ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Architecture
Apply standard terminology for layer 1, layer 2, sidechains, and rollup architectures.
- Architecture document
- Layer classification
- Scaling rationale
- Security inheritance analysis
- Layer terminology mixed
- No scaling rationale
- Security inheritance unclear
Asset Classes
Use ISO terminology for stablecoins, asset backed tokens, and algorithmic peg mechanisms.
- Asset classification
- Reserve attestation
- Peg mechanism specification
- Audit report
- Classification missing
- No reserve attestation
- Peg mechanism unclear
Auditability
Apply ISO terminology when describing audit trail properties of shared ledger systems.
- Audit trail specification
- Log retention policy
- Access records
- Verification procedure
- Audit trail undefined
- No retention policy
- Missing verification procedure
Conformance
Maintain conformance by ensuring all internal and external documentation uses ISO 22739 terminology consistently.
- Conformance statement
- Documentation review log
- Glossary alignment audit
- Training completion records
- No conformance statement
- Documentation drift
- Training not delivered
Consensus
Define consensus mechanism categories such as proof of work, proof of stake, and Byzantine fault tolerant variants using ISO terminology.
- Consensus mechanism description
- Algorithm parameters document
- Fault tolerance analysis
- Selection rationale
- Vague consensus description
- No fault tolerance bounds
- Missing parameter documentation
Core Concepts
Establish a definition of distributed ledger as a shared, replicated record system synchronized across multiple nodes without a central authority.
- Internal glossary referencing ISO 22739 terms
- Architecture diagrams labeled with standard terminology
- Training materials
- Vocabulary alignment matrix
- Ad hoc terminology across teams
- Marketing language conflicting with standard definitions
- No mapping to ISO 22739 in documentation
Custody
Define wallet types, custodial vs non-custodial models, and key management terminology consistently with ISO 22739.
- Wallet inventory
- Custody model classification
- Key management procedure
- Hot vs cold storage diagram
- Custodial classification unclear
- Mixed wallet definitions
- No key lifecycle documentation
Data Structures
Adopt standard terminology for blocks, transactions, hashes, and Merkle structures.
- Data structure specification
- Hash algorithm documentation
- Merkle tree diagram
- Block format reference
- No format specification
- Hash algorithm undocumented
- Missing structural diagrams
Economics
Adopt ISO terminology for token issuance, supply, burning, and incentive mechanisms.
- Token economics document
- Issuance schedule
- Burn policy
- Incentive design rationale
- Tokenomics undocumented
- No issuance schedule
- Burn policy missing
External Data
Define oracles as services providing external data to on ledger logic, including trust assumptions.
- Oracle inventory
- Trust assumption document
- Data source attestations
- Oracle SLA
- No oracle inventory
- Trust assumptions undocumented
- Missing source attestations
Governance
Use ISO terminology for on ledger and off ledger governance, including voting, proposals, and upgrade paths.
- Governance charter
- Proposal procedure
- Voting records
- Upgrade policy
- No governance charter
- Voting undocumented
- Upgrade path unclear
Identity
Apply standardized terminology for decentralized identifiers, verifiable credentials, and self sovereign identity concepts.
- Identity model document
- DID specification
- Credential schema
- Issuer trust policy
- DID model unclear
- No credential schema
- Missing issuer policy
Interoperability
Adopt standard terminology for cross ledger interoperability, bridges, and atomic swap mechanisms.
- Bridge specification
- Cross ledger transaction log
- Atomic swap procedure
- Interoperability test results
- Bridge terminology inconsistent
- No test results
- Missing specification
Network Roles
Adopt standardized terminology for nodes, validators, and participants in a shared ledger network.
- Node role definitions
- Validator participation policy
- Network topology diagram
- Participant onboarding documentation
- Inconsistent role names
- Validator vs node confusion
- Missing participant registry
Network Types
Distinguish permissioned and permissionless network configurations using ISO defined terminology.
- Network classification statement
- Access control policy
- Permissioning documentation
- Network type rationale
- Network type not declared
- Mixed permissioning
- No rationale documented
Privacy
Use ISO terminology for zero knowledge proofs, ring signatures, mixers, and confidential transaction techniques.
- Privacy technique inventory
- Cryptographic protocol specification
- Privacy impact assessment
- Implementation review
- Privacy techniques undocumented
- No protocol specification
- Missing assessment
Programmable Logic
Use standardized terminology for executable code stored on a shared ledger, distinguishing smart contracts from legal contracts.
- Smart contract inventory
- Code repository
- Legal vs technical distinction policy
- Deployment records
- Smart contract conflated with legal contract
- No inventory
- Missing deployment audit trail
Properties
Use ISO defined terms for probabilistic, deterministic, and economic finality of recorded transactions.
- Finality classification
- Settlement assurance policy
- Probabilistic depth thresholds
- Economic finality analysis
- Finality type not specified
- No depth thresholds
- Missing settlement definition
Define immutability as practical resistance to alteration rather than absolute, with reference to threat models.
- Immutability statement
- Threat model document
- Reorganization risk analysis
- Finality policy
- Absolute immutability claimed
- No threat model
- Missing finality definition
Section 3.1: Distributed Ledger Technology Fundamentals
Defines a distributed ledger as a ledger that is shared across a set of DLT nodes and synchronized between the DLT nodes using a consensus mechanism.
