Skip to content

Evidence request lists

ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Architecture

ISO22739-3.19
Layer Terminology

Apply standard terminology for layer 1, layer 2, sidechains, and rollup architectures.

Artefacts an auditor will ask for
  • Architecture document
  • Layer classification
  • Scaling rationale
  • Security inheritance analysis
Where this commonly fails
  • Layer terminology mixed
  • No scaling rationale
  • Security inheritance unclear

Asset Classes

ISO22739-3.18
Stablecoin and Pegged Asset Terms

Use ISO terminology for stablecoins, asset backed tokens, and algorithmic peg mechanisms.

Artefacts an auditor will ask for
  • Asset classification
  • Reserve attestation
  • Peg mechanism specification
  • Audit report
Where this commonly fails
  • Classification missing
  • No reserve attestation
  • Peg mechanism unclear

Auditability

ISO22739-3.16
Audit Trail Vocabulary

Apply ISO terminology when describing audit trail properties of shared ledger systems.

Artefacts an auditor will ask for
  • Audit trail specification
  • Log retention policy
  • Access records
  • Verification procedure
Where this commonly fails
  • Audit trail undefined
  • No retention policy
  • Missing verification procedure

Conformance

ISO22739-3.20
Vocabulary Conformance

Maintain conformance by ensuring all internal and external documentation uses ISO 22739 terminology consistently.

Artefacts an auditor will ask for
  • Conformance statement
  • Documentation review log
  • Glossary alignment audit
  • Training completion records
Where this commonly fails
  • No conformance statement
  • Documentation drift
  • Training not delivered

Consensus

ISO22739-3.4
Consensus Mechanism Definitions

Define consensus mechanism categories such as proof of work, proof of stake, and Byzantine fault tolerant variants using ISO terminology.

Artefacts an auditor will ask for
  • Consensus mechanism description
  • Algorithm parameters document
  • Fault tolerance analysis
  • Selection rationale
Where this commonly fails
  • Vague consensus description
  • No fault tolerance bounds
  • Missing parameter documentation

Core Concepts

ISO22739-3.1
Distributed Ledger Definition

Establish a definition of distributed ledger as a shared, replicated record system synchronized across multiple nodes without a central authority.

Artefacts an auditor will ask for
  • Internal glossary referencing ISO 22739 terms
  • Architecture diagrams labeled with standard terminology
  • Training materials
  • Vocabulary alignment matrix
Where this commonly fails
  • Ad hoc terminology across teams
  • Marketing language conflicting with standard definitions
  • No mapping to ISO 22739 in documentation

Custody

ISO22739-3.6
Wallet and Key Management Terms

Define wallet types, custodial vs non-custodial models, and key management terminology consistently with ISO 22739.

Artefacts an auditor will ask for
  • Wallet inventory
  • Custody model classification
  • Key management procedure
  • Hot vs cold storage diagram
Where this commonly fails
  • Custodial classification unclear
  • Mixed wallet definitions
  • No key lifecycle documentation

Data Structures

ISO22739-3.8
Block and Transaction Structure

Adopt standard terminology for blocks, transactions, hashes, and Merkle structures.

Artefacts an auditor will ask for
  • Data structure specification
  • Hash algorithm documentation
  • Merkle tree diagram
  • Block format reference
Where this commonly fails
  • No format specification
  • Hash algorithm undocumented
  • Missing structural diagrams

Economics

ISO22739-3.17
Token Economics Terms

Adopt ISO terminology for token issuance, supply, burning, and incentive mechanisms.

Artefacts an auditor will ask for
  • Token economics document
  • Issuance schedule
  • Burn policy
  • Incentive design rationale
Where this commonly fails
  • Tokenomics undocumented
  • No issuance schedule
  • Burn policy missing

External Data

ISO22739-3.11
Oracle Terminology

Define oracles as services providing external data to on ledger logic, including trust assumptions.

Artefacts an auditor will ask for
  • Oracle inventory
  • Trust assumption document
  • Data source attestations
  • Oracle SLA
Where this commonly fails
  • No oracle inventory
  • Trust assumptions undocumented
  • Missing source attestations

Governance

ISO22739-3.13
Governance Terminology

Use ISO terminology for on ledger and off ledger governance, including voting, proposals, and upgrade paths.

Artefacts an auditor will ask for
  • Governance charter
  • Proposal procedure
  • Voting records
  • Upgrade policy
Where this commonly fails
  • No governance charter
  • Voting undocumented
  • Upgrade path unclear

Identity

ISO22739-3.14
Identity and Self Sovereign Terms

Apply standardized terminology for decentralized identifiers, verifiable credentials, and self sovereign identity concepts.

Artefacts an auditor will ask for
  • Identity model document
  • DID specification
  • Credential schema
  • Issuer trust policy
Where this commonly fails
  • DID model unclear
  • No credential schema
  • Missing issuer policy

Interoperability

ISO22739-3.12
Interoperability and Bridge Terms

Adopt standard terminology for cross ledger interoperability, bridges, and atomic swap mechanisms.

