Skip to content

Evidence request lists

Singapore Government Instruction Manual on ICT&SS Management (IM8)

Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

AI Governance

SGIMEIGHT-3
AI and Algorithmic System Governance

Per IM8: AI and Algorithmic System Governance + ethics + risk + integration with SG AI Verify.

Artefacts an auditor will ask for
  • IM8 evidence for SGIMEIGHT-3
Where this commonly fails
  • AI governance + cloud + audit partial

Awareness and Training

IM8-AWR
Security Awareness and Training

Deliver security awareness and role-specific training to public officers and contractors handling government data, with knowledge checks and refresher cycles aligned to IM8.

Artefacts an auditor will ask for
  • Annual awareness curriculum and completion records
  • Role-specific training for developers, administrators, and data handlers
  • Phishing simulation programme outputs
  • Refresh schedule and exception handling
Where this commonly fails
  • Awareness training completion measured at policy publication only, not actual completion
  • Role-based training optional for senior officers
  • Phishing simulations performed but failures not converted to targeted training

Cloud Services

IM8-CLD
Use of Cloud Services and Government-on-Commercial-Cloud

Where cloud services are used, comply with IM8 requirements for government cloud adoption, including approved cloud service providers, data residency, sensitivity restrictions, and Government-on-Commercial-Cloud (GCC) usage where applicable.

Artefacts an auditor will ask for
  • Approved cloud service provider list and contracts
  • Data residency configuration evidence
  • GCC tenant configuration and guardrails
  • Cloud risk assessment per workload
Where this commonly fails
  • Workloads classified as Restricted deployed on non-approved cloud tiers
  • Data residency configured at storage level but not at backup and analytics layers
  • GCC guardrails disabled for development tenants without compensating controls
IM8-CLD.1
Cloud Adoption Governance

Agencies must follow prescribed governance processes when adopting cloud services for government workloads.

Artefacts an auditor will ask for
  • cloud adoption policy
  • cloud governance framework
  • approval procedures
  • exception register
Where this commonly fails
  • no cloud governance framework
  • weak approval procedures
  • missing exception register
IM8-CLD.2
Cloud Security Controls

Agencies must implement security controls for cloud environments covering access, encryption, and monitoring.

Artefacts an auditor will ask for
  • cloud control matrix
  • shared responsibility documentation
  • control implementation evidence
  • monitoring records
Where this commonly fails
  • unclear shared responsibility
  • missing control matrix
  • weak monitoring
IM8-CLD.3
Cloud Service Provider Assessment

Agencies must assess and validate the security posture of cloud service providers before engagement.

Artefacts an auditor will ask for
  • CSP risk assessment reports
  • MTCS certification records
  • contract clauses
  • ongoing monitoring records
Where this commonly fails
  • no CSP risk assessment
  • weak contracts
  • missing ongoing monitoring
IM8-CLD.4
Cloud Data Sovereignty

Agencies must ensure government data stored in cloud environments meets data residency and sovereignty requirements.

Artefacts an auditor will ask for
  • data residency mapping
  • data location records
  • transfer agreements
  • regulatory compliance documentation
Where this commonly fails
  • no residency mapping
  • weak transfer agreements
  • missing compliance documentation

Cloud and Data

SGIMEIGHT-4
Cloud, Data, Procurement, Outsourcing

Per IM8: cloud + data + procurement + outsourcing controls per government context.

Artefacts an auditor will ask for
  • IM8 evidence for SGIMEIGHT-4
Where this commonly fails
  • AI governance + cloud + audit partial

Data Management

IM8-DAT.1
Data Classification

Agencies must classify data according to sensitivity levels and apply appropriate handling and protection measures.

Artefacts an auditor will ask for
  • data classification policy
  • classification scheme
  • labelling records
  • review cadence
Where this commonly fails
  • no classification scheme
  • weak labelling
  • no review cadence
IM8-DAT.2
Data Protection

Agencies must implement controls to protect the confidentiality, integrity, and availability of government data.

