Skip to content

Evidence request lists

ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM)

Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Asset Management

P3.5.1
Asset Information Triggers

Triggers for information delivery during operational phase are identified and managed.

Artefacts an auditor will ask for
  • Trigger list
  • Procedure document
  • Schedule of updates
Where this commonly fails
  • Operational triggers not linked to maintenance system
  • No periodic refresh
P3.5.2
Asset Information Requirements (AIR)

AIR specifies information needed for operational decisions throughout asset lifecycle.

Artefacts an auditor will ask for
  • AIR specification
  • Use case library
  • Approval signoff
Where this commonly fails
  • AIR copied from PIR
  • Use cases not validated by FM team
P3.5.4
Appointment for Asset Information Updates

Appointed party for asset information updates is selected with clear responsibilities and deliverables.

Artefacts an auditor will ask for
  • Signed appointment
  • RACI
  • Deliverable list
Where this commonly fails
  • Updates outsourced without controls
  • Deliverables not tied to triggers
P3.5.5
Information Production for Asset

Information is produced and quality-assured for operational use across asset systems.

Artefacts an auditor will ask for
  • Workflow record
  • QA reports
  • Integration test logs
Where this commonly fails
  • AIM not synced with CAFM
  • Quality checks skipped
P3.5.6
Asset Information Model Maintenance

Asset Information Model (AIM) is maintained current and reflects actual asset state.

Artefacts an auditor will ask for
  • AIM version log
  • Validation reports
  • Discrepancy register
Where this commonly fails
  • AIM drift from physical asset
  • No periodic validation

Concepts and Principles

P1.5
Information Management Process

Information management activities follow defined process throughout asset and project lifecycle.

Artefacts an auditor will ask for
  • IM process diagram
  • RACI matrix
  • Stage gate checklist
Where this commonly fails
  • Process not embedded in project gateways
  • Roles unclear at handover
P1.6
Common Data Environment

Common Data Environment (CDE) is implemented to enable collaborative production and management of information.

Artefacts an auditor will ask for
  • CDE configuration
  • WIP-Shared-Published-Archived states
  • User access matrix
Where this commonly fails
  • States not enforced by tool
  • Approval gates bypassed
P1.7
Information Containers

Information is structured into containers with consistent naming, classification and metadata.

Artefacts an auditor will ask for
  • Naming standard
  • Classification tables
  • Metadata template
Where this commonly fails
  • Project teams improvise names
  • Classification inconsistent

General

GEN.1
Naming Convention for Information Containers

Information containers follow standardised naming convention across project and asset lifecycle.

Artefacts an auditor will ask for
  • Naming policy
  • Validation tooling
  • Exception register
Where this commonly fails
  • Suffix codes inconsistent
  • No automated validation
GEN.2
Federation Strategy

Information models are federated according to defined strategy enabling coordination and clash detection.

Artefacts an auditor will ask for
  • Federation diagram
  • Clash reports
  • Coordination minutes
Where this commonly fails
  • Clash detection ad-hoc
  • Federation rules not documented

Part 1: Concepts and Principles

ISO-19650-1-4
Information management concepts

Defines the conceptual framework for information management throughout the asset lifecycle, including the information delivery cycle.

Artefacts an auditor will ask for
  • tender response documentation
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
  • asset information model
Where this commonly fails
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
  • gaps in mobilisation evidence
ISO-19650-1-5
Delivery team and task team concepts

Establishes team structures, roles, and responsibilities for managing information within project and asset management contexts.

Artefacts an auditor will ask for
  • common data environment configuration
  • asset information model
  • security triage register
Where this commonly fails
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
  • gaps in mobilisation evidence
ISO-19650-1-6
Information delivery planning

Provides guidance on delivery planning including Master Information Delivery Plans (MIDP) and Task Information Delivery Plans (TIDP).

Artefacts an auditor will ask for
  • asset information model
  • security triage register
  • tender response documentation
  • BIM execution plan
Where this commonly fails
  • insufficient security triage
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
ISO-19650-1-7
Common Data Environment (CDE) concept

Defines the CDE solution and workflows for managing collaborative production of information across project teams.

Artefacts an auditor will ask for
  • common data environment configuration
  • asset information model
  • security triage register
  • tender response documentation
  • BIM execution plan
  • information delivery plan
Where this commonly fails
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
  • gaps in mobilisation evidence
ISO-19650-1-8
Information model concepts (PIM and AIM)

Describes the Project Information Model (PIM) for the delivery phase and Asset Information Model (AIM) for the operational phase.

