Direct answer
The point of a self-check is that it can be verified, so keep three categories of evidence: configuration evidence (screenshots or exports of the transfer rules, thresholds and keyword lists), operational evidence (samples of real conversations, including cases where a transfer fired correctly), and process evidence (who is responsible, the recheck cycle, and remediation records). The standard does not set a single retention period, so follow your industry's data retention requirements and your contracts; the principle is to cover one complete recheck cycle and still be able to trace back to a specific conversation.
Why "we did it" is not the same as "we can prove we did it"
Ticking boxes on a self-check sheet is easy. The usual problem is being unable to produce anything when someone asks a follow-up question. What a client, a platform or a reviewer wants is not your conclusion but the evidence behind it — which is why a self-check should be run on a record-keeping basis from day one.
Three categories of evidence — leave one out and it is incomplete
Configuration evidence (proving the rules exist)
- Screenshots or export files of the transfer configuration, including the five automatic-transfer scenarios;
- the configured values for the keyword list, the failure threshold and the timeout;
- a version record: what was changed, when, and to what.
Operational evidence (proving the rules actually fire)
- Real conversation samples: at least a few actual triggers kept for each type of automatic-transfer scenario;
- sampling records: conversations drawn at random on a fixed cycle and assessed one by one for transfers that should have fired and did not, or records that should have been kept and were not;
- an exception log: transfer failures found through complaints or internally, and how they were resolved.
Process evidence (proving someone is accountable)
- A named owner list: who sets, changes and reviews the human-machine collaboration rules;
- the recheck cycle and the conclusion of the most recent recheck;
- remediation records: the issue found, the action taken, and the date it was closed.
How to decide a retention period
The standard itself gives no uniform retention period. In practice, take the strictest of three: your industry's data retention requirements, the terms agreed with customers or platforms, and coverage of one complete recheck cycle with traceability back to a specific conversation. Whichever of the three demands the longest wins. If there is no clear basis yet, retain for at least one annual cycle and write the policy into your internal rules.
How to sample so that it means something
Sampling is not reading a few conversations at random; it is drawing by scenario. Take at least 5 conversations for each of the five automatic-transfer scenarios and check whether they triggered as required, then take 20 ordinary conversations at random and look for cases that should have transferred but did not. The first set verifies the rule; the second finds the blind spots.
One point that is easy to miss
Conversation records can themselves contain customer personal information. Record-keeping and personal information protection have to be satisfied at the same time: keep only the fields you need, control who can see them, and log access. Piling up every raw conversation indefinitely in the name of compliance is a different kind of risk.
Key facts
| Evidence categories | Three: configuration / operational / process |
| Targeted sampling | At least 5 conversations per automatic-transfer scenario, plus 20 random ordinary conversations |
| Basis for retention | Industry requirements / contract terms / coverage of one recheck cycle — whichever is strictest |
| Must-keep items | Transfer configuration, thresholds and keyword lists, real transfer trigger samples, owners and recheck records |
Sources
- GB/T 47746—2026, chapter 4 (general requirements — service safety and control)
- GB/T 47746—2026, clause 5.2.2.6 (automatic transfer in specific scenarios)
- Record-keeping items among the 59 checklist items (including 53 mandatory items)
Follow-up questions
Do I have to keep raw conversations?
Not the full set of raw conversations. Keep the samples and statistics that demonstrate the rules are working, and handle personal information as necessary, so that record-keeping does not create a new exposure of its own.
How long is long enough?
The standard gives no uniform figure. Take the strictest of industry retention requirements, contract terms and coverage of a recheck cycle; with no clear basis, retain for at least one annual cycle and write it into your policy.
If there are no complaints, can I skip the evidence?
No. Records demonstrate that the rules exist and are effective, regardless of whether a complaint has occurred. When a dispute does arise, the side without evidence is in the weaker position.
Do configuration screenshots count as valid evidence?
They are a starting point, not the finish line. Screenshots prove the rules exist; you also need operational evidence showing they have actually been triggered. The two together are what make it complete.