A practical evidence-pack guide for trust service providers applying ETSI EN 319 401 clause 7.10 and its supporting policy, risk, incident, continuity, and supplier controls.
Based on ETSI EN 319 401 V3.1.1 and linked public sources. Use it as implementation guidance, not for legal interpretation.
Use this outline to show what a trust service provider recorded, how each record was protected and retained, and which service and review period it supports under ETSI EN 319 401 V3.1.1 (2024-06). V3.2.1, published in January 2026, is the current ETSI edition; use this V3.1.1 outline only when that earlier edition is expressly in scope, and otherwise update the clause map and evidence requests to V3.2.1. The pack should let an authorized reviewer trace a requirement to a current control and inspectable record. It supports review; it is not a conformity certificate or qualified-status decision.
1
Section 1
What belongs in an ETSI EN 319 401 audit evidence pack?
Start with clause 7.10. It requires the to record and keep accessible all relevant information concerning data it issued and received for an appropriate period, including after its activities have ceased, for legal evidence and service continuity. The pack therefore extends beyond audit logs: show what was issued or received, how operation records were protected, and how records remain available for the stated retention period.
Use the trust service practice statement, terms and conditions, information security policy, risk assessment, audit logs, incident records, backup tests, termination plan, legal-requirement evidence, and supplier register as the core index. Those artifacts are tied to separate EN 319 401 clauses, but together they explain whether the record set is complete, confidential, integrity-protected, and aligned with disclosed business practices.
The should maintain the source records in their systems of record and appoint a pack maintainer to control the index, evidence cut-off, access, versions, and release history. Do not copy uncontrolled files into a folder and treat the copies as authoritative. Each entry should point to the controlled record or explain how an authorized reviewer can inspect it.
Create a source-to-evidence index that names the relevant EN 319 401 clause, internal control owner, evidence location, retention period, and latest review date.
Include records of service operation, data issued and received by the , significant environmental events, key-management events, and clock-synchronization events.
Show how current and archived records keep confidentiality and integrity, including the archive method and the controls that prevent easy deletion or destruction during the retention period.
Tie each service-record retention period to the 's terms and conditions. EN 319 401 does not set one universal duration; REQ-7.10-07 requires a period appropriate for necessary legal evidence and notified in the terms.
For every index entry, capture the artifact title and version, source requirement, service boundary, period covered, owner, system of record, access classification, retention and disposal rule, collection date, reviewer, review result, exception, and next review trigger.
Do not organize the pack only by department. Use the control areas that show how the operates and preserves evidence: risk assessment, published practices, terms, security policy, personnel and trusted roles, asset inventory, access and configuration control, incident management, continuity, termination, compliance, and supply chain.
The pack should let a reviewer move from claim to proof without private context. For example, a claim that logs are reviewable should point to the logging control, a sample review record, the alerting or monitoring process, the person or trusted role responsible, and the retention rule that protects the log after the review.
Risk assessment: include management approval, residual-risk acceptance, chosen risk-treatment measures, and the review record required by clause 5.
Policies and practices: include the approved trust service practice statement, terms and conditions, information security policy, change-notice procedure, and evidence that relevant parties can access non-sensitive documentation.
Operations: include personnel training and trusted-role appointments, asset inventory and classification, access-control records, configuration reviews, vulnerability scans, and patch or exception documentation.
Incidents and continuity: include monitoring and audit-log reviews, incident response documentation, event classification, post-incident reviews, backup integrity checks, recovery-test results, crisis-management reviews, and continuity-plan ownership.
Suppliers: include supply-chain policy, supplier criteria, documented subcontracting or outsourcing agreements, service-level or audit mechanisms, supplier register, and planned supplier-review evidence.
The operational record set is often sensitive. EN 319 401 requires confidentiality and integrity for current and archived service-operation records, complete and confidential archiving, availability of records for evidence of correct operation, and UTC synchronization for audit-log event time at least once a day.
Treat logs as evidence, not background telemetry. The pack should show which logs exist, why they matter to the trust service, how they are reviewed, how alerts are escalated, how deletion is prevented during the required period, and how records can be retrieved without exposing sensitive material unnecessarily.