Artefacts an auditor will ask for
  • data protection policy
  • encryption records
  • access control documentation
  • DLP configurations
Where this commonly fails
  • weak encryption
  • no DLP
  • missing access controls
IM8-DAT.3
Data Sharing and Transfer

Agencies must establish controls for secure data sharing and transfer between agencies and with external parties.

Artefacts an auditor will ask for
  • data sharing agreements
  • transfer impact assessments
  • approval records
  • monitoring logs
Where this commonly fails
  • no sharing agreements
  • weak TIA
  • missing monitoring
IM8-DAT.4
Data Retention and Disposal

Agencies must implement policies for data retention schedules and secure disposal of data no longer required.

Artefacts an auditor will ask for
  • retention schedule
  • disposal procedures
  • destruction certificates
  • audit records
Where this commonly fails
  • no retention schedule
  • weak disposal
  • missing certificates
IM8-DEC
Decommissioning and Data Disposal

Decommission ICT and SS assets and dispose of government data in line with IM8 requirements, including secure data destruction, decommission records, and confirmation of asset disposal.

Artefacts an auditor will ask for
  • Decommissioning plan per system
  • Secure destruction certificates from approved providers
  • Inventory updates reflecting disposal
  • Confirmation of removal from backups and archives
Where this commonly fails
  • Production data destroyed but copies in backups and analytics not addressed
  • Destruction certificates accepted from non-approved providers
  • Inventory not updated post-decommissioning, leaving phantom assets

Digital Services and Secure Development

IM8-DEV
Secure Software Development for Government Systems

Apply secure software development practices to government ICT and SS, including secure coding standards, code review, automated security testing, and security gates within the development lifecycle.

Artefacts an auditor will ask for
  • Secure development policy aligned with IM8
  • Code review records and pull request templates referencing security checks
  • SAST, DAST, and SCA tool configuration and findings
  • Security gate evidence at build and release
Where this commonly fails
  • Secure development policy aligned to outdated IM8 revision
  • Automated testing runs but findings not blocked at gates
  • Third-party code integrated without SCA scanning
IM8-DSS.1
User-Centric Design

Digital services must be designed with user needs and accessibility requirements as primary considerations.

Artefacts an auditor will ask for
  • user research records
  • service blueprints
  • usability test reports
  • design standards documentation
Where this commonly fails
  • no user research
  • weak usability testing
  • missing design standards
IM8-DSS.2
Service Reliability Standards

Digital services must meet prescribed availability and performance standards for public-facing systems.

Artefacts an auditor will ask for
  • SLA documentation
  • uptime reports
  • incident metrics
  • reliability test results
Where this commonly fails
  • no SLA
  • weak uptime tracking
  • missing reliability tests
IM8-DSS.3
Secure Development Practices

Agencies must adopt secure software development lifecycle practices for digital services.

Artefacts an auditor will ask for
  • secure SDLC documentation
  • code review records
  • SAST and DAST results
  • developer training records
Where this commonly fails
  • no secure SDLC
  • weak code review
  • missing security testing

Governance

SGIMEIGHT-1
Governance, Audit, Independent Assurance

Per Singapore IM8: governance + Internal Audit and Independent Assurance + reporting to senior management + SmartNation Group + GovTech.

Artefacts an auditor will ask for
  • IM8 evidence for SGIMEIGHT-1
Where this commonly fails
  • AI governance + cloud + audit partial

Governance and Risk Management

IM8-CLF
Data Classification and Handling

Classify government data and information products according to the IM8 sensitivity and security classification scheme (Official-Open, Official-Closed, Restricted, Confidential, Secret) and apply handling controls appropriate to each tier.

