Skip to content

Evidence request lists

CSA STAR (Security, Trust, Assurance, and Risk)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CSA STAR: Assurance Quality and Lifecycle

STAR-INTERNAL-01
Internal audit coverage of STAR scope

The provider performs internal audit or self-assessment of the CCM controls in the STAR scope between external assessments, to maintain readiness and detect drift.

Artefacts an auditor will ask for
  • Internal audit/self-assessment results covering the STAR scope
  • Remediation tracking from internal findings
Where this commonly fails
  • No internal assurance between external assessments
STAR-NONCONF-01
Nonconformity and corrective action management

Nonconformities identified during assessment or surveillance are recorded, root-caused, and remediated through corrective action within the timeframes required by the scheme.

Artefacts an auditor will ask for
  • Nonconformity register and corrective-action records
  • Evidence of timely closure of findings
Where this commonly fails
  • Open nonconformities past their deadline
  • No corrective-action process
STAR-RETIRE-01
Status withdrawal and suspension

Where the provider no longer meets the requirements, or on request, its STAR status is suspended or withdrawn and the registry updated, so published assurance is not misleading.

Artefacts an auditor will ask for
  • Process for suspension/withdrawal of STAR status
  • Registry reflecting any withdrawal
Where this commonly fails
  • Continuing to claim STAR status after it lapses or is withdrawn
STAR-RISK-01
Risk treatment alignment with CCM

The provider's risk treatment decisions for the assessed service are aligned with the CCM control objectives, with residual risks documented and accepted at an appropriate level.

Artefacts an auditor will ask for
  • Risk register linking treatments to CCM control objectives
  • Documented residual-risk acceptance
Where this commonly fails
  • Risk treatment disconnected from the CCM controls assessed

CSA STAR: Level 1 Self-Assessment (CAIQ)

STAR-CAIQ-01
CAIQ response accuracy and completeness

Each CAIQ response must accurately and completely reflect the provider's implementation of the corresponding CCM control, with no misleading or unsupported answers.

Artefacts an auditor will ask for
  • Internal review confirming CAIQ answers are evidenced
  • Mapping of CAIQ answers to supporting controls/evidence
Where this commonly fails
  • Yes answers unsupported by implemented controls
  • Responses copied without verification
STAR-CCM-01
CCM control mapping completeness

The assessment covers the full set of applicable CCM control domains, with any not-applicable controls justified, so the assurance reflects the complete CCM control set rather than a subset.

Artefacts an auditor will ask for
  • Coverage matrix of CCM domains assessed
  • Justification for any controls marked not applicable
Where this commonly fails
  • CCM domains silently omitted
  • Unjustified not-applicable determinations
STAR-L1-01
Level 1 CAIQ self-assessment submission

At Level 1 the provider completes the Consensus Assessments Initiative Questionnaire (CAIQ) self-assessment against the CCM and submits it to the publicly accessible STAR Registry.

Artefacts an auditor will ask for
  • Completed CAIQ self-assessment against the current CCM version
  • Evidence of submission to the STAR Registry
Where this commonly fails
  • Incomplete CAIQ responses
  • Self-assessment not published to the registry
STAR-L1-02
Self-assessment refresh cadence

The provider refreshes and resubmits its Level 1 self-assessment on a regular basis so that the published assurance reflects the current state of the service.

Artefacts an auditor will ask for
  • Dated self-assessment showing periodic refresh
  • Change log of material updates between submissions
Where this commonly fails
  • Stale self-assessment no longer reflecting the service
  • No refresh cadence defined

CSA STAR: Level 2 Third-Party Assurance

STAR-L2-01
STAR Certification (ISO/IEC 27001 + CCM)

STAR Certification is a third-party independent assessment that integrates the requirements of ISO/IEC 27001 with the CCM, including a maturity assessment, performed by an accredited certification body.

Artefacts an auditor will ask for
  • Valid STAR Certification certificate and report
  • Underlying ISO/IEC 27001 certification covering the service
  • Maturity assessment results
Where this commonly fails
  • Claiming certification without an accredited body
  • ISO 27001 scope not covering the assessed service
STAR-L2-02
STAR Attestation (SOC 2 + CCM)

STAR Attestation, developed in collaboration with the AICPA, is a third-party attestation that combines a SOC 2 examination with the CCM criteria, performed by a licensed CPA firm.

Artefacts an auditor will ask for
  • SOC 2 + CCM STAR Attestation report from a licensed CPA firm
  • Mapping of CCM criteria into the SOC 2 examination
Where this commonly fails
  • SOC 2 report without the CCM mapping
  • Attestation by an unqualified provider
STAR-L2-03
C-STAR assessment (Greater China market)

C-STAR is a third-party independent assessment of a cloud service provider for the Greater China market, harmonising the CCM with applicable Chinese national standards.

Artefacts an auditor will ask for
  • C-STAR assessment evidence where the provider serves the Greater China market
Where this commonly fails
  • Using C-STAR claims outside its assessed scope
STAR-L2-04
Accredited assessor / auditor selection

Level 2 assessments must be performed by assessors that are appropriately accredited or qualified (certification body, licensed CPA firm, or CSA-qualified auditor) for the relevant STAR scheme.

