  • Published complaint/report channel and timelines
Where this commonly fails
  • No accessible complaint mechanism for recommendation services
CN-ALG-A24
Algorithm Filing

Providers with public-opinion attributes or social-mobilisation capacity must, within ten working days of providing service, file via the internet information service algorithm filing system the provider name, service form, application field, algorithm type, algorithm self-assessment report, content to be publicised and other information; changes within ten working days and termination within twenty working days.

Artefacts an auditor will ask for
  • Algorithm filing record (name, type, self-assessment report)
  • Change/termination filings
Where this commonly fails
  • Opinion-influential algorithm not filed within ten working days
CN-ALG-A26
Display of Filing Number

Providers that have completed filing must indicate their filing number in a conspicuous position on their website, application or other service interface and provide a link to the publicised information.

Artefacts an auditor will ask for
  • Filing number displayed on the service interface
Where this commonly fails
  • Filing number not displayed after registration
CN-ALG-A27
Algorithm Security Assessment

Providers with public-opinion attributes or social-mobilisation capacity must carry out a security assessment in accordance with relevant national provisions.

Artefacts an auditor will ask for
  • Completed algorithm security assessment
Where this commonly fails
  • No security assessment for opinion-influential algorithms
CN-ALG-A28
Audit Cooperation and Log Retention

Providers must cooperate with cyberspace and other authorities' supervision and inspection, give explanations, retain relevant logs (records) for the period prescribed by law, and provide necessary technical/data support and assistance.

Artefacts an auditor will ask for
  • Retained algorithm logs/records
  • Inspection cooperation evidence
Where this commonly fails
  • Inadequate log retention or failure to cooperate with inspection
CN-ALG-A7
Algorithm Security Management System

Algorithmic recommendation service providers must establish and improve management systems and technical measures for algorithm-mechanism review, science-and-technology ethics review, user registration, information release review, data security and personal information protection, anti-telecom-fraud, security assessment and monitoring, and security incident response.

Artefacts an auditor will ask for
  • Documented algorithm security management system covering the listed domains
Where this commonly fails
  • Missing one or more mandated management systems (ethics review, incident response, etc.)
CN-ALG-A8
Periodic Algorithm Review (Anti-Addiction)

Providers must regularly review, evaluate and verify algorithm mechanisms, models, data and application outcomes, and must not set up algorithm models that induce users to become addicted or spend excessively, or that violate laws or ethics.

Artefacts an auditor will ask for
  • Periodic algorithm review/evaluation records
Where this commonly fails
  • No periodic algorithm review
  • Addiction-inducing algorithm design
CN-ALG-A9
Illegal and Harmful Information Handling

Providers must strengthen information-content management, establish feature libraries to identify illegal and undesirable information, label or stop transmission, and report illegal information to authorities; undesirable information must be handled per relevant rules.

Artefacts an auditor will ask for
  • Illegal/undesirable-content feature library and handling records
Where this commonly fails
  • No detection/handling of illegal or harmful recommended content

Cross-Cutting

CN-CSL-MLPS
MLPS and Cybersecurity Obligations

The CAC AI regime is grounded in the Cybersecurity Law, Data Security Law and Personal Information Protection Law. Network operators providing these services must fulfil Multi-Level Protection Scheme (MLPS / dengbao) obligations: graded protection, security measures, log retention and incident handling. Referenced here as a cross-cutting obligation; full text not held in this corpus.

Artefacts an auditor will ask for
  • MLPS grading certificate
  • Baseline security controls and log retention
Where this commonly fails
  • No MLPS grading or baseline cybersecurity controls
CN-PIPL-A24
Automated Decision-Making Transparency (PIPL)

Where the recommendation/generation services process personal information through automated decision-making, the Personal Information Protection Law requires transparency and fairness of the decision, prohibits unreasonable differential treatment in trading conditions, and grants individuals the right to an explanation and to refuse decisions made solely by automated means. Referenced here as a cross-cutting obligation of the CAC AI regime; full text not held in this corpus.