Artefacts an auditor will ask for
  • Data classification policy aligned with IM8 scheme
  • Inventory of datasets and information products with assigned classifications
  • Handling instructions per classification including transmission, storage, and destruction
  • Sample documents and systems with applied markings
Where this commonly fails
  • Classifications applied at dataset level but not at field level for mixed-sensitivity records
  • Handling instructions not implemented in technical controls (DLP, labelling)
  • Markings inconsistent between document templates and actual outputs
IM8-CON
Contractor Compliance and Flow-Down

Ensure contractors who develop, operate, or maintain government ICT and SS comply with applicable IM8 instructions through contractual obligations, training, monitoring, and assurance.

Artefacts an auditor will ask for
  • Standard government ICT contract clauses referencing IM8
  • Contractor staff IM8 awareness training records
  • Ongoing assurance reviews of contractor compliance
  • Right-to-audit exercises performed and findings closed
Where this commonly fails
  • Older contracts predating current IM8 revisions not amended
  • Training delivered to contractor leads only, not to engineering staff
  • Right-to-audit clauses never exercised, leaving compliance unverified
IM8-DPP
Data Protection and Privacy by Design for Government Services

Apply data protection and privacy by design principles to government services, including data minimisation, purpose limitation, retention controls, and Data Protection Trustmark or equivalent assurance where applicable.

Artefacts an auditor will ask for
  • Privacy impact assessment per service
  • Data minimisation analysis showing fields collected versus required
  • Retention schedule per dataset
  • Records of purpose limitation review when data is reused
Where this commonly fails
  • Privacy impact assessment performed for citizen-facing services only, omitting internal datasets
  • Retention schedules documented but not implemented in storage layers
  • Secondary use of data approved without revisiting privacy impact assessment
IM8-RA
Risk Assessment for ICT and SS Initiatives

Conduct risk assessments for every ICT and SS initiative covering security, privacy, operational, and supplier dimensions, and refresh assessments at defined lifecycle gates.

Artefacts an auditor will ask for
  • Risk assessment template aligned to IM8 dimensions
  • Completed assessments per ICT and SS project
  • Gate review records linking risk outcomes to approval decisions
  • Refresh schedule per system criticality
Where this commonly fails
  • Assessments performed only at initiation, never refreshed when scope changes
  • Risk treatment plans logged without ownership
  • Supplier risk treated separately and not integrated into the initiative risk view

Incident

SGIMEIGHT-5
Incident Response and Continuity

Per IM8: incident response + business continuity + cyber resilience.

Artefacts an auditor will ask for
  • IM8 evidence for SGIMEIGHT-5
Where this commonly fails
  • AI governance + cloud + audit partial

Information Security

IM8-DLP
Protection of Government Data Across Channels

Protect government data across storage, transmission, and processing using encryption, data loss prevention, and approved transmission channels appropriate to the data classification.

Artefacts an auditor will ask for
  • Encryption inventory mapped to data classification
  • TLS configuration and certificate inventory
  • DLP policy and event handling records
  • Approved channel list for sensitive data exchange
Where this commonly fails
  • Encryption applied at storage layer but bypassed by direct database access
  • Legacy transmission channels (FTP, unauthenticated email) still in operational use
  • DLP alerts triaged inconsistently across business units
IM8-IAM
Identity, Authentication, and Privileged Access

Apply identity, authentication, and privileged access controls in line with IM8 requirements, including strong authentication for sensitive access, role-based access control, and oversight of privileged accounts.

Artefacts an auditor will ask for
  • Sign-In with Singpass or equivalent strong authentication evidence for sensitive transactions
  • Role definitions and access matrices
  • Privileged access management tool logs
  • Periodic access review records
Where this commonly fails
  • Multi-factor authentication enforced for end users but not for system-to-system credentials
  • Role definitions overlap creating implicit privilege accumulation
  • Privileged session recording configured but recordings never reviewed
IM8-LOG
Logging, Monitoring, and Audit Trail

Generate and retain logs of security-relevant events from government ICT and SS systems, monitor them for indicators of compromise, and protect them from tampering.

