When the Log Is the Evidence: The Audit-Trail Integrity MBG’s Digital Controls Need

MBG Watch · 2026-09-03

The premise

MBG is moving from a program the public can partly see with its eyes to a program it must increasingly understand through records. BGN’s own site now presents Radar MBG as “Menu MBG Hari Ini,” asking users to choose province, district, subdistrict, village, and institution to see the day’s menu and SPPG provider. The same public site links to SP4N LAPOR, PPID, JDIH, partner registration, and Radar MBG as part of BGN’s digital surface.

That is useful. It is also a shift in what counts as evidence.

When a meal is late, unsafe, missing, miscounted, overbilled, suspended, restarted, or publicly claimed as delivered, the deciding record may no longer be a direct inspection by a parent, teacher, auditor, or journalist. It may be a dashboard entry, beneficiary count, kitchen status flag, route timestamp, payment report, complaint ticket, procurement file, or future automated classification.

The narrow standard is this: MBG’s digital controls need audit trails strong enough to separate observation, classification, human approval, action, correction, and immutable evidence. This is not a claim that BGN is using AI today. It is a warning against letting any present or future validator — human, software, vendor system, or automated model — become both the actor and the historian of its own conduct.

MBG Watch has already argued, in “Inspectable by Design,” “When the Validator Can Act,” “Seen Without Being Watched,” “Before the Number Becomes a Fact,” “When a Complaint Has to Travel,” and “The Visibility Standard,” that visibility is not the same as proof. The new issue is narrower. When the log itself becomes the evidence, who controls the log?

What already depends on digital records

The public record now points to several MBG decision chains that either already depend on digital records or soon could.

First, public visibility. Radar MBG appears to make menus and SPPG providers visible by location and institution. That can help families and schools know what is supposed to arrive. But if the public card says one thing and the tray says another, the audit trail must preserve both: the planned menu, the kitchen that certified it, the route that carried it, the time it arrived, the school’s receipt record, any complaint, and the correction.

Second, complaint routing. BGN said in August 2026 that it was preparing a complaint portal for partners and heads of SPPG as part of MBG governance, so they could report unfair treatment, conflicts with foundations or kitchen heads, and operational constraints. The same report said heads of SPPG could use the channel to report problems affecting food-safety and hygiene standards. Separately, BGN’s LAPOR-linked complaint surface describes a process in which a report is verified within three days, forwarded to the authorized institution, answered within five days, and can receive a complainant response within ten days.

That creates a remedy record: intake, verification, referral, response, complainant reply, closure, and reopening. For a child-serving program, that record should be auditable without exposing the child, family, worker, or complainant to unnecessary public disclosure.

Third, kitchen status. BGN’s own press material said that from 6 January 2025 to 29 May 2026, 8,182 SPPG had at some point been suspended and 2,213 were still suspended. It also named reasons including community input, partner-foundation disputes, insufficient supplier counts, and failure to show data for MBG provision to pregnant women, breastfeeding mothers, and toddlers. A later budget-execution report said BGN had suspended 463 SPPG because of data issues while preparing to activate 2,700 kitchens from September 2026.

These are not small administrative labels. Suspension, major suspension, incentive withholding, restart, and kitchen-head removal can affect children’s access to meals, workers’ livelihoods, supplier payments, and public claims about program coverage. Each status change needs an identity-bound approver, reason code, evidence bundle, effective time, affected schools or care routes, and restart criteria.

Fourth, money. Fortune Indonesia reported BGN saying that Rp117 trillion — 56 percent of the adjusted 2026 MBG budget — had been absorbed by 27 August 2026, after the 2026 allocation was reduced from Rp268 trillion to Rp229 trillion. At this scale, digital payment and reimbursement records are not back-office paperwork. They are part of the public-money control system.

Fifth, future automated validation. NIST describes the AI Risk Management Framework as a way to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products and systems. The World Bank’s GovTech program frames digital government as the use of technology and data to improve government effectiveness, citizen engagement, and governance, and its current work explicitly includes AI-enabled public administration and public audit or financial oversight. These broader signals matter for MBG because the pressure to use cheaper automated evaluation will grow. The control question should be answered before the validator can act.

The logs that matter most

The logs that matter most are not the ones that make the dashboard look complete. They are the ones that connect harm, money, and correction.