Artefacts an auditor will ask for
  • Bridge specification
  • Cross ledger transaction log
  • Atomic swap procedure
  • Interoperability test results
Where this commonly fails
  • Bridge terminology inconsistent
  • No test results
  • Missing specification

Network Roles

ISO22739-3.2
Shared Ledger Node Terminology

Adopt standardized terminology for nodes, validators, and participants in a shared ledger network.

Artefacts an auditor will ask for
  • Node role definitions
  • Validator participation policy
  • Network topology diagram
  • Participant onboarding documentation
Where this commonly fails
  • Inconsistent role names
  • Validator vs node confusion
  • Missing participant registry

Network Types

ISO22739-3.7
Permissioned vs Permissionless Networks

Distinguish permissioned and permissionless network configurations using ISO defined terminology.

Artefacts an auditor will ask for
  • Network classification statement
  • Access control policy
  • Permissioning documentation
  • Network type rationale
Where this commonly fails
  • Network type not declared
  • Mixed permissioning
  • No rationale documented

Privacy

ISO22739-3.15
Privacy Preserving Technique Terms

Use ISO terminology for zero knowledge proofs, ring signatures, mixers, and confidential transaction techniques.

Artefacts an auditor will ask for
  • Privacy technique inventory
  • Cryptographic protocol specification
  • Privacy impact assessment
  • Implementation review
Where this commonly fails
  • Privacy techniques undocumented
  • No protocol specification
  • Missing assessment

Programmable Logic

ISO22739-3.5
Smart Contract Terminology

Use standardized terminology for executable code stored on a shared ledger, distinguishing smart contracts from legal contracts.

Artefacts an auditor will ask for
  • Smart contract inventory
  • Code repository
  • Legal vs technical distinction policy
  • Deployment records
Where this commonly fails
  • Smart contract conflated with legal contract
  • No inventory
  • Missing deployment audit trail

Properties

ISO22739-3.10
Finality Definition

Use ISO defined terms for probabilistic, deterministic, and economic finality of recorded transactions.

Artefacts an auditor will ask for
  • Finality classification
  • Settlement assurance policy
  • Probabilistic depth thresholds
  • Economic finality analysis
Where this commonly fails
  • Finality type not specified
  • No depth thresholds
  • Missing settlement definition
ISO22739-3.9
Immutability Terminology

Define immutability as practical resistance to alteration rather than absolute, with reference to threat models.

Artefacts an auditor will ask for
  • Immutability statement
  • Threat model document
  • Reorganization risk analysis
  • Finality policy
Where this commonly fails
  • Absolute immutability claimed
  • No threat model
  • Missing finality definition

Section 3.1: Distributed Ledger Technology Fundamentals

ISO-22739-3.1.1
Distributed ledger

Defines a distributed ledger as a ledger that is shared across a set of DLT nodes and synchronized between the DLT nodes using a consensus mechanism.

Artefacts an auditor will ask for
  • asset taxonomy
  • interoperability assessment
  • terminology glossary
Where this commonly fails
  • gaps in asset classification
  • inconsistent terminology use
  • unclear governance roles
  • weak node accountability
ISO-22739-3.1.2
Distributed ledger technology (DLT)

Defines technology that enables the operation and use of distributed ledgers.

Artefacts an auditor will ask for
  • system architecture document
  • governance framework
  • node configuration baseline
Where this commonly fails
  • weak node accountability
  • missing interoperability specification
  • gaps in asset classification
ISO-22739-3.1.3
DLT node

Defines a device or process that participates in a distributed ledger technology network and may hold a complete or partial replica of the ledger.

Artefacts an auditor will ask for
  • governance framework
  • node configuration baseline
  • asset taxonomy
Where this commonly fails
  • inconsistent terminology use
  • unclear governance roles
  • weak node accountability
ISO-22739-3.1.4
Consensus mechanism

Defines the rules and procedures by which consensus is reached among DLT nodes to validate transactions.

Artefacts an auditor will ask for
  • asset taxonomy
  • interoperability assessment
  • terminology glossary
  • system architecture document
Where this commonly fails
  • missing interoperability specification
  • gaps in asset classification
  • inconsistent terminology use
  • unclear governance roles
  • weak node accountability
ISO-22739-3.1.5
Transaction

Defines the smallest unit of a work process in a distributed ledger that is relevant to a specific DLT system.

Artefacts an auditor will ask for
  • interoperability assessment
  • terminology glossary
  • system architecture document
  • governance framework
  • node configuration baseline
  • asset taxonomy
Where this commonly fails
  • unclear governance roles
  • weak node accountability
  • missing interoperability specification
  • gaps in asset classification

Section 3.2: Blockchain Concepts

ISO-22739-3.2.1
Blockchain

Defines blockchain as a distributed ledger with confirmed transactions organized in append-only, sequentially linked blocks.

Artefacts an auditor will ask for
  • governance framework
  • node configuration baseline
  • asset taxonomy
Where this commonly fails
  • missing interoperability specification
  • gaps in asset classification
  • inconsistent terminology use
ISO-22739-3.2.2
Block

Defines a block as a data structure containing a set of confirmed transactions and a reference to the previous block in the chain.