- asset taxonomy
- interoperability assessment
- terminology glossary
- gaps in asset classification
- inconsistent terminology use
- unclear governance roles
- weak node accountability
Defines technology that enables the operation and use of distributed ledgers.
- system architecture document
- governance framework
- node configuration baseline
- weak node accountability
- missing interoperability specification
- gaps in asset classification
Defines a device or process that participates in a distributed ledger technology network and may hold a complete or partial replica of the ledger.
- governance framework
- node configuration baseline
- asset taxonomy
- inconsistent terminology use
- unclear governance roles
- weak node accountability
Defines the rules and procedures by which consensus is reached among DLT nodes to validate transactions.
- asset taxonomy
- interoperability assessment
- terminology glossary
- system architecture document
- missing interoperability specification
- gaps in asset classification
- inconsistent terminology use
- unclear governance roles
- weak node accountability
Defines the smallest unit of a work process in a distributed ledger that is relevant to a specific DLT system.
- interoperability assessment
- terminology glossary
- system architecture document
- governance framework
- node configuration baseline
- asset taxonomy
- unclear governance roles
- weak node accountability
- missing interoperability specification
- gaps in asset classification
Section 3.2: Blockchain Concepts
Defines blockchain as a distributed ledger with confirmed transactions organized in append-only, sequentially linked blocks.
- governance framework
- node configuration baseline
- asset taxonomy
- missing interoperability specification
- gaps in asset classification
- inconsistent terminology use
Defines a block as a data structure containing a set of confirmed transactions and a reference to the previous block in the chain.
- node configuration baseline
- asset taxonomy
- interoperability assessment
- terminology glossary
- system architecture document
- governance framework
- missing interoperability specification
- gaps in asset classification
- inconsistent terminology use
Defines the initial block in a blockchain that has no reference to a previous block.
- interoperability assessment
- terminology glossary
- system architecture document
- governance framework
- node configuration baseline
- asset taxonomy
- inconsistent terminology use
- unclear governance roles
- weak node accountability
- missing interoperability specification
Defines the cryptographic function used to create fixed-length output from variable-length input for block identification.
- system architecture document
- governance framework
- node configuration baseline
- missing interoperability specification
- gaps in asset classification
- inconsistent terminology use
- unclear governance roles
Defines a computer program stored in a DLT system wherein the outcome of any execution of the program is recorded on the distributed ledger.
- terminology glossary
- system architecture document
- governance framework
- node configuration baseline
- gaps in asset classification
- inconsistent terminology use
- unclear governance roles
Section 3.3: DLT System Types and Governance
Defines a DLT system where participation requires authorization from one or more designated parties.
- terminology glossary
- system architecture document
- governance framework
- gaps in asset classification
- inconsistent terminology use
- unclear governance roles
Defines a DLT system where any party can participate without requiring authorization.
- governance framework
- node configuration baseline
- asset taxonomy
- interoperability assessment
- weak node accountability
- missing interoperability specification
- gaps in asset classification
Defines a DLT system where the records are accessible to any party.
- terminology glossary
- system architecture document
- governance framework
- node configuration baseline
- asset taxonomy
- interoperability assessment
- unclear governance roles
- weak node accountability
- missing interoperability specification
Defines a DLT system where record access is restricted to a specified set of DLT nodes.
- asset taxonomy
- interoperability assessment
- terminology glossary
- system architecture document
- weak node accountability
- missing interoperability specification
- gaps in asset classification
Defines the framework for establishing accountability, authority, and decision-making within a DLT system.
- terminology glossary
- system architecture document
- governance framework
- node configuration baseline
- asset taxonomy
- gaps in asset classification
- inconsistent terminology use
- unclear governance roles
- weak node accountability
Section 3.4: Tokens and Digital Assets
Defines a digital asset that represents a collection of entitlements recorded on a distributed ledger.
- governance framework
- node configuration baseline
- asset taxonomy
- inconsistent terminology use
- unclear governance roles
- weak node accountability
Defines the process of creating a digital representation of an asset or entitlement on a distributed ledger.
- node configuration baseline
- asset taxonomy
- interoperability assessment
- terminology glossary
- system architecture document
- governance framework
- unclear governance roles
- weak node accountability
- missing interoperability specification
- gaps in asset classification
Defines an asset that exists only in digital form or is a digital representation of another asset.
- asset taxonomy
- interoperability assessment
- terminology glossary
- unclear governance roles
- weak node accountability
- missing interoperability specification
- gaps in asset classification
Defines the ability of different DLT systems to exchange and make use of information across system boundaries.
- node configuration baseline
- asset taxonomy
- interoperability assessment
- gaps in asset classification
- inconsistent terminology use
- unclear governance roles
- weak node accountability
- missing interoperability specification
Tokens
Apply consistent terminology for tokenized records, fungible and non-fungible representations, and token lifecycle states.
- Token taxonomy document
- Lifecycle state diagram
- Fungibility classification
- Token specification sheet
- Conflating coin and token
- No lifecycle definition
- Missing fungibility classification
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.