Regulation — energy-specific
NERC CIP-013 R6 + CIP-005 — AI supply-chain risk + BES cyber + audit records
CIP-013 requires each Responsible Entity to implement a documented supply-chain cyber-security risk management plan for BES Cyber Systems. When the supplier is an AI/ML vendor whose model influences grid operations, the plan has to cover model-supply-chain risk, not just hardware and firmware. CIP-013 R6 governs how long the audit records need to be kept.
What the regulation actually says
"Each Responsible Entity shall implement one or more documented supply chain cyber security risk management plan(s) for high and medium impact BES Cyber Systems … The plan(s) shall address … identification and assessment of cyber security risk(s) to the Bulk Electric System from vendor products or services resulting from … (i) procuring and installing vendor equipment and software; and (ii) transitions from one vendor(s) to another vendor(s)."
CIP-013-2 — Requirement R1 (paraphrased operative language)
"Each Responsible Entity shall keep data or evidence to show compliance … unless directed by its Compliance Enforcement Authority to retain specific evidence for a longer period as part of an investigation."
CIP-013 — Requirement R6 (record retention obligation)
"Each Responsible Entity shall implement one or more documented processes … to permit only necessary inbound and outbound electronic access to BES Cyber Assets …"
CIP-005-6 — Requirement R1 (Electronic Security Perimeter, paraphrased)
What this means in plain English
Three obligations relevant to AI grid-load-forecasting:
- Identify the risk. The AI vendor is a supplier. Model-drift, vendor-model-update, and vendor-data-pipeline changes are supply-chain events that can affect grid reliability.
- Retain the records. Every AI-driven forecast + dispatch decision, plus the model version at decision-time, has to be kept long enough to survive a NERC compliance audit or FERC Section 206 investigation.
- Protect the perimeter. AI systems that read from or write to BES cyber assets sit inside the Electronic Security Perimeter and inherit CIP-005 controls.
What triggers the exposure in the sample
The AI grid-load-forecaster produced 4,969 scored forecast intervals over the audit window. Every one is subject to CIP-013 R6 retention once a NERC compliance audit, FERC Section 206 investigation, state PUC customer-hearing, ISO/RTO market-monitor referral, or wholesale market-manipulation inquiry is reasonably anticipated. Without model-version pin + input snapshot + decision hash, retention is nominal rather than defensible.
What the $499 Snapshot shows against this rule
- Model version pinned per forecast interval — the supply-chain-change record
- Input snapshot bound to output via cryptographic hash — the tamper-evident retention
- Independent retention pipeline distinct from the production model — the CIP-013 R6 record
- Signed independent-verifier declaration — the "reasonable-diligence" evidence a NERC auditor will look for
See the 5-decision reproducibility drill →
$499 Snapshot. 3 business days.
Model-version pin + decision-hash-bound retention + signed independent-verifier declaration on your operator's actual AI surface.
Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.