Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Audit Evidence Pack

A practical evidence-pack guide for trust service providers applying ETSI EN 319 401 clause 7.10 and its supporting policy, risk, incident, continuity, and supplier controls.

Based on ETSI EN 319 401 V3.1.1 and linked public sources. Use it as implementation guidance, not for legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use this outline to show what a trust service provider recorded, how each record was protected and retained, and which service and review period it supports under ETSI EN 319 401 V3.1.1 (2024-06). V3.2.1, published in January 2026, is the current ETSI edition; use this V3.1.1 outline only when that earlier edition is expressly in scope, and otherwise update the clause map and evidence requests to V3.2.1. The pack should let an authorized reviewer trace a requirement to a current control and inspectable record. It supports review; it is not a conformity certificate or qualified-status decision.

Section 1

What belongs in an ETSI EN 319 401 audit evidence pack?

Start with clause 7.10. It requires the to record and keep accessible all relevant information concerning data it issued and received for an appropriate period, including after its activities have ceased, for legal evidence and service continuity. The pack therefore extends beyond audit logs: show what was issued or received, how operation records were protected, and how records remain available for the stated retention period.

Use the trust service practice statement, terms and conditions, information security policy, risk assessment, audit logs, incident records, backup tests, termination plan, legal-requirement evidence, and supplier register as the core index. Those artifacts are tied to separate EN 319 401 clauses, but together they explain whether the record set is complete, confidential, integrity-protected, and aligned with disclosed business practices.

The should maintain the source records in their systems of record and appoint a pack maintainer to control the index, evidence cut-off, access, versions, and release history. Do not copy uncontrolled files into a folder and treat the copies as authoritative. Each entry should point to the controlled record or explain how an authorized reviewer can inspect it.

  • Create a source-to-evidence index that names the relevant EN 319 401 clause, internal control owner, evidence location, retention period, and latest review date.
  • Include records of service operation, data issued and received by the , significant environmental events, key-management events, and clock-synchronization events.
  • Show how current and archived records keep confidentiality and integrity, including the archive method and the controls that prevent easy deletion or destruction during the retention period.
  • Tie each service-record retention period to the 's terms and conditions. EN 319 401 does not set one universal duration; REQ-7.10-07 requires a period appropriate for necessary legal evidence and notified in the terms.
  • For every index entry, capture the artifact title and version, source requirement, service boundary, period covered, owner, system of record, access classification, retention and disposal rule, collection date, reviewer, review result, exception, and next review trigger.
Section 2

Evidence map by EN 319 401 control area

Do not organize the pack only by department. Use the control areas that show how the operates and preserves evidence: risk assessment, published practices, terms, security policy, personnel and trusted roles, asset inventory, access and configuration control, incident management, continuity, termination, compliance, and supply chain.

The pack should let a reviewer move from claim to proof without private context. For example, a claim that logs are reviewable should point to the logging control, a sample review record, the alerting or monitoring process, the person or trusted role responsible, and the retention rule that protects the log after the review.

  • Risk assessment: include management approval, residual-risk acceptance, chosen risk-treatment measures, and the review record required by clause 5.
  • Policies and practices: include the approved trust service practice statement, terms and conditions, information security policy, change-notice procedure, and evidence that relevant parties can access non-sensitive documentation.
  • Operations: include personnel training and trusted-role appointments, asset inventory and classification, access-control records, configuration reviews, vulnerability scans, and patch or exception documentation.
  • Incidents and continuity: include monitoring and audit-log reviews, incident response documentation, event classification, post-incident reviews, backup integrity checks, recovery-test results, crisis-management reviews, and continuity-plan ownership.
  • Suppliers: include supply-chain policy, supplier criteria, documented subcontracting or outsourcing agreements, service-level or audit mechanisms, supplier register, and planned supplier-review evidence.
Section 3

Records and logs that need special handling

The operational record set is often sensitive. EN 319 401 requires confidentiality and integrity for current and archived service-operation records, complete and confidential archiving, availability of records for evidence of correct operation, and UTC synchronization for audit-log event time at least once a day.

