Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Audit Evidence Pack Workflow

A practical workflow for turning EN 319 401 requirements into an audit-ready evidence pack for trust service provider operations.

Use it to organize risk, policy, record, log, continuity, supplier, and legal-compliance evidence. This is implementation guidance, not a conformity certificate; validate it against the applicable service policy, assessment scheme, contracts, and law.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use this workflow for ETSI EN 319 401 V3.1.1 (2024-06) without confusing an evidence folder with a conformity decision. V3.2.1, published in January 2026, is the current ETSI edition; use this V3.1.1 workflow only when that earlier edition is expressly in scope, and otherwise update the clause map and evidence requests to V3.2.1. Start with the exact trust service, policy, assessment period, systems, locations, and suppliers in scope. Then collect current records for risk, policies and practices, terms, security operations, incidents, evidence retention, continuity, termination, compliance, and supply chain.

Section 1

Start the evidence pack with service scope and requirement ownership

EN 319 401 defines policy requirements for operation and management independent of the specific trust service type. Start the pack by naming the provider, trust service, applicable trust service policy, assessment period, systems, facilities, service components, suppliers, and exclusions. Without that boundary, a reviewer cannot tell which evidence supports which service.

Do not treat the pack as a generic spreadsheet. The standard ties evidence to concrete artifacts: a risk assessment, risk treatment decisions, security requirements, operational procedures, a trust service practice statement, terms and conditions, an information security policy, operational records, continuity planning, termination planning, and supplier controls.

Assign one pack maintainer and one accountable owner for each control family. The maintainer controls the index, versions, access, and review state; control owners attest only to records they own. The final reviewer should be able to distinguish evidence that was inspected, evidence supplied but not tested, accepted exclusions, open findings, and records unavailable for the period.

  • Record the trust service policy or policies supported by the , plus the trust service practice statement that describes how the TSP addresses applicable policy requirements.
  • Link each evidence request to an accountable owner: management approval, risk owner, security owner, operations owner, legal/compliance owner, continuity owner, and supplier owner.
  • Separate subscriber- or relying-party documentation from sensitive details. REQ-6.1-05X requires relevant documentation to be available as necessary to demonstrate conformance to the policy, but its note says sensitive aspects need not be disclosed.
  • Flag any assessment-scope question separately because EN 319 401 says independent-party assessment requirements are addressed outside this standard, with EN 319 403-1 noted for conformity assessment body requirements.
  • Record an explicit disposition for every requirement: applicable with evidence, applicable with an open gap, conditional and triggered, conditional and not triggered with reasons, or outside the documented service boundary.
Section 2

Collect the risk and policy evidence before operational records

Start with risk evidence. EN 319 401 requires the to identify, analyse, and evaluate trust service risks; select treatment measures; document the necessary security requirements and operational procedures in the information security policy and practice statement; review and revise the assessment; and obtain management approval and residual-risk acceptance.

Next collect the policy evidence. The needs policies and practices appropriate for the trust services it provides, management approval, communication to relevant employees and external parties, a practice statement covering applicable trust service policy requirements, external-organization obligations, and a defined review process for maintaining the practice statement.

  • Risk evidence: risk register or assessment, risk treatment decisions, selected control measures, review history, management approval, and residual-risk acceptance.
  • Practice evidence: current practice statement, policy-to-practice mapping, management approval, publication or communication record, owner list, and review cadence.
  • Terms evidence: subscriber and relying-party terms, limits on service use, event-log retention period, relying-party information, availability undertaking, and durable publication method.
  • Security-policy evidence: approved information security policy, operating procedures for facilities, systems and information assets, change-notification procedure, asset inventory review trigger, and the maximum interval between configuration checks documented in the practice statement.
Section 3

Build the records pack around EN 319 401 collection-of-evidence duties

Clause 7.10 is the core evidence-pack clause. It requires the to record and keep accessible all relevant information concerning data it issued and received for an appropriate period, including after the TSP's activities have ceased, for legal evidence and continuity of service.

The records pack must show both content and control: which service records exist, how current and archived records retain confidentiality and integrity, how operation records are completely and confidentially archived under disclosed business practices, and how records can be produced when required as evidence of correct service operation in legal proceedings. EN 319 401 does not set one universal retention period; the chosen period must support necessary legal evidence and match the period notified in the terms and conditions.

  • Create a records inventory that identifies issued and received service data, operating records, archive location, retention period, confidentiality control, integrity control, and access path.
  • Include disclosed business practices that explain how operation records are archived and retained.
  • Capture significant environmental, key-management, and clock-synchronization events with precise time.
  • Show that audit-log event time is synchronized with UTC at least once a day.
  • Document how logged events are protected from easy deletion or destruction during their required retention period, unless reliably transferred to long-term media.
Section 4

Use a workflow table that keeps every evidence item reviewable

Use this operating workflow when assigning the pack. Each row should produce a named, versioned artifact for the stated service and review period.

1 | Scope and policy intake | Practice statement owner | Trust service policy list, practice statement, external-organization obligations | Does the pack match the trust service and its declared policies?

2 | Risk and control baseline | Risk and security owners | Risk assessment, risk treatment record, information security policy, operating procedures | Are selected controls tied to approved risk treatment?

3 | Subscriber and relying-party disclosures | Legal/compliance owner | Terms and conditions, limitations, event-log retention statement, relying-party instructions | Are disclosed practices consistent with evidence retention and service operation?

4 | Operational records and logs | Operations/security owner | Service records inventory, archive controls, UTC synchronization evidence, significant event logs | Can the show correct service operation and protect records during retention?

5 | Continuity, termination, and suppliers | Continuity and supplier owners | Continuity plan, backup test results, termination plan, supplier register, agreements and SLAs | Will evidence remain accessible after disaster, service cessation, or supplier change?

6 | Quality review and release | Pack maintainer and independent reviewer | completeness check, exception log, sensitivity label, release record, and approved evidence index | Is the pack ready for its named recipient and purpose, or must it be released with stated gaps?

  • Attach a source clause, owner, artifact name, repository location, retention rule, and next-review trigger to every evidence item.
  • Use change triggers for practice-statement changes, information-security-policy changes, asset inventory changes, supplier changes, incidents, and continuity-test findings.
  • Record exceptions and unavailable evidence as open findings with an owner and disposition; do not replace missing evidence with an assertion.
  • A requirement identifier ending in X marks a requirement added, changed, renumbered, or moved since V2.3.1. It is not an optionality marker.
  • Keep assessment claims narrow: the pack can support review and conformity-assessment preparation, but it is not itself an EN 319 401 conformity decision.
  • Release the pack as ready, ready with stated gaps, or not ready. Record the reviewer, date, purpose, recipient, evidence cut-off, unresolved findings, and next trigger instead of using a bare complete label.
Section 5

Add continuity, termination, compliance, and supplier evidence

The pack should not stop at logs. EN 319 401 also requires evidence around continuity planning, backup resources, recovery testing, crisis management, termination, legal compliance, personal-data protection, and supply-chain controls