Skip to content

Evidence request lists

ISO 27018

Evidence request list. 45 controls, 45 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Data Lifecycle

A.12.2
Return, transfer and disposal of PII

On termination the processor shall return or securely dispose of PII as instructed by the customer.

Artefacts an auditor will ask for
  • Exit clause
  • Deletion certificates
  • Backup purge evidence
  • Return logs
Where this commonly fails
  • Backups retain PII
  • No deletion certificate
  • Return method unclear

ISO 27018: Cloud Governance

ISO27018-01
Shared responsibility model definition

Shared responsibility model definition. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27018-02
Cloud security policy and strategy

Cloud security policy and strategy. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27018-03
Cloud risk assessment

Cloud risk assessment. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27018-04
Regulatory compliance for cloud services

Regulatory compliance for cloud services. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale
ISO27018-05
Cloud security roles and responsibilities

Cloud security roles and responsibilities. Control from ISO 27018 framework, domain: ISO 27018: Cloud Governance.

Artefacts an auditor will ask for
  • Shared responsibility matrix
  • Cloud security policy
  • Cloud risk register
  • Regulatory mapping
Where this commonly fails
  • Shared responsibility unclear per service
  • Cloud risks not in enterprise register
  • Regulatory mapping stale

ISO 27018: Cloud Infrastructure Security

ISO27018-16
Virtual network segmentation

Virtual network segmentation. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27018-17
Container and serverless security

Container and serverless security. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27018-18
Cloud workload protection

Cloud workload protection. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27018-19
Image and template hardening

Image and template hardening. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved
ISO27018-20
Cloud configuration management

Cloud configuration management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Infrastructure Security.

Artefacts an auditor will ask for
  • VPC design diagram
  • Container security baseline
  • Hardened image catalogue
  • CSPM report
Where this commonly fails
  • Default VPC still in use
  • Containers run as root
  • CSPM misconfigurations unresolved

ISO 27018: Cloud Operations & Monitoring

ISO27018-21
Cloud security monitoring and logging

Cloud security monitoring and logging. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27018-22
Incident response in cloud

Incident response in cloud. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27018-23
Cloud vulnerability management

Cloud vulnerability management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27018-24
Cloud change management

Cloud change management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured
ISO27018-25
Service level agreement management

Service level agreement management. Control from ISO 27018 framework, domain: ISO 27018: Cloud Operations & Monitoring.

Artefacts an auditor will ask for
  • Cloud SIEM configuration
  • Incident response runbook
  • Vulnerability scan output
  • SLA performance report
Where this commonly fails
  • Cloud logs not centralized
  • Incident playbooks not cloud-specific
  • SLAs not measured

ISO 27018: Data Protection in Cloud

ISO27018-11
Data classification for cloud

Data classification for cloud. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27018-12
Encryption of cloud-stored data

Encryption of cloud-stored data. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27018-13
Data residency and sovereignty

Data residency and sovereignty. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27018-14
Data backup and recovery in cloud

Data backup and recovery in cloud. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing
ISO27018-15
Secure data deletion in cloud

Secure data deletion in cloud. Control from ISO 27018 framework, domain: ISO 27018: Data Protection in Cloud.

Artefacts an auditor will ask for
  • Data classification policy
  • Encryption configuration baseline
  • Residency map
  • Secure deletion attestation
Where this commonly fails
  • Encryption not enforced on all storage classes
  • Residency assumptions undocumented
  • Deletion attestations missing

ISO 27018: Identity & Access in Cloud

ISO27018-06
Cloud identity management

Cloud identity management. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27018-07
Multi-factor authentication for cloud

Multi-factor authentication for cloud. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27018-08
Privileged access in cloud environments

Privileged access in cloud environments. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27018-09
Federation and single sign-on

Federation and single sign-on. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time
ISO27018-10
API security and access tokens

API security and access tokens. Control from ISO 27018 framework, domain: ISO 27018: Identity & Access in Cloud.

Artefacts an auditor will ask for
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory
Where this commonly fails
  • MFA bypass on legacy auth
  • Long-lived tokens
  • Privileged roles not just-in-time

Incident

A.12.1
Notification of a data breach

The processor shall promptly notify the customer of any incident leading to loss, disclosure or alteration of PII.

Artefacts an auditor will ask for
  • Breach notification SLA
  • Notification templates
  • Incident records
  • Customer communications log
Where this commonly fails
  • No SLA
  • Notification informal
  • Customer comms missing

PII Principles

A.1.1
Consent and choice

Public cloud PII processor shall process PII only as instructed by the cloud service customer who is the PII controller or by the PII principal.

Artefacts an auditor will ask for
  • Customer agreement clauses
  • Processing instructions log
  • Use restriction policy
  • Audit trail
Where this commonly fails
  • Vague processing instructions
  • Marketing use of PII
  • No audit trail
A.2.1
Purpose legitimacy and specification

PII shall be processed only for the purposes specified by the customer and not used for the processor's own purposes.

Artefacts an auditor will ask for
  • Purpose register
  • Use case approvals
  • Internal use prohibition policy
  • Marketing opt-in records
Where this commonly fails
  • Telemetry uses PII
  • No purpose register
  • Marketing reuse without consent
A.3.1
Collection limitation

The processor shall not collect PII beyond what is required for the agreed purpose.