Treat logs as evidence, not background telemetry. The pack should show which logs exist, why they matter to the trust service, how they are reviewed, how alerts are escalated, how deletion is prevented during the required period, and how records can be retrieved without exposing sensitive material unnecessarily.

  • List each record family: service-operation records, issued and received data records, audit logs, environmental events, key-management events, clock-synchronization events, incident records, backup records, and supplier records.
  • For each record family, capture owner, system of record, retention rule, confidentiality and integrity control, archive location, retrieval process, and destruction or long-term-transfer rule.
  • Evidence the daily UTC synchronization control for event time recording where audit logs are used to satisfy clause 7.10.
  • For incident logs, preserve the path from detection through documentation, reporting decision, containment, eradication, recovery, severity assessment, reclassification if needed, and post-incident review.
Section 4

Review checklist before an audit or assessment

Review this checklist before giving the pack to an assessor, customer, supervisory contact, or independent review board. Every claim should have a clause, a record, a retention rule, an owner, a review period, and a way to verify that the evidence still represents the current trust service.

Do not claim that EN 319 401 itself defines the independent assessment method. The standard states general policy requirements for operation and management; it points readers to ETSI EN 319 403-1 for requirements about conformity assessment bodies assessing TSPs.

Release decisions should name the recipient and purpose. A customer extract may omit sensitive material that remains available under controlled inspection, while an assessor pack may need broader access under the applicable scheme. Record redactions, summaries, withheld items, and the reason for each access decision so absence is not mistaken for missing evidence.

  • Version check: confirm the page and pack cite ETSI EN 319 401 V3.1.1 (2024-06) or deliberately document why a different version is in scope.
  • Scope check: name the trust service, locations, systems, trustworthy systems, suppliers, cloud services, and trust service components covered by the pack.
  • Completeness check: confirm that each clause-level evidence item has an owner, date, system of record, retention rule, and exception status.
  • Sensitivity check: separate assessor-shareable evidence from sensitive details that should be summarized, redacted, or inspected under controlled access.
  • Change check: trigger review when the practice statement, information security policy, trust service provision, systems, keys, suppliers, cloud services, or continuity assumptions materially change.
  • Identifier check: treat an X suffix as a change indicator from V2.3.1, not as an optional requirement.
  • Release check: record the evidence cut-off, recipient, purpose, reviewer, open gaps, controlled-access items, and whether the pack is ready, ready with stated gaps, or not ready.
Section 5

Common evidence-pack mistakes

Presentation cannot replace traceability. Tie each record to the trust service boundary, disclosed practices, retention commitments, incident procedures, continuity assumptions, and supplier obligations.

Remove claims that the available evidence cannot support. State the service and period covered, the source requirement, the artifact showing operation, and any open exception.

Is an the same as a conformity assessment report?

No. An evidence pack is the 's organized set of policies, records, and control evidence. EN 319 401 does not define the independent assessment method or the assessor's report. A conformity assessment report follows the applicable scheme and legal process; for an EU qualified trust service, current eIDAS Article 20 also governs recurring audits and report submission.

How much evidence should be shared with subscribers or customers?

Share enough relevant documentation to meet the applicable policy, terms, contract, and review purpose, but control sensitive information. The note to EN 319 401 REQ-6.1-05X says the need not disclose sensitive aspects in documentation made available to subscribers and relying parties. Keep a full controlled pack and prepare scoped extracts or supervised access where appropriate.

  • Do not treat a generic information security policy as proof of clause 7.10 unless it maps to actual retained records and archive controls.
  • Do not list logs without showing review, alerting, retention, confidentiality, integrity, and deletion-resistance controls.
  • Do not leave retention periods implicit; clause 7.10 connects service-record retention to necessary legal evidence and the 's terms and conditions.
  • Do not omit termination evidence, because EN 319 401 requires continued maintenance or transfer of information needed to verify trust-service correctness when services cease.
  • Do not cite assessor expectations as EN 319 401 requirements unless the evidence pack distinguishes EN 319 401 from EN 319 403-1 or the actual assessment scheme.
Primary sources

References and citations

Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.