Artefacts an auditor will ask for
  • Automated-decision transparency notice
  • Opt-out / human-review mechanism
Where this commonly fails
  • No transparency or opt-out for automated decisions

Deep Synthesis

CN-DS-A10
Content Moderation and Violation Database

Providers must strengthen management of deep synthesis content, take technical or manual measures to review user inputs and synthesis results, establish and improve feature libraries to identify illegal and undesirable information, and keep records and report to authorities when such information is found.

Artefacts an auditor will ask for
  • Input/output moderation controls
  • Illegal-content feature library and reporting records
Where this commonly fails
  • No moderation of deep synthesis inputs or outputs
CN-DS-A14
Training Data Security and Biometric Consent

Providers and technical supporters must strengthen training-data management and ensure data security; where training data contains personal information they must comply with personal-information protection rules, and where it involves editing biometric information such as faces or voices they must notify and obtain the separate consent of the individuals concerned.

Artefacts an auditor will ask for
  • Training-data security controls
  • Separate consent records for biometric editing
Where this commonly fails
  • Editing faces/voices without separate consent
CN-DS-A15
Security Assessment of Editing Functions

Providers and technical supporters offering functions such as biometric editing of faces/voices or generation/significant alteration of content that may involve national security, national image, public interest or social order must conduct a security assessment themselves or commission a professional body.

Artefacts an auditor will ask for
  • Security assessment of high-risk editing/generation functions
Where this commonly fails
  • High-risk biometric editing deployed without security assessment
CN-DS-A16
Technical Marking of Synthetic Content

Providers must add technical markings (e.g. implicit identifiers) to information content generated or edited using deep synthesis that do not affect users' use, and must retain logs in accordance with law.

Artefacts an auditor will ask for
  • Implicit/technical watermarking of synthetic content
  • Log retention
Where this commonly fails
  • Synthetic content without technical markers
CN-DS-A17
Conspicuous Labelling of Synthetic Content

For deep synthesis services that may cause public confusion or mistaken identity (e.g. intelligent dialogue, synthetic human voice, face generation/replacement/manipulation, immersive simulated scenes), providers must add conspicuous labels in reasonable positions to alert the public to the synthesis.

Artefacts an auditor will ask for
  • Conspicuous synthetic-content labels on high-deception services
Where this commonly fails
  • Unlabelled deepfakes or voice clones
CN-DS-A18
No Tampering with Synthesis Identifiers

No organisation or individual may use technical means to delete, alter or conceal the deep synthesis markings required by the Provisions.

Artefacts an auditor will ask for
  • Controls preventing removal of synthesis markings
Where this commonly fails
  • Removal or concealment of synthesis identifiers
CN-DS-A19
Deep Synthesis Filing

Deep synthesis service providers with public-opinion attributes or social-mobilisation capacity must complete filing and change/cancellation procedures under the Algorithmic Recommendation Management Provisions, and display their filing number conspicuously.

Artefacts an auditor will ask for
  • Deep synthesis algorithm filing record and displayed number
Where this commonly fails
  • No filing for opinion-influential deep synthesis services
CN-DS-A20
Security Assessment Before New Functions

When developing and launching new products, applications or functions with public-opinion attributes or social-mobilisation capacity, providers must conduct a security assessment in accordance with relevant national provisions.

Artefacts an auditor will ask for
  • Pre-launch security assessment for mobilisation-capable functions
Where this commonly fails
  • Launching opinion-influential features without security assessment
CN-DS-A6
Prohibited Use of Deep Synthesis

No organisation or individual may use deep synthesis services to produce, copy, publish or transmit information prohibited by law, or to engage in activities such as endangering national security/interests, damaging the national image, infringing others' lawful rights, or fabricating and disseminating false information.

Artefacts an auditor will ask for
  • Acceptable-use policy aligned to the Art. 6 prohibitions
Where this commonly fails
  • Deep synthesis used to fabricate news or harm others
CN-DS-A7
Deep Synthesis Security Management System

Deep synthesis service providers must establish and improve management systems for user registration, algorithm-mechanism review, science-and-technology ethics review, information release review, data security, personal information protection, anti-telecom-fraud, and emergency response, with effective technical safeguards.