Artefacts an auditor will ask for
  • node configuration baseline
  • asset taxonomy
  • interoperability assessment
  • terminology glossary
  • system architecture document
  • governance framework
Where this commonly fails
  • missing interoperability specification
  • gaps in asset classification
  • inconsistent terminology use
ISO-22739-3.2.3
Genesis block

Defines the initial block in a blockchain that has no reference to a previous block.

Artefacts an auditor will ask for
  • interoperability assessment
  • terminology glossary
  • system architecture document
  • governance framework
  • node configuration baseline
  • asset taxonomy
Where this commonly fails
  • inconsistent terminology use
  • unclear governance roles
  • weak node accountability
  • missing interoperability specification
ISO-22739-3.2.4
Hash function

Defines the cryptographic function used to create fixed-length output from variable-length input for block identification.

Artefacts an auditor will ask for
  • system architecture document
  • governance framework
  • node configuration baseline
Where this commonly fails
  • missing interoperability specification
  • gaps in asset classification
  • inconsistent terminology use
  • unclear governance roles
ISO-22739-3.2.5
Smart contract

Defines a computer program stored in a DLT system wherein the outcome of any execution of the program is recorded on the distributed ledger.

Artefacts an auditor will ask for
  • terminology glossary
  • system architecture document
  • governance framework
  • node configuration baseline
Where this commonly fails
  • gaps in asset classification
  • inconsistent terminology use
  • unclear governance roles

Section 3.3: DLT System Types and Governance

ISO-22739-3.3.1
Permissioned DLT system

Defines a DLT system where participation requires authorization from one or more designated parties.

Artefacts an auditor will ask for
  • terminology glossary
  • system architecture document
  • governance framework
Where this commonly fails
  • gaps in asset classification
  • inconsistent terminology use
  • unclear governance roles
ISO-22739-3.3.2
Permissionless DLT system

Defines a DLT system where any party can participate without requiring authorization.

Artefacts an auditor will ask for
  • governance framework
  • node configuration baseline
  • asset taxonomy
  • interoperability assessment
Where this commonly fails
  • weak node accountability
  • missing interoperability specification
  • gaps in asset classification
ISO-22739-3.3.3
Public DLT system

Defines a DLT system where the records are accessible to any party.

Artefacts an auditor will ask for
  • terminology glossary
  • system architecture document
  • governance framework
  • node configuration baseline
  • asset taxonomy
  • interoperability assessment
Where this commonly fails
  • unclear governance roles
  • weak node accountability
  • missing interoperability specification
ISO-22739-3.3.4
Private DLT system

Defines a DLT system where record access is restricted to a specified set of DLT nodes.

Artefacts an auditor will ask for
  • asset taxonomy
  • interoperability assessment
  • terminology glossary
  • system architecture document
Where this commonly fails
  • weak node accountability
  • missing interoperability specification
  • gaps in asset classification
ISO-22739-3.3.5
DLT governance

Defines the framework for establishing accountability, authority, and decision-making within a DLT system.

Artefacts an auditor will ask for
  • terminology glossary
  • system architecture document
  • governance framework
  • node configuration baseline
  • asset taxonomy
Where this commonly fails
  • gaps in asset classification
  • inconsistent terminology use
  • unclear governance roles
  • weak node accountability

Section 3.4: Tokens and Digital Assets

ISO-22739-3.4.1
Token

Defines a digital asset that represents a collection of entitlements recorded on a distributed ledger.

Artefacts an auditor will ask for
  • governance framework
  • node configuration baseline
  • asset taxonomy
Where this commonly fails
  • inconsistent terminology use
  • unclear governance roles
  • weak node accountability
ISO-22739-3.4.2
Tokenization

Defines the process of creating a digital representation of an asset or entitlement on a distributed ledger.

Artefacts an auditor will ask for
  • node configuration baseline
  • asset taxonomy
  • interoperability assessment
  • terminology glossary
  • system architecture document
  • governance framework
Where this commonly fails
  • unclear governance roles
  • weak node accountability
  • missing interoperability specification
  • gaps in asset classification
ISO-22739-3.4.3
Digital asset

Defines an asset that exists only in digital form or is a digital representation of another asset.

Artefacts an auditor will ask for
  • asset taxonomy
  • interoperability assessment
  • terminology glossary
Where this commonly fails
  • unclear governance roles
  • weak node accountability
  • missing interoperability specification
  • gaps in asset classification
ISO-22739-3.4.4
Interoperability

Defines the ability of different DLT systems to exchange and make use of information across system boundaries.

Artefacts an auditor will ask for
  • node configuration baseline
  • asset taxonomy
  • interoperability assessment
Where this commonly fails
  • gaps in asset classification
  • inconsistent terminology use
  • unclear governance roles
  • weak node accountability
  • missing interoperability specification

Tokens

ISO22739-3.3
Tokenized Record Terminology

Apply consistent terminology for tokenized records, fungible and non-fungible representations, and token lifecycle states.

Artefacts an auditor will ask for
  • Token taxonomy document
  • Lifecycle state diagram
  • Fungibility classification
  • Token specification sheet
Where this commonly fails
  • Conflating coin and token
  • No lifecycle definition
  • Missing fungibility classification
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.