Vigilance Reporting Criteria define which information observed and analyzed through AI Vigilance should become subject to formal Reporting. Because Vigilance continuously processes large volumes of Events, Incidents, Changes, and Signals from Real-world Operation, it is neither practical nor useful to Report every Observation at the same level of granularity or significance. What is required is a distinction between Observation itself and Reportable Information that should be preserved as an Institutional Record.

Reporting Criteria should include the relevant Scope / Coverage, reportable Events / Incidents, Trends / Changes identified over time, Findings / Significance established through analysis, and Responses / Actions taken in relation to them. They should also identify the Evidence and its Limitations supporting each determination. This makes it possible to distinguish not only “what was observed,” but also “why it became reportable,” “what Response was taken,” “what can be established from the available Evidence,” and “what remains unknown.”

Reporting Criteria are not a Checklist requiring all information generated through Vigilance to be Reported uniformly. They are Governance Criteria for determining which information should be connected to which Reporting Process according to factors such as Signal Severity, Materiality, Urgency, scope of impact, Repetition, and Governance Relevance. This prevents Routine Observations and significant Findings from being treated identically and connects relevant information to the appropriate Institutional Response.

However, defining Reporting Criteria alone does not establish the reliability of the Report itself. Reported Events, Findings, Evaluations, and Responses must be connected to the underlying Evidence Architecture, including Evaluation Tags, the Governance State at the relevant time, Decision-State Evidence (DSE) and Provenance, Event / Execution Records, and Audit Trails, so that they can later be independently verified.

The objective is not to trust the explanation provided by the Human or AI that produced the Report. It must be possible to trace statements in the Report back to the underlying Events and Evidence, the Governance State at the relevant time, and associated Decisions and Executions, allowing verification of why a particular Finding or Response was formed. Where Evidence is insufficient, that insufficiency must itself remain visible as a Limitation.

Accordingly, Vigilance Reporting Criteria define “what must be reported,” while Evidence Architecture supports “how that report can be verified.” By connecting these two functions, a Vigilance Report becomes more than information sharing or a Monitoring Summary. It becomes a Verifiable Institutional Record that can support Audit / Assurance, Institutional Review, and Governance Update.