CNBS 025/2022: the log must identify the person
The IT Management Rules apply to every institution supervised by the CNBS. When a growing share of changes is generated by AI, Article 42 stops having a clean answer in tickets and screenshots.
CNBS 025/2022 · Article 42 · LogsRequires automated records identifying “the person, place, time and actions,” available to the Commission on demand.
Retention: five years for transactions. Evidence must be independently verifiable, even years later.
What the regulation demands of software development
- Art. 7. IT management framework with every internal process duly documented.
- Art. 22. Specific security controls, including development.
- Arts. 39-41. Specialized, risk-based internal systems audit.
- Art. 43. Record retention: five years for transactions.
How LineBreak answers
- Nothing reaches production with known vulnerabilities. Every change is scanned before merging; if the scanner cannot run, the change does not pass. Exceptions are human, scoped to one exact finding, with name and reason on the record.
- The AI writes the code; an identified person signs. Approved criteria carry the name of who approved them. The AI writing code can read them, but cannot modify them.
- Every approval is cryptographically signed. Your auditor verifies it independently, without relying on us or on the team's word, years later if needed.
- The evidence lives in YOUR infrastructure. Not on our servers. The record of every change (who approved what, when, with what result) travels with the code itself.
What LineBreak is NOT
- LineBreak does not certify or guarantee compliance with any regulation: it produces the evidence your accountable people answer with.
- It does not replace the roles your regulation requires (security officers, internal audit, regulatory reporting).
- Decisions and accountability remain human. That is the product's design principle.
An AI-generated change is blocked, a person approves it by name, and the audit report is generated in front of you. With your risk team or your auditor present.