Artefacts an auditor will ask for
  • security triage register
  • tender response documentation
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
Where this commonly fails
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage

Part 2: Delivery Phase of Assets

ISO-19650-2-5.1
Assessment and need

Requires the appointing party to assess the need for information management and establish the approach and responsibilities.

Artefacts an auditor will ask for
  • common data environment configuration
  • asset information model
  • security triage register
  • tender response documentation
Where this commonly fails
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
ISO-19650-2-5.2
Invitation to tender

Requires compilation of exchange information requirements and establishment of project information requirements for tender.

Artefacts an auditor will ask for
  • tender response documentation
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
  • asset information model
Where this commonly fails
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
  • gaps in mobilisation evidence
  • unclear information requirements
ISO-19650-2-5.3
Tender response

Requires the lead appointed party to prepare a BIM Execution Plan (BEP) in response to project information requirements.

Artefacts an auditor will ask for
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
  • asset information model
Where this commonly fails
  • weak project information model handover
  • insufficient security triage
  • gaps in mobilisation evidence
ISO-19650-2-5.4
Appointment

Requires confirmation of the information delivery plan and finalization of the BEP upon appointment.

Artefacts an auditor will ask for
  • security triage register
  • tender response documentation
  • BIM execution plan
Where this commonly fails
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
ISO-19650-2-5.5
Mobilization

Requires the appointed party to mobilize resources, establish the CDE, and test information production methods.

Artefacts an auditor will ask for
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
Where this commonly fails
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
ISO-19650-2-5.6
Collaborative production of information

Requires teams to produce information in accordance with the agreed delivery plan using CDE workflows.

Artefacts an auditor will ask for
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
Where this commonly fails
  • insufficient security triage
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
ISO-19650-2-5.7
Information model delivery

Requires review and authorization of information model deliverables against project information requirements.

Artefacts an auditor will ask for
  • common data environment configuration
  • asset information model
  • security triage register
Where this commonly fails
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
  • gaps in mobilisation evidence
  • unclear information requirements
ISO-19650-2-5.8
Project close-out

Requires compilation of the as-built Project Information Model and handover to the appointing party.

Artefacts an auditor will ask for
  • security triage register
  • tender response documentation
  • BIM execution plan
Where this commonly fails
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover

Part 3: Operational Phase of Assets

ISO-19650-3-5.1
Assessment and need for operational information

Requires the asset owner to establish organizational information requirements and asset information requirements.

Artefacts an auditor will ask for
  • tender response documentation
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
  • asset information model
Where this commonly fails
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
  • insufficient security triage
  • gaps in mobilisation evidence
ISO-19650-3-5.2
Information model maintenance

Requires ongoing maintenance of the Asset Information Model throughout the asset's operational life.

Artefacts an auditor will ask for
  • tender response documentation
  • BIM execution plan
  • information delivery plan
Where this commonly fails
  • insufficient security triage
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
ISO-19650-3-5.3
Trigger events for information exchange

Defines events that trigger information updates, such as maintenance activities, renovations, and regulatory changes.

Artefacts an auditor will ask for
  • information delivery plan
  • common data environment configuration
  • asset information model
  • security triage register
  • tender response documentation
  • BIM execution plan
Where this commonly fails
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
ISO-19650-3-5.4
Transition from delivery to operational phase

Requires seamless transfer of BIM data and documentation from the delivery to operational phase.

Artefacts an auditor will ask for
  • security triage register
  • tender response documentation
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
Where this commonly fails
  • insufficient security triage
  • gaps in mobilisation evidence
  • unclear information requirements

Part 5: Security-Minded Approach to Information Management

ISO-19650-5-5
Establishing sensitivity of information

Requires assessment of the sensitivity of built asset information and classification of data accordingly.

Artefacts an auditor will ask for
  • security triage register
  • tender response documentation
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
  • asset information model
Where this commonly fails
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls
ISO-19650-5-6
Security triage process

Requires a structured triage process to determine appropriate security measures based on information sensitivity.

Artefacts an auditor will ask for
  • BIM execution plan
  • information delivery plan
  • common data environment configuration
  • asset information model
Where this commonly fails
  • unclear information requirements
  • missing CDE access controls
  • weak project information model handover
ISO-19650-5-7
Security management of information

Requires implementation of security controls for managing sensitive built asset information throughout its lifecycle.