Artefacts an auditor will ask for
  • Log source inventory covering OS, application, database, network, and identity layers
  • Retention configured to IM8 prescribed period
  • SIEM ingestion and use-case catalogue
  • Integrity controls for log storage
Where this commonly fails
  • Application logs sampled rather than complete
  • Retention shortened to manage storage costs without authorisation
  • No tamper evidence (hashing, immutability) on archived logs
IM8-PATCH
Patching and Vulnerability Remediation

Patch ICT and SS systems within the prescribed timeframes based on severity, and track unpatched vulnerabilities with documented risk acceptance.

Artefacts an auditor will ask for
  • Patch deployment records meeting IM8 SLAs per severity
  • Vulnerability tracker with status and aging
  • Risk acceptance forms for deferred patches
  • Reporting to senior accountable officer
Where this commonly fails
  • SLA tracked at fleet average rather than per asset
  • Risk acceptance forms missing senior officer signature
  • Reporting lacks trending over time, missing systemic patch debt
IM8-SEC.1
Security Architecture Design

Agencies must adopt defence-in-depth security architecture principles for ICT systems design.

Artefacts an auditor will ask for
  • security architecture documents
  • reference architectures
  • design review records
  • approval logs
Where this commonly fails
  • no security architecture
  • weak design reviews
  • missing approvals
IM8-SEC.2
Access Control

Agencies must implement access control mechanisms based on least privilege and need-to-know principles.

Artefacts an auditor will ask for
  • access control policy
  • RBAC documentation
  • access review reports
  • privileged access logs
Where this commonly fails
  • weak access control
  • no reviews
  • missing privileged access controls
IM8-SEC.3
Network Security

Agencies must implement network segmentation, firewalls, and intrusion detection to protect government networks.

Artefacts an auditor will ask for
  • network architecture diagrams
  • firewall rule reviews
  • segmentation documentation
  • monitoring records
Where this commonly fails
  • flat network
  • stale rules
  • weak segmentation
IM8-SEC.4
Vulnerability Management

Agencies must conduct regular vulnerability assessments and penetration testing of ICT systems.

Artefacts an auditor will ask for
  • vulnerability scan reports
  • remediation tracking
  • patching records
  • exception register
Where this commonly fails
  • scanning gaps
  • remediation past SLA
  • missing patches
IM8-VAPT
Vulnerability Assessment and Penetration Testing

Conduct vulnerability assessment and penetration testing (VAPT) on ICT and SS systems prior to go-live and at defined intervals thereafter, using approved testers and addressing identified findings within prescribed timeframes.

Artefacts an auditor will ask for
  • VAPT schedule aligned to IM8 frequencies
  • Engagement records with approved testers
  • VAPT reports with severity-ranked findings
  • Remediation tracker meeting prescribed SLA
Where this commonly fails
  • Penetration testing performed pre-launch but not refreshed post material change
  • Remediation extensions granted without revisiting risk acceptance
  • Test scope limited to surface assets, omitting internal lateral paths
SGIMEIGHT-2
Information Security, Classification, Access

Per IM8: information security + classification + access control + encryption + cybersecurity baseline.

Artefacts an auditor will ask for
  • IM8 evidence for SGIMEIGHT-2
Where this commonly fails
  • AI governance + cloud + audit partial

Resilience and Incident Response

IM8-BCM
Business Continuity and Disaster Recovery

Maintain business continuity and disaster recovery plans for government ICT and SS aligned to service criticality, with regular testing and senior officer sign-off on residual risk.

Artefacts an auditor will ask for
  • BCP covering essential government services
  • DR test plans and results
  • Service criticality matrix linking RTO and RPO to citizen impact
  • Senior officer sign-off on residual risk
Where this commonly fails
  • BCPs static after first publication, not refreshed for service changes
  • DR tests performed without independent observation
  • Criticality matrix not aligned with whole-of-government service classifications
IM8-IR
Cyber Incident Response and Reporting to GovTech

Maintain a cyber incident response capability and report incidents affecting government ICT and SS to GovTech (the lead agency) and other authorities within prescribed timelines, including incidents at contractors.

