ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM)
Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Asset Management
Triggers for information delivery during operational phase are identified and managed.
- Trigger list
- Procedure document
- Schedule of updates
- Operational triggers not linked to maintenance system
- No periodic refresh
AIR specifies information needed for operational decisions throughout asset lifecycle.
- AIR specification
- Use case library
- Approval signoff
- AIR copied from PIR
- Use cases not validated by FM team
Appointed party for asset information updates is selected with clear responsibilities and deliverables.
- Signed appointment
- RACI
- Deliverable list
- Updates outsourced without controls
- Deliverables not tied to triggers
Information is produced and quality-assured for operational use across asset systems.
- Workflow record
- QA reports
- Integration test logs
- AIM not synced with CAFM
- Quality checks skipped
Asset Information Model (AIM) is maintained current and reflects actual asset state.
- AIM version log
- Validation reports
- Discrepancy register
- AIM drift from physical asset
- No periodic validation
Concepts and Principles
Information management activities follow defined process throughout asset and project lifecycle.
- IM process diagram
- RACI matrix
- Stage gate checklist
- Process not embedded in project gateways
- Roles unclear at handover
Common Data Environment (CDE) is implemented to enable collaborative production and management of information.
- CDE configuration
- WIP-Shared-Published-Archived states
- User access matrix
- States not enforced by tool
- Approval gates bypassed
Information is structured into containers with consistent naming, classification and metadata.
- Naming standard
- Classification tables
- Metadata template
- Project teams improvise names
- Classification inconsistent
General
Information containers follow standardised naming convention across project and asset lifecycle.
- Naming policy
- Validation tooling
- Exception register
- Suffix codes inconsistent
- No automated validation
Information models are federated according to defined strategy enabling coordination and clash detection.
- Federation diagram
- Clash reports
- Coordination minutes
- Clash detection ad-hoc
- Federation rules not documented
Part 1: Concepts and Principles
Defines the conceptual framework for information management throughout the asset lifecycle, including the information delivery cycle.
- tender response documentation
- BIM execution plan
- information delivery plan
- common data environment configuration
- asset information model
- unclear information requirements
- missing CDE access controls
- weak project information model handover
- insufficient security triage
- gaps in mobilisation evidence
Establishes team structures, roles, and responsibilities for managing information within project and asset management contexts.
- common data environment configuration
- asset information model
- security triage register
- unclear information requirements
- missing CDE access controls
- weak project information model handover
- insufficient security triage
- gaps in mobilisation evidence
Provides guidance on delivery planning including Master Information Delivery Plans (MIDP) and Task Information Delivery Plans (TIDP).
- asset information model
- security triage register
- tender response documentation
- BIM execution plan
- insufficient security triage
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
Defines the CDE solution and workflows for managing collaborative production of information across project teams.
- common data environment configuration
- asset information model
- security triage register
- tender response documentation
- BIM execution plan
- information delivery plan
- unclear information requirements
- missing CDE access controls
- weak project information model handover
- insufficient security triage
- gaps in mobilisation evidence
Describes the Project Information Model (PIM) for the delivery phase and Asset Information Model (AIM) for the operational phase.
- security triage register
- tender response documentation
- BIM execution plan
- information delivery plan
- common data environment configuration
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
- weak project information model handover
- insufficient security triage
Part 2: Delivery Phase of Assets
Requires the appointing party to assess the need for information management and establish the approach and responsibilities.
- common data environment configuration
- asset information model
- security triage register
- tender response documentation
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
Requires compilation of exchange information requirements and establishment of project information requirements for tender.
- tender response documentation
- BIM execution plan
- information delivery plan
- common data environment configuration
- asset information model
- missing CDE access controls
- weak project information model handover
- insufficient security triage
- gaps in mobilisation evidence
- unclear information requirements
Requires the lead appointed party to prepare a BIM Execution Plan (BEP) in response to project information requirements.
- BIM execution plan
- information delivery plan
- common data environment configuration
- asset information model
- weak project information model handover
- insufficient security triage
- gaps in mobilisation evidence
Requires confirmation of the information delivery plan and finalization of the BEP upon appointment.
- security triage register
- tender response documentation
- BIM execution plan
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
- weak project information model handover
- insufficient security triage
Requires the appointed party to mobilize resources, establish the CDE, and test information production methods.
- BIM execution plan
- information delivery plan
- common data environment configuration
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
- weak project information model handover
- insufficient security triage
Requires teams to produce information in accordance with the agreed delivery plan using CDE workflows.
- BIM execution plan
- information delivery plan
- common data environment configuration
- insufficient security triage
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
- weak project information model handover
Requires review and authorization of information model deliverables against project information requirements.
- common data environment configuration
- asset information model
- security triage register
- missing CDE access controls
- weak project information model handover
- insufficient security triage
- gaps in mobilisation evidence
- unclear information requirements
Requires compilation of the as-built Project Information Model and handover to the appointing party.
