Skip to content

Evidence request lists

ISO/IEC 27018:2019

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

PII Processor

A.1.1
Consent and choice

Public cloud PII processor shall process PII only as instructed by the cloud service customer who is the PII controller or by the PII principal.

Artefacts an auditor will ask for
  • Customer agreement clauses
  • Processing instructions log
  • Use restriction policy
  • Audit trail
Where this commonly fails
  • Vague processing instructions
  • Marketing use of PII
  • No audit trail
A.10.1
Information security

PII shall be protected with appropriate technical and organizational measures consistent with risk.

Artefacts an auditor will ask for
  • Risk assessment
  • Control implementation evidence
  • Pen test reports
  • Encryption standards
Where this commonly fails
  • Risk assessment dated
  • Encryption gaps
  • No regular pen tests
A.10.10
User ID management

De-activated or expired user IDs shall not be granted to other individuals.

Artefacts an auditor will ask for
  • IAM provisioning standard
  • User ID uniqueness control
  • Audit log of ID reuse attempts
Where this commonly fails
  • IDs recycled in legacy systems
  • No prevention control
  • Manual provisioning errors
A.10.11
Contract measures

Contracts between the public cloud PII processor and its customers shall specify the allocation of responsibilities for the protection of PII.

Artefacts an auditor will ask for
  • Shared responsibility model documentation
  • Customer-facing responsibility matrix
  • DPA addendum
  • Onboarding materials
Where this commonly fails
  • Ambiguous responsibility allocation
  • No customer-facing matrix
  • Conflicting clauses across documents
A.10.12
Sub-contracted PII processing

Contracts between the public cloud PII processor and any subcontractors involved in PII processing shall specify equivalent measures for protection of PII.

Artefacts an auditor will ask for
  • Subprocessor DPAs
  • Flow-down clause register
  • Subprocessor security assessment reports
  • Annual subprocessor review
Where this commonly fails
  • Subprocessor with weaker controls
  • No reassessment after material change
  • Flow-down missing key clauses
A.10.13
Access to data on pre-used data-storage space

The cloud PII processor shall ensure that whenever data storage space is assigned to a customer, any previous PII residing on that storage space is not accessible.

Artefacts an auditor will ask for
  • Storage sanitization procedure
  • Crypto-erasure standard
  • Multi-tenant isolation design
  • Hypervisor and storage zeroization controls
Where this commonly fails
  • Residual data on reused volumes
  • No zeroization on storage release
  • Snapshots not purged
A.10.2
Confidentiality obligations of personnel

Personnel processing PII shall be under confidentiality obligations recorded in writing.

Artefacts an auditor will ask for
  • Signed confidentiality agreements
  • Contractor agreements
  • Training records
  • Exit confirmation
Where this commonly fails
  • Contractors missing
  • No exit confirmation
  • Training not specific to PII
A.10.3
Restriction of creation of hardcopy material

Creation of hardcopy materials containing PII shall be restricted and controlled.

Artefacts an auditor will ask for
  • Print policy
  • Pull-print logs
  • Hardcopy register
  • Destruction records
Where this commonly fails
  • No print policy
  • Hardcopy not registered
  • Destruction unverified
A.10.4
Control and logging of data restoration

Restoration of PII from backups shall be controlled and logged.

Artefacts an auditor will ask for
  • Restoration runbook
  • Approval log
  • Restore test records
  • Audit trail
Where this commonly fails
  • No approval workflow
  • Restores not logged
  • Test restores skipped
A.10.5
Protection of data on storage media leaving premises

PII on media leaving premises shall be subject to authorization and protective measures including encryption.

Artefacts an auditor will ask for
  • Removable media policy
  • Encryption enforcement
  • Movement log
  • Authorization records
Where this commonly fails
  • Unencrypted USB allowed
  • No movement log
  • Authorization informal
A.10.6
PII transmission

PII transmitted over networks shall be encrypted and integrity-protected.

Artefacts an auditor will ask for
  • TLS configuration
  • Cipher inventory
  • API gateway settings
  • Network test reports
Where this commonly fails
  • Weak ciphers enabled
  • Internal traffic unencrypted
  • No integrity controls
A.10.7
Disclosure of PII

Disclosures of PII to third parties including law enforcement shall be logged and where lawful notified to the customer.

Artefacts an auditor will ask for
  • Disclosure register
  • Customer notification policy
  • Legal review records
  • Transparency reports
Where this commonly fails
  • No customer notification
  • Register absent
  • Legal review skipped
A.10.8
Unique use of user IDs

If more than one individual has access to stored PII, then they shall each have a distinct user ID for identification, authentication, and authorization.

Artefacts an auditor will ask for
  • IAM standard prohibiting shared accounts
  • User account inventory
  • Shared account exception register
  • Privileged access logs
Where this commonly fails
  • Shared admin accounts
  • Service accounts used interactively
  • No audit trail per user
A.10.9
Records of authorized users

An up-to-date record of users or profiles of users who have authorized access to information systems handling PII shall be maintained.

Artefacts an auditor will ask for
  • User access register
  • Role-to-access mapping
  • Quarterly access review records
  • Joiner/mover/leaver workflow logs
Where this commonly fails
  • Stale access for departed users
  • No ownership of role definitions
  • Access reviews missed
A.11.1
Geographical location of PII

Customer shall be informed of countries in which PII is or may be stored or processed.