List each record family: service-operation records, issued and received data records, audit logs, environmental events, key-management events, clock-synchronization events, incident records, backup records, and supplier records.
For each record family, capture owner, system of record, retention rule, confidentiality and integrity control, archive location, retrieval process, and destruction or long-term-transfer rule.
Evidence the daily UTC synchronization control for event time recording where audit logs are used to satisfy clause 7.10.
For incident logs, preserve the path from detection through documentation, reporting decision, containment, eradication, recovery, severity assessment, reclassification if needed, and post-incident review.
Review this checklist before giving the pack to an assessor, customer, supervisory contact, or independent review board. Every claim should have a clause, a record, a retention rule, an owner, a review period, and a way to verify that the evidence still represents the current trust service.
Do not claim that EN 319 401 itself defines the independent assessment method. The standard states general policy requirements for operation and management; it points readers to ETSI EN 319 403-1 for requirements about conformity assessment bodies assessing TSPs.
Release decisions should name the recipient and purpose. A customer extract may omit sensitive material that remains available under controlled inspection, while an assessor pack may need broader access under the applicable scheme. Record redactions, summaries, withheld items, and the reason for each access decision so absence is not mistaken for missing evidence.
Version check: confirm the page and pack cite ETSI EN 319 401 V3.1.1 (2024-06) or deliberately document why a different version is in scope.
Scope check: name the trust service, locations, systems, trustworthy systems, suppliers, cloud services, and trust service components covered by the pack.
Completeness check: confirm that each clause-level evidence item has an owner, date, system of record, retention rule, and exception status.
Sensitivity check: separate assessor-shareable evidence from sensitive details that should be summarized, redacted, or inspected under controlled access.
Change check: trigger review when the practice statement, information security policy, trust service provision, systems, keys, suppliers, cloud services, or continuity assumptions materially change.
Identifier check: treat an X suffix as a change indicator from V2.3.1, not as an optional requirement.
Release check: record the evidence cut-off, recipient, purpose, reviewer, open gaps, controlled-access items, and whether the pack is ready, ready with stated gaps, or not ready.
Presentation cannot replace traceability. Tie each record to the trust service boundary, disclosed practices, retention commitments, incident procedures, continuity assumptions, and supplier obligations.
Remove claims that the available evidence cannot support. State the service and period covered, the source requirement, the artifact showing operation, and any open exception.
Is an the same as a conformity assessment report?
No. An evidence pack is the 's organized set of policies, records, and control evidence. EN 319 401 does not define the independent assessment method or the assessor's report. A conformity assessment report follows the applicable scheme and legal process; for an EU qualified trust service, current eIDAS Article 20 also governs recurring audits and report submission.
How much evidence should be shared with subscribers or customers?
Share enough relevant documentation to meet the applicable policy, terms, contract, and review purpose, but control sensitive information. The note to EN 319 401 REQ-6.1-05X says the need not disclose sensitive aspects in documentation made available to subscribers and relying parties. Keep a full controlled pack and prepare scoped extracts or supervised access where appropriate.
Do not treat a generic information security policy as proof of clause 7.10 unless it maps to actual retained records and archive controls.
Do not list logs without showing review, alerting, retention, confidentiality, integrity, and deletion-resistance controls.
Do not leave retention periods implicit; clause 7.10 connects service-record retention to necessary legal evidence and the 's terms and conditions.
Do not omit termination evidence, because EN 319 401 requires continued maintenance or transfer of information needed to verify trust-service correctness when services cease.
Do not cite assessor expectations as EN 319 401 requirements unless the evidence pack distinguishes EN 319 401 from EN 319 403-1 or the actual assessment scheme.
For EU qualified trust services, Article 24(2)(h) supplies separate legal context for keeping relevant issued and received information accessible after activities cease.
For EU qualified trust services, Articles 20 and 24 provide separate legal context for conformity assessment and retained information; those legal duties should not be attributed to EN 319 401 alone.