Artefacts an auditor will ask for
  • IR plan referencing GovTech notification obligations
  • Incident reporting log with timestamps
  • Contractor notification clauses and operational evidence
  • Post-incident review reports
Where this commonly fails
  • Reporting starts from confirmation rather than detection
  • Contractor incidents notified to procuring agency only, not escalated as required
  • Post-incident reviews completed but findings not fed into baseline improvements
IM8-RES.1
Business Continuity Planning

Agencies must develop and maintain business continuity plans for critical ICT systems and services.

Artefacts an auditor will ask for
  • BCP documentation
  • BIA records
  • BCP testing reports
  • executive sign-off
Where this commonly fails
  • no BCP
  • weak BIA
  • missing testing
IM8-RES.2
Disaster Recovery

Agencies must establish disaster recovery procedures and infrastructure to restore critical systems within defined timeframes.

Artefacts an auditor will ask for
  • DR plan
  • DR test reports
  • RTO and RPO documentation
  • failover records
Where this commonly fails
  • no DR plan
  • untested DR
  • missing RTO and RPO
IM8-RES.3
Incident Response

Agencies must implement incident response procedures to detect, contain, and recover from cybersecurity incidents.

Artefacts an auditor will ask for
  • incident response plan
  • Playbooks
  • exercise reports
  • lessons learned register
Where this commonly fails
  • no IR plan
  • weak playbooks
  • missing exercises
IM8-RES.4
Resilience Testing

Agencies must conduct regular testing of business continuity and disaster recovery plans to ensure effectiveness.

Artefacts an auditor will ask for
  • resilience test plan
  • exercise reports
  • scenario documentation
  • improvement tracking
Where this commonly fails
  • no resilience testing
  • weak scenarios
  • missing improvement tracking

Third Party and Supply Chain

IM8-SCM
Supply Chain and Vendor Management

Manage supply chain and vendor risks for government ICT and SS, including third-party security assessments, contractual security obligations, and ongoing monitoring of vendor performance.

Artefacts an auditor will ask for
  • Vendor risk assessment records
  • Contract clauses referencing IM8 obligations, audit rights, and incident reporting
  • Quarterly or annual vendor performance reviews
  • Sub-contractor flow-down evidence
Where this commonly fails
  • Due diligence performed at award with no refresh
  • Contracts lack flow-down clauses to sub-contractors
  • Performance reviews track delivery only, omitting security KPIs
IM8-TPM.1
Vendor Security Assessment

Agencies must assess the security posture of third-party vendors before granting access to government systems.

Artefacts an auditor will ask for
  • vendor risk assessments
  • security questionnaires
  • due diligence records
  • approval logs
Where this commonly fails
  • no vendor assessment
  • weak questionnaires
  • missing approvals
IM8-TPM.2
Contractual Security Requirements

Agencies must include security requirements in contracts with third-party ICT service providers.

Artefacts an auditor will ask for
  • contract security clauses
  • DPA records
  • right-to-audit clauses
  • contract review logs
Where this commonly fails
  • missing clauses
  • no DPA
  • no audit rights
IM8-TPM.3
Third-Party Monitoring

Agencies must monitor third-party compliance with security requirements throughout the engagement period.

Artefacts an auditor will ask for
  • vendor monitoring records
  • performance reports
  • compliance dashboards
  • review cadence
Where this commonly fails
  • no ongoing monitoring
  • weak dashboards
  • missing review cadence
IM8-TPM.4
Supply Chain Risk Management

Agencies must manage supply chain risks associated with ICT products and services procurement.

Artefacts an auditor will ask for
  • supply chain risk register
  • subcontractor inventory
  • concentration analyses
  • executive reports
Where this commonly fails
  • no supply chain register
  • weak subcontractor visibility
  • missing concentration analyses
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.