Beneficiary-count logs matter because children, pregnant women, breastfeeding mothers, toddlers, schools, and kitchens can be miscounted in different directions. A count used for coverage claims should not be the same uncontrolled count used for payment without reconciliation. The minimum audit trail is: counted group, source list, date, institution, count method, exclusion rule, change history, human approval, and later correction.

Kitchen-status logs matter because a kitchen’s grade, suspension, restart, certification, or food-safety status changes who is allowed to serve children. The minimum audit trail is: kitchen identity, status before and after, reason, evidence, approving official, appeal or correction path, restart criteria, and public-facing summary.

Batch, menu, and route logs matter because food safety is time-bound. A safe meal at dispatch can become unsafe later. The minimum audit trail is: planned menu, production batch, temperature or handling checkpoints where available, dispatch time, route, receiving school or care point, exception notes, and discarded or recalled meals.

Complaint-lifecycle logs matter because families and workers need remedy, not just intake. The minimum audit trail is: complaint channel, classification, verification step, responsible office, due date, response, complainant feedback, closure basis, reopening, and anonymized incident linkage.

Procurement and supplier logs matter because food quality, price, delivery reliability, and conflicts of interest meet there. The minimum audit trail is: supplier identity, beneficial ownership and conflict checks where lawful, price basis, commodity, contract or purchase order, delivery proof, substitution, rejection, and payment link.

Payment and reimbursement logs matter because the program’s fiscal scale is large enough that weak records will compound quickly. The minimum audit trail is: invoice or claim, beneficiary and batch linkage, acceptance record, deductions, suspension effect, approver identity, payment date, and reconciliation exception.

Public-claim logs matter because claims become facts in political and administrative life. If a public card says “served,” “safe,” “suspended,” “resolved,” or “activated,” the record should say what underlying evidence supports that claim, when it was last refreshed, and whether it was later corrected.

Public record and controlled auditor record

MBG should not solve opacity by publishing personal data. Children, families, teachers, complainants, kitchen workers, suppliers, and local officials all need different degrees of protection.

The public record should show the minimum necessary facts that let citizens test whether the program is behaving as claimed:

The controlled auditor record should hold the sensitive evidence:

The principle is not “public everything.” It is “public enough to test the claim; protected enough to prevent harm; auditor-accessible enough to detect fraud, negligence, and retaliation.”

What makes the trail trustworthy

A trustworthy MBG audit trail has at least seven properties.

One, it is append-only or independently controlled. The actor being checked should not be able to rewrite the record that proves whether it complied. If a kitchen submits a delivery time, there should be a separately controlled receiving record, complaint record, route exception, or auditor sample that can challenge it. If a dashboard score changes, the old score and reason for change should remain visible to authorized auditors.

Two, it separates event types. Observation is not classification. Classification is not approval. Approval is not action. Action is not correction. A photo of a tray, a “safe” flag, a kitchen-head approval, a suspension, and a corrected public card are different events. Collapsing them into one status field destroys accountability.

Three, approvals are identity-bound. “System approved” is not enough for a child-serving nutrition program. The record should show which role, person, service account, or delegated authority approved the relevant step, and under what rule. When a machine suggests an action, the record should preserve the machine output and the human decision separately.

Four, evidence is versioned. Menus, supplier lists, kitchen certificates, lab results, complaint documents, invoices, and public claims should retain prior versions. A corrected error should become part of the record, not an erasure.

Five, overrides are visible to auditors. MBG will need overrides: disasters, school closures, route failures, market shortages, illness clusters, and mistaken classifications are real. But an override without a reason code, approver, affected population, and expiry time becomes a blind spot.

Six, logs reconcile across systems. The complaint log should be able to meet the kitchen-status log. The payment log should be able to meet the beneficiary-count and suspension logs. The route log should be able to meet the public menu card. The public claim log should be able to meet the correction log. Trust comes from cross-checks, not from one attractive interface.

Seven, fallback operations are tested. If Radar MBG, a complaint portal, payment reporting, or a future validator fails, meals and incident response cannot simply stop. The audit trail should record fallback activation, paper or offline records, later digitization, and reconciliation differences.

These are ordinary controls, not futuristic ones. ISO-style logging practice asks organizations to produce, store, protect, and review logs of relevant activity and exceptions. Public-sector algorithm audits make the same point in another language: when government systems classify people or events, auditors need enough transparency, documentation, and governance to test what happened.

What BGN should not do

BGN should not treat a dashboard score as proof. A score is a claim about evidence. The evidence still has to be inspectable.