Artefacts an auditor will ask for
  • Documented deep-synthesis management systems including ethics review
Where this commonly fails
  • Missing mandated management systems for deep synthesis
CN-DS-A9
Real-Name Verification

Deep synthesis service providers must authenticate the real identity of users based on mobile phone number, identity document number, unified social credit code or national network-identity authentication public service, and must not provide information-publishing services to users who have not completed real-identity authentication.

Artefacts an auditor will ask for
  • Real-name authentication implementation
  • Block on publishing for unverified users
Where this commonly fails
  • Allowing unverified users to publish synthetic content

Ethics

CN-ETH-REV
Science and Technology Ethics Review

Both the Deep Synthesis Provisions (Art. 7) and the Algorithmic Recommendation Provisions (Art. 7) require providers to establish a science-and-technology ethics review system as part of their algorithm management. Ethically sensitive AI activities must undergo ethics review before deployment.

Artefacts an auditor will ask for
  • Science-and-technology ethics review committee/process
  • Ethics review records for AI features
Where this commonly fails
  • No ethics review process for AI/algorithmic features

Generative AI Measures

CN-GAI-A10
Target Users and Minor Anti-Addiction

Providers must clarify and disclose the applicable users, occasions and purposes of the service, guide users to lawful use, and take effective measures to prevent minors from over-reliance on or addiction to generative AI services.

Artefacts an auditor will ask for
  • Disclosed usage scope and guidance
  • Anti-addiction measures for minors
Where this commonly fails
  • No safeguards against minor over-reliance
CN-GAI-A11
Protection of User Input and Records

Providers must fulfil personal-information protection duties for user input information and usage records; must not collect unnecessary personal information, unlawfully retain input/records that can identify users, or unlawfully provide them to others; and must handle data-subject access, copy, correction, supplement and deletion requests in accordance with law.

Artefacts an auditor will ask for
  • Retention and minimisation policy for prompts and logs
  • Data-subject request handling procedure
Where this commonly fails
  • Indefinite retention of identifiable prompts
  • No mechanism for access/deletion requests
CN-GAI-A12
Labelling of Generated Content

Providers must label generated images, videos and other content in accordance with the Provisions on the Management of Deep Synthesis of Internet Information Services.

Artefacts an auditor will ask for
  • Synthetic-content labelling implementation evidence
Where this commonly fails
  • Unlabelled AI-generated media
CN-GAI-A13
Safe, Stable and Continuous Service

Providers must provide safe, stable and continuous service throughout the service period, safeguarding users' normal use.

Artefacts an auditor will ask for
  • Service-availability and continuity controls
  • Incident/outage handling records
Where this commonly fails
  • No continuity safeguards for the service
CN-GAI-A14
Illegal Content Disposal and Reporting

On discovering illegal content, providers must promptly stop generation and transmission, take disposal measures such as model optimisation training, and report to the competent authorities. On discovering a user using the service to engage in illegal activity, providers must warn, restrict functions, suspend or terminate service, keep records and report to authorities.

Artefacts an auditor will ask for
  • Illegal-content takedown procedure
  • User-violation handling and reporting records
Where this commonly fails
  • No takedown or authority-reporting process for illegal content
CN-GAI-A15
Complaint and Reporting Mechanism

Providers must establish a sound complaint and reporting mechanism, set up easy-to-use entry points, disclose the process and timeframes, and promptly handle complaints and provide feedback.

Artefacts an auditor will ask for
  • Published complaint channel and timelines
  • Complaint-handling logs
Where this commonly fails
  • No accessible complaint mechanism
CN-GAI-A16
Categorised and Graded Supervision

Relevant competent authorities (cyberspace, development/reform, education, science/technology, industry/IT, public security, radio/TV, press/publication) supervise generative AI services according to their duties and are to formulate corresponding categorised and graded regulatory rules or guidelines.