Artefacts an auditor will ask for
  • information delivery plan
  • common data environment configuration
  • asset information model
  • security triage register
  • tender response documentation
Where this commonly fails
  • insufficient security triage
  • gaps in mobilisation evidence
  • unclear information requirements
ISO-19650-5-8
Security breach management

Requires procedures for identifying, responding to, and recovering from information security breaches.

Artefacts an auditor will ask for
  • common data environment configuration
  • asset information model
  • security triage register
  • tender response documentation
  • BIM execution plan
  • information delivery plan
Where this commonly fails
  • gaps in mobilisation evidence
  • unclear information requirements
  • missing CDE access controls

Project Delivery

P2.5.1
Assessment and Need

Appointing party assesses need for information and defines purpose for information delivery.

Artefacts an auditor will ask for
  • Needs analysis
  • Purpose document
  • Consultation log
Where this commonly fails
  • Information requested without purpose
  • No stakeholder input
P2.5.10
Project Close-out

Project close-out archives information model and transfers asset information to operational environment.

Artefacts an auditor will ask for
  • Archive index
  • AIM handover record
  • Lessons learned log
Where this commonly fails
  • AIM not validated before transfer
  • Archive missing context
P2.5.2
Information Requirements

Organisational, asset, project and exchange information requirements are established and communicated.

Artefacts an auditor will ask for
  • OIR document
  • AIR document
  • PIR document
  • EIR document
Where this commonly fails
  • EIR copied from template without tailoring
  • AIR missing for existing assets
P2.5.3
Information Standards and Methods

Information standard, production methods and procedures for project are established.

Artefacts an auditor will ask for
  • Project information standard
  • Method statements
  • Reference library link
Where this commonly fails
  • Standard not version-controlled
  • Methods not enforced
P2.5.4
Invitation to Tender

Invitation to tender includes EIR and information particulars sufficient for prospective lead appointed parties.

Artefacts an auditor will ask for
  • Tender documents
  • EIR appendix
  • Evaluation matrix
Where this commonly fails
  • EIR missing from tender
  • Criteria not weighted for BIM
P2.5.5
Tender Response

Prospective lead appointed party responds with BIM Execution Plan (BEP), capability and capacity evidence.

Artefacts an auditor will ask for
  • BEP document
  • Capability matrix
  • Capacity statement
Where this commonly fails
  • BEP unsigned
  • Capacity claims not evidenced
P2.5.6
Appointment

Appointment confirms information requirements, delivery responsibility matrix and BEP are agreed and signed.

Artefacts an auditor will ask for
  • Contract appendix
  • TIDP roll-up
  • Master Information Delivery Plan
Where this commonly fails
  • BEP versioned after signing without re-approval
  • TIDP gaps
P2.5.7
Mobilisation

Project delivery team mobilises resources, technology and information ahead of production.

Artefacts an auditor will ask for
  • Mobilisation plan
  • Tool deployment record
  • Project information model start state
Where this commonly fails
  • CDE not configured at mobilisation
  • Skills gap discovered late
P2.5.8
Collaborative Production of Information

Information is produced collaboratively in CDE following defined checks, reviews and approvals.

Artefacts an auditor will ask for
  • Workflow configuration
  • QA checklists
  • Approval audit trail
Where this commonly fails
  • Approvals bypassed under deadline pressure
  • No technical author check
P2.5.9
Information Model Delivery

Information model is delivered at defined exchange points and accepted by appointing party.

Artefacts an auditor will ask for
  • MIDP
  • Delivery notes
  • Acceptance signoffs
Where this commonly fails
  • Acceptance criteria not measurable
  • Delivery dates slip without re-baseline

Security

P5.5
Security-Minded Approach

Security-minded approach is applied to identify sensitivity and security needs for information.

Artefacts an auditor will ask for
  • Sensitivity assessment record
  • Built Asset Security Strategy
  • Built Asset Security Management Plan
Where this commonly fails
  • Sensitivity assessment done once and not updated
  • Strategy not approved by senior leadership
P5.7
Built Asset Security Information Requirements

Built asset security information requirements define what information is sensitive and how it is protected.

Artefacts an auditor will ask for
  • Sensitive data register
  • Control implementation evidence
  • Role-based access list
Where this commonly fails
  • Sensitive items mixed with general data in CDE
  • Access reviews not periodic
P5.8
Incident Management for Built Assets

Process for managing security incidents affecting built asset information is established.

Artefacts an auditor will ask for
  • Incident response plan
  • On-call roster
  • Post-incident reviews
Where this commonly fails
  • No tabletop exercise
  • Lessons not fed back into security plan
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) framework page.