- security triage register
- tender response documentation
- BIM execution plan
- unclear information requirements
- missing CDE access controls
- weak project information model handover
Part 3: Operational Phase of Assets
Requires the asset owner to establish organizational information requirements and asset information requirements.
- tender response documentation
- BIM execution plan
- information delivery plan
- common data environment configuration
- asset information model
- unclear information requirements
- missing CDE access controls
- weak project information model handover
- insufficient security triage
- gaps in mobilisation evidence
Requires ongoing maintenance of the Asset Information Model throughout the asset's operational life.
- tender response documentation
- BIM execution plan
- information delivery plan
- insufficient security triage
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
Defines events that trigger information updates, such as maintenance activities, renovations, and regulatory changes.
- information delivery plan
- common data environment configuration
- asset information model
- security triage register
- tender response documentation
- BIM execution plan
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
- weak project information model handover
Requires seamless transfer of BIM data and documentation from the delivery to operational phase.
- security triage register
- tender response documentation
- BIM execution plan
- information delivery plan
- common data environment configuration
- insufficient security triage
- gaps in mobilisation evidence
- unclear information requirements
Part 5: Security-Minded Approach to Information Management
Requires assessment of the sensitivity of built asset information and classification of data accordingly.
- security triage register
- tender response documentation
- BIM execution plan
- information delivery plan
- common data environment configuration
- asset information model
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
Requires a structured triage process to determine appropriate security measures based on information sensitivity.
- BIM execution plan
- information delivery plan
- common data environment configuration
- asset information model
- unclear information requirements
- missing CDE access controls
- weak project information model handover
Requires implementation of security controls for managing sensitive built asset information throughout its lifecycle.
- information delivery plan
- common data environment configuration
- asset information model
- security triage register
- tender response documentation
- insufficient security triage
- gaps in mobilisation evidence
- unclear information requirements
Requires procedures for identifying, responding to, and recovering from information security breaches.
- common data environment configuration
- asset information model
- security triage register
- tender response documentation
- BIM execution plan
- information delivery plan
- gaps in mobilisation evidence
- unclear information requirements
- missing CDE access controls
Project Delivery
Appointing party assesses need for information and defines purpose for information delivery.
- Needs analysis
- Purpose document
- Consultation log
- Information requested without purpose
- No stakeholder input
Project close-out archives information model and transfers asset information to operational environment.
- Archive index
- AIM handover record
- Lessons learned log
- AIM not validated before transfer
- Archive missing context
Organisational, asset, project and exchange information requirements are established and communicated.
- OIR document
- AIR document
- PIR document
- EIR document
- EIR copied from template without tailoring
- AIR missing for existing assets
Information standard, production methods and procedures for project are established.
- Project information standard
- Method statements
- Reference library link
- Standard not version-controlled
- Methods not enforced
Invitation to tender includes EIR and information particulars sufficient for prospective lead appointed parties.
- Tender documents
- EIR appendix
- Evaluation matrix
- EIR missing from tender
- Criteria not weighted for BIM
Prospective lead appointed party responds with BIM Execution Plan (BEP), capability and capacity evidence.
- BEP document
- Capability matrix
- Capacity statement
- BEP unsigned
- Capacity claims not evidenced
Appointment confirms information requirements, delivery responsibility matrix and BEP are agreed and signed.
- Contract appendix
- TIDP roll-up
- Master Information Delivery Plan
- BEP versioned after signing without re-approval
- TIDP gaps
Project delivery team mobilises resources, technology and information ahead of production.
- Mobilisation plan
- Tool deployment record
- Project information model start state
- CDE not configured at mobilisation
- Skills gap discovered late
Information is produced collaboratively in CDE following defined checks, reviews and approvals.
- Workflow configuration
- QA checklists
- Approval audit trail
- Approvals bypassed under deadline pressure
- No technical author check
Information model is delivered at defined exchange points and accepted by appointing party.
- MIDP
- Delivery notes
- Acceptance signoffs
- Acceptance criteria not measurable
- Delivery dates slip without re-baseline
Security
Security-minded approach is applied to identify sensitivity and security needs for information.
- Sensitivity assessment record
- Built Asset Security Strategy
- Built Asset Security Management Plan
- Sensitivity assessment done once and not updated
- Strategy not approved by senior leadership
Built asset security information requirements define what information is sensitive and how it is protected.
- Sensitive data register
- Control implementation evidence
- Role-based access list
- Sensitive items mixed with general data in CDE
- Access reviews not periodic
Process for managing security incidents affecting built asset information is established.
- Incident response plan
- On-call roster
- Post-incident reviews
- No tabletop exercise
- Lessons not fed back into security plan
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) framework page.