Yes, approved
No rule fires on this answer, for a third-party or fine-tuned model that reaches a consumer. A reviewer moves on.
A provenance record states where the training or tuning data came from, what period it covers, roughly how much of it there was, and what you took out before training, such as personal data or one customer's proprietary content. A commit message or a notebook is not a provenance record.
For a model you fine-tuned or bought, this is the finding most likely to be raised. An examiner wants to know what went in, where it came from, and what was stripped out. Engineering notes are not the same as an approved record.
Each outcome below was produced by running Vaulith's rules engine on that answer, for a third-party or fine-tuned model that reaches a consumer. The same rules run in the paid assessment, on your whole estate, with the arithmetic shown.
No rule fires on this answer, for a third-party or fine-tuned model that reaches a consumer. A reviewer moves on.
The training corpus is described in engineering documentation but has never been approved as a record. Because the model is consumer-impacting, it is the one an examiner is most likely to name, and the gap sits on exactly that model.
The snapshot asks this and eight more, in about ninety seconds, with nothing leaving your browser, and returns every finding with its reasoning and its remediation.