Artefacts an auditor will ask for
  • Awareness of applicable sector classification/grading
Where this commonly fails
  • Not applicable as a control objective; defines the supervisory regime
CN-GAI-A17
Security Assessment and Algorithm Filing

Providers of generative AI services with public-opinion attributes or social-mobilisation capacity must carry out a security assessment in accordance with national provisions and complete algorithm filing (and changes/cancellation) under the Algorithmic Recommendation Management Provisions.

Artefacts an auditor will ask for
  • Completed security assessment report
  • Algorithm filing record and number
Where this commonly fails
  • No security assessment or filing for opinion-influential services
CN-GAI-A19
Regulatory Inspection Cooperation

Providers must cooperate with competent-authority supervision and inspection, explain as required the sources, scale and types of training data, annotation rules and algorithm mechanisms, and provide necessary technical and other support; authorities must keep state secrets, trade secrets and personal information confidential.

Artefacts an auditor will ask for
  • Documentation of training data sources/scale/types, annotation rules, algorithm mechanisms ready for inspection
Where this commonly fails
  • Inability to explain data sources or algorithm mechanisms on request
CN-GAI-A2
Scope of Application

Applies to the provision of generative AI services to the public within China to generate text, images, audio or video. Internal research and development not provided to the public is excluded.

Artefacts an auditor will ask for
  • Scoping determination of whether the service is public-facing generative AI under the Measures
Where this commonly fails
  • Treating a public-facing service as exempt internal R&D
CN-GAI-A21
Legal Liability for Violations

Violations are dealt with under the Cybersecurity Law, Data Security Law, Personal Information Protection Law, Law on Scientific and Technological Progress and other laws; where no specific provision exists, authorities may warn, order correction and suspend service; serious cases may incur criminal liability.

Artefacts an auditor will ask for
  • Awareness of enforcement exposure across the cited laws
Where this commonly fails
  • Not applicable as a control objective; defines penalties
CN-GAI-A4
Content Compliance and Prohibited Content

Service provision and use must uphold core socialist values and must not generate content that incites subversion of state power, endangers national security/interests or damages the national image; must not contain ethnic/belief/gender/age/occupation/health discrimination, infringe IP or commercial ethics, harm others' rights (likeness, reputation, honour, privacy, personal information); and must take measures to improve transparency, accuracy and reliability of generated content.

Artefacts an auditor will ask for
  • Content moderation policy mapped to the Art. 4 prohibitions
  • Bias and discrimination testing records
Where this commonly fails
  • No content filter for prohibited categories
  • Unmitigated discriminatory outputs
CN-GAI-A7
Training Data Lawfulness

Providers must use training data from lawful sources, not infringe intellectual property, obtain consent where personal information is used (or meet another lawful basis), and take measures to improve the quality, truthfulness, accuracy, objectivity and diversity of training data, complying with data-protection and other laws.

Artefacts an auditor will ask for
  • Data provenance / licensing records
  • Consent or lawful-basis records for personal data in training sets
  • Data quality assessment
Where this commonly fails
  • Unlicensed or scraped training data
  • No lawful basis for personal data used in training
CN-GAI-A8
Data Annotation Rules

Where data annotation is carried out during development, providers must establish clear, specific and operable annotation rules that meet the Measures' requirements, conduct quality assessment and sampling verification of annotation accuracy, and train annotation staff on the rules.

Artefacts an auditor will ask for
  • Documented annotation rules
  • Annotation quality-assessment and sampling records
  • Annotator training records
Where this commonly fails
  • Undocumented or inconsistent annotation
  • No annotation quality control
CN-GAI-A9
Provider Responsibility for Outputs

The provider bears responsibility as the producer of online information content and as the personal-information processor for information-security obligations, and must sign a service agreement with registered users clarifying both parties' rights and obligations.

Artefacts an auditor will ask for
  • User service agreement
  • Records evidencing producer-liability controls
Where this commonly fails
  • No service agreement defining responsibilities
  • Provider disclaiming responsibility for outputs
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.