Artefacts an auditor will ask for
  • Evidence of the assessor's accreditation/qualification for the STAR scheme used
Where this commonly fails
  • Assessor lacking the required accreditation
STAR-L2-05
Maturity model scoring

STAR Certification includes a maturity capability assessment that scores the management of CCM control areas beyond a pass/fail basis, giving customers insight into control maturity.

Artefacts an auditor will ask for
  • Maturity scoring results per CCM control area
  • Methodology used for the maturity assessment
Where this commonly fails
  • No maturity assessment where the scheme requires it
STAR-L2-06
Surveillance and recertification cycle

STAR Certification and Attestation are maintained through periodic surveillance and recertification activities, consistent with the underlying ISO 27001 or SOC 2 cycle.

Artefacts an auditor will ask for
  • Surveillance audit and recertification records
  • Currency of the certificate/report
Where this commonly fails
  • Lapsed certificate presented as current
  • No surveillance activity between certifications

CSA STAR: Level 3 Continuous

STAR-L3-01
Continuous auditing capability

STAR Continuous provides ongoing, automated validation of security controls between point-in-time assessments, enabling near-real-time assurance of the cloud service.

Artefacts an auditor will ask for
  • Continuous control-monitoring tooling and outputs
  • Evidence of automated validation against CCM controls
Where this commonly fails
  • Only point-in-time assurance where continuous is claimed
STAR-L3-02
Continuous evidence publication

Continuous assurance evidence (such as STARWatch / STAR Continuous outputs) is maintained and made available to support the published continuous assurance status.

Artefacts an auditor will ask for
  • Continuous-assurance evidence records and publication
  • Linkage of continuous evidence to CCM controls
Where this commonly fails
  • Continuous status without supporting evidence

CSA STAR: Program, Scope and Shared Responsibility

STAR-PROG-01
STAR Program eligibility and assurance-level selection

The cloud service provider determines its eligibility for the STAR program and selects the appropriate assurance level (Level 1 self-assessment, Level 2 third-party certification or attestation, or Level 3 continuous), based on the assurance its customers require.

Artefacts an auditor will ask for
  • Documented decision on the STAR assurance level pursued and rationale
  • Evidence the offered cloud service is in scope of the STAR program
Where this commonly fails
  • No defined STAR assurance objective
  • Claiming a STAR level not actually achieved
STAR-SCOPE-01
Service scope definition for the assessment

The provider defines the boundary of the cloud service(s) covered by the STAR self-assessment or certification, including the service models and components in scope, so that the assurance statement accurately reflects what was assessed.

Artefacts an auditor will ask for
  • Documented scope statement of the assessed service and its boundaries
  • Architecture/service description supporting the scope
Where this commonly fails
  • Ambiguous or overstated assessment scope
  • Scope excluding components customers rely on
STAR-SHARED-01
Shared responsibility disclosure

The provider documents and discloses the shared security responsibility model for the service, identifying which CCM controls are the responsibility of the provider, the customer, or shared, consistent with the CCM Shared Security Responsibility Model.

Artefacts an auditor will ask for
  • Shared responsibility matrix mapping CCM controls to provider/customer/shared
  • Customer-facing responsibility guidance
Where this commonly fails
  • No shared responsibility model published
  • Responsibilities for key controls left undefined
STAR-SUPPLY-01
Subservice and supply chain disclosure

The provider identifies subservice organisations and supply chain dependencies relevant to the assessed service, and reflects their treatment (inclusive or carve-out) in the assurance statement.

Artefacts an auditor will ask for
  • List of subservice organisations and the inclusive/carve-out treatment
  • Assurance over relevant subservice controls
Where this commonly fails
  • Undisclosed subservice dependencies
  • Carve-out subservices with no complementary controls stated

CSA STAR: Registry and Customer Transparency

STAR-COMM-01
Customer communication of assurance status

The provider communicates its STAR assurance status and the associated reports/certificates to customers and prospects in a clear and non-misleading way.

Artefacts an auditor will ask for
  • Customer-facing assurance documentation (reports, certificates, CAIQ)
  • Process for sharing assurance artefacts under NDA where needed
Where this commonly fails
  • Overstating the assurance level to customers
STAR-INCIDENT-01
Incident notification to registry users

Where the program or customer commitments require, the provider notifies affected customers/registry users of security incidents affecting the assessed service in a timely manner.

Artefacts an auditor will ask for
  • Customer incident-notification procedure
  • Records of notifications made
Where this commonly fails
  • No customer notification path for incidents affecting assured services
STAR-REG-01
STAR Registry listing

The provider's assurance status (Level 1 self-assessment, Level 2 certification/attestation, or continuous) is published in the publicly accessible CSA STAR Registry so customers can verify it.

Artefacts an auditor will ask for
  • STAR Registry entry for the assessed service
  • Accuracy of the level and status shown
Where this commonly fails
  • Assurance not published to the registry
  • Registry entry inconsistent with actual status
STAR-REG-02
Registry update process

The provider keeps its STAR Registry entry current, updating it on reassessment, recertification, scope change, or withdrawal.

Artefacts an auditor will ask for
  • Process for updating the registry entry on material change
  • History of registry updates
Where this commonly fails
  • Outdated registry entry after scope or status change
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.