Artefacts an auditor will ask for
  • Data location disclosure
  • Region pinning configs
  • Subprocessor list
  • Audit reports
Where this commonly fails
  • Region drift
  • No customer disclosure
  • Subprocessor regions hidden
A.11.2
Intended destination of PII

PII shall be transmitted only to destinations agreed with the customer.

Artefacts an auditor will ask for
  • Data flow diagrams
  • Egress controls
  • Approved destination list
  • Network policy
Where this commonly fails
  • No data flow diagrams
  • Unapproved destinations
  • Egress wide open
A.11.3
Disposal of PII

The processor shall have a policy on the disposal of PII when it is no longer required, including for backup copies.

Artefacts an auditor will ask for
  • Data retention and disposal schedule
  • Backup expiration configuration
  • Disposal verification records
  • Customer-facing retention commitments
Where this commonly fails
  • Backups never expire
  • Disposal not verified
  • Customer not informed of backup retention
A.11.4
Temporary files

Temporary files containing PII shall be identified and securely deleted within a documented period.

Artefacts an auditor will ask for
  • Temp file inventory
  • Automated purge configuration
  • Purge job logs
  • Periodic review records
Where this commonly fails
  • No identification of temp PII locations
  • Failed cleanup jobs unnoticed
  • Long-lived caches with PII
A.11.5
PII transmission

The cloud PII processor shall ensure that information transmissions are routed and protected in a manner appropriate to the sensitivity of the PII.

Artefacts an auditor will ask for
  • Data classification standard
  • Transmission control matrix
  • Network segmentation design
  • DLP egress monitoring
Where this commonly fails
  • No DLP on email egress
  • Internal transmissions unencrypted
  • Insufficient segmentation
A.12.1
Notification of a data breach

The processor shall promptly notify the customer of any incident leading to loss, disclosure or alteration of PII.

Artefacts an auditor will ask for
  • Breach notification SLA
  • Notification templates
  • Incident records
  • Customer communications log
Where this commonly fails
  • No SLA
  • Notification informal
  • Customer comms missing
A.12.2
Return, transfer and disposal of PII

On termination the processor shall return or securely dispose of PII as instructed by the customer.

Artefacts an auditor will ask for
  • Exit clause
  • Deletion certificates
  • Backup purge evidence
  • Return logs
Where this commonly fails
  • Backups retain PII
  • No deletion certificate
  • Return method unclear
A.12.3
Periodic audits and reviews

The public cloud PII processor shall be subject to periodic audits and reviews of its PII protection controls by an independent third party.

Artefacts an auditor will ask for
  • ISO 27018 certification or attestation report
  • Third-party audit reports
  • Audit schedule
  • Management response to findings
Where this commonly fails
  • Audit findings not remediated
  • Lapsed certification
  • No customer-facing report (SOC 2 or ISO bridge letter)
A.2.1
Purpose legitimacy and specification

PII shall be processed only for the purposes specified by the customer and not used for the processor's own purposes.

Artefacts an auditor will ask for
  • Purpose register
  • Use case approvals
  • Internal use prohibition policy
  • Marketing opt-in records
Where this commonly fails
  • Telemetry uses PII
  • No purpose register
  • Marketing reuse without consent
A.3.1
Collection limitation

The processor shall not collect PII beyond what is required for the agreed purpose.

Artefacts an auditor will ask for
  • Data minimization review
  • Field-level necessity analysis
  • Schema documentation
  • Change control records
Where this commonly fails
  • No minimization review
  • Over-collection by default
  • Schema drift
A.4.1
Data minimization

Temporary files and copies of PII shall be erased or destroyed in a defined period.

Artefacts an auditor will ask for
  • Retention schedule
  • Temporary file purge job logs
  • Cache policy
  • Deletion certificates
Where this commonly fails
  • Cache retains PII
  • No purge jobs
  • Backups out of scope
A.5.1
Use, retention and disclosure limitation

PII shall not be retained beyond the timeframe required to fulfil the agreed purpose unless required by law.

Artefacts an auditor will ask for
  • Retention policy
  • Deletion logs
  • Legal hold register
  • Customer-driven deletion workflow
Where this commonly fails
  • No customer-driven deletion
  • Indefinite logs
  • Legal holds without review
A.6.1
Accuracy and quality

PII processed shall be accurate and up to date to the extent necessary for the purpose.

Artefacts an auditor will ask for
  • Data quality controls
  • Correction workflow
  • Customer correction requests log
  • Validation rules
Where this commonly fails
  • No correction workflow
  • Customer can't correct via portal
  • Validation absent
A.7.1
Openness, transparency and notice

The processor shall provide the customer with information about the processing of PII including subcontractors and locations.

Artefacts an auditor will ask for
  • Subprocessor list
  • Data location disclosure
  • Trust page
  • Notification process for changes
Where this commonly fails
  • Subprocessor list stale
  • No location disclosure
  • No change notification
A.8.1
Individual participation and access

The processor shall provide means for the customer to fulfil PII principal rights including access, correction and deletion.

Artefacts an auditor will ask for
  • DSAR support runbook
  • Customer APIs for rights
  • Response time SLA
  • Closure records
Where this commonly fails
  • No DSAR API
  • Manual fulfilment slow
  • No SLA tracking
A.9.1
Accountability

The processor shall assign roles to manage PII protection and demonstrate compliance.

Artefacts an auditor will ask for
  • Privacy officer appointment
  • Privacy program charter
  • Compliance reports
  • Audit evidence
Where this commonly fails
  • No privacy officer
  • Program informal
  • No external audit
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO/IEC 27018:2019 framework page.