Artefacts an auditor will ask for
  • Data minimization review
  • Field-level necessity analysis
  • Schema documentation
  • Change control records
Where this commonly fails
  • No minimization review
  • Over-collection by default
  • Schema drift
A.4.1
Data minimization

Temporary files and copies of PII shall be erased or destroyed in a defined period.

Artefacts an auditor will ask for
  • Retention schedule
  • Temporary file purge job logs
  • Cache policy
  • Deletion certificates
Where this commonly fails
  • Cache retains PII
  • No purge jobs
  • Backups out of scope
A.5.1
Use, retention and disclosure limitation

PII shall not be retained beyond the timeframe required to fulfil the agreed purpose unless required by law.

Artefacts an auditor will ask for
  • Retention policy
  • Deletion logs
  • Legal hold register
  • Customer-driven deletion workflow
Where this commonly fails
  • No customer-driven deletion
  • Indefinite logs
  • Legal holds without review
A.6.1
Accuracy and quality

PII processed shall be accurate and up to date to the extent necessary for the purpose.

Artefacts an auditor will ask for
  • Data quality controls
  • Correction workflow
  • Customer correction requests log
  • Validation rules
Where this commonly fails
  • No correction workflow
  • Customer can't correct via portal
  • Validation absent
A.7.1
Openness, transparency and notice

The processor shall provide the customer with information about the processing of PII including subcontractors and locations.

Artefacts an auditor will ask for
  • Subprocessor list
  • Data location disclosure
  • Trust page
  • Notification process for changes
Where this commonly fails
  • Subprocessor list stale
  • No location disclosure
  • No change notification
A.8.1
Individual participation and access

The processor shall provide means for the customer to fulfil PII principal rights including access, correction and deletion.

Artefacts an auditor will ask for
  • DSAR support runbook
  • Customer APIs for rights
  • Response time SLA
  • Closure records
Where this commonly fails
  • No DSAR API
  • Manual fulfilment slow
  • No SLA tracking
A.9.1
Accountability

The processor shall assign roles to manage PII protection and demonstrate compliance.

Artefacts an auditor will ask for
  • Privacy officer appointment
  • Privacy program charter
  • Compliance reports
  • Audit evidence
Where this commonly fails
  • No privacy officer
  • Program informal
  • No external audit

Privacy by Design

A.11.1
Geographical location of PII

Customer shall be informed of countries in which PII is or may be stored or processed.

Artefacts an auditor will ask for
  • Data location disclosure
  • Region pinning configs
  • Subprocessor list
  • Audit reports
Where this commonly fails
  • Region drift
  • No customer disclosure
  • Subprocessor regions hidden
A.11.2
Intended destination of PII

PII shall be transmitted only to destinations agreed with the customer.

Artefacts an auditor will ask for
  • Data flow diagrams
  • Egress controls
  • Approved destination list
  • Network policy
Where this commonly fails
  • No data flow diagrams
  • Unapproved destinations
  • Egress wide open

Security

A.10.1
Information security

PII shall be protected with appropriate technical and organizational measures consistent with risk.

Artefacts an auditor will ask for
  • Risk assessment
  • Control implementation evidence
  • Pen test reports
  • Encryption standards
Where this commonly fails
  • Risk assessment dated
  • Encryption gaps
  • No regular pen tests
A.10.2
Confidentiality obligations of personnel

Personnel processing PII shall be under confidentiality obligations recorded in writing.

Artefacts an auditor will ask for
  • Signed confidentiality agreements
  • Contractor agreements
  • Training records
  • Exit confirmation
Where this commonly fails
  • Contractors missing
  • No exit confirmation
  • Training not specific to PII
A.10.3
Restriction of creation of hardcopy material

Creation of hardcopy materials containing PII shall be restricted and controlled.

Artefacts an auditor will ask for
  • Print policy
  • Pull-print logs
  • Hardcopy register
  • Destruction records
Where this commonly fails
  • No print policy
  • Hardcopy not registered
  • Destruction unverified
A.10.4
Control and logging of data restoration

Restoration of PII from backups shall be controlled and logged.

Artefacts an auditor will ask for
  • Restoration runbook
  • Approval log
  • Restore test records
  • Audit trail
Where this commonly fails
  • No approval workflow
  • Restores not logged
  • Test restores skipped
A.10.5
Protection of data on storage media leaving premises

PII on media leaving premises shall be subject to authorization and protective measures including encryption.

Artefacts an auditor will ask for
  • Removable media policy
  • Encryption enforcement
  • Movement log
  • Authorization records
Where this commonly fails
  • Unencrypted USB allowed
  • No movement log
  • Authorization informal
A.10.6
PII transmission

PII transmitted over networks shall be encrypted and integrity-protected.

Artefacts an auditor will ask for
  • TLS configuration
  • Cipher inventory
  • API gateway settings
  • Network test reports
Where this commonly fails
  • Weak ciphers enabled
  • Internal traffic unencrypted
  • No integrity controls
A.10.7
Disclosure of PII

Disclosures of PII to third parties including law enforcement shall be logged and where lawful notified to the customer.

Artefacts an auditor will ask for
  • Disclosure register
  • Customer notification policy
  • Legal review records
  • Transparency reports
Where this commonly fails
  • No customer notification
  • Register absent
  • Legal review skipped
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 27018 framework page.