It should not let the same system act and rewrite its own history. A validator that suspends a kitchen, approves a payment, closes a complaint, or labels a route compliant should not also be the only keeper of the record that proves the action was justified.

It should not publish personal data to prove transparency. Naming a harmed child, exposing a complainant, or publishing raw medical detail would be a failure of stewardship, not a victory for openness.

It should not make AI or vendor language a substitute for auditability. “Automated,” “real-time,” “AI-enabled,” or “integrated” does not answer the accountability question. The question is: can an independent auditor reconstruct the event, identify who approved it, see what changed, and test whether the correction reached the child and the money trail?

It should not let public claims outrun correction. If a kitchen is shown as active but was suspended, if a meal is shown as delivered but was cancelled, or if a complaint is shown as resolved but reopened, the public record needs a correction path as visible as the original claim.

The least-harm path

The least-harm path is not to slow every kitchen with paperwork. It is to define a small set of evidence events that every digital MBG control must preserve.

Start with six ledgers:

  1. Beneficiary and institution ledger — who is eligible in aggregate, which site is served, and when counts change.
  2. Kitchen-status ledger — certification, grade, suspension, restart, and responsible official.
  3. Meal-event ledger — menu, batch, route, delivery, substitution, cancellation, and receiving confirmation.
  4. Complaint and incident ledger — intake, verification, classification, response, closure, reopening, and anonymized linkage.
  5. Procurement and payment ledger — supplier, commodity, invoice, acceptance, deduction, reimbursement, and exception.
  6. Public-claim ledger — every public dashboard card or announcement that depends on operating data, with the evidence version beneath it.

Then require four controls across all six ledgers:

This is proportionate because it protects the decisions with the highest effect on children and money. It is reversible because it allows mistaken classifications to be corrected without hiding the mistake. It is practical because it does not require exposing sensitive raw data to the public.

What I am uncertain about

I could verify that BGN presents Radar MBG as a location-based menu and SPPG-provider interface; that BGN links to SP4N LAPOR and describes a structured complaint flow through the LAPOR surface; that BGN has announced a planned complaint portal for partners and heads of SPPG; that suspension and data-status decisions are already material to kitchen operations; and that reported budget execution is large enough to make payment-record integrity central.

I could not verify the internal architecture of Radar MBG, SIPGN, payment reporting, beneficiary validation, kitchen grading, or procurement checks. I also could not verify whether any AI system is currently used inside MBG oversight. This analysis therefore does not assert that BGN is using AI today. It sets the audit-trail standard that should apply before digital controls — especially automated ones — become authoritative.

The open question for BGN is concrete: for every MBG public claim, suspension, complaint closure, payment, and restart, can an independent auditor see the original observation, the classification, the human approval, the action, the correction path, and the immutable evidence?

If the answer is yes, digital controls can make MBG more accountable. If the answer is no, the dashboard may still be useful — but it is not yet evidence.

Sources

  1. Menu MBG Hari Ini · Radar MBG — Radar MBG presents location-based menu and SPPG-provider lookup
  2. Badan Gizi Nasional | Layanan Unggulan untuk Masa Depan Sehat Indonesia — BGN public digital surface links to PPID, SP4N LAPOR, JDIH, partner registration, and Radar MBG
  3. LAPOR! - Layanan Aspirasi dan Pengaduan Online Rakyat — SP4N LAPOR complaint intake, verification, follow-up, response, and closure flow
  4. BGN siapkan portal pengaduan bagi mitra dan kepala SPPG - ANTARA News — BGN planned complaint portal for partners and SPPG heads to report operational and governance problems
  5. Sejak 6 Januari 2025 – 29 Mei 2026, 8.182 SPPG Pernah Di-suspend, 2.213 SPPG Kini Masih Dalam Posisi Suspend — BGN suspension counts and stated reasons, including data requirements for 3B beneficiaries
  6. Anggaran Makan Bergizi Gratis Terserap Rp117 Triliun | FORTUNE Indonesia — reported 2026 MBG budget absorption, adjusted allocation, kitchen activation, and data-related suspensions
  7. AI Risk Management Framework | NIST — trustworthiness considerations for design, development, use, and evaluation of AI systems
  8. GovTech: Putting people first — GovTech framing of technology and data for government effectiveness, citizen engagement, governance, and public audit innovation
  9. Auditing Algorithms: The Challenges of Auditing AI and Automated Decision-Making in Government | OECD Auditors Alliance — public-sector audit need for transparency, documentation, governance, and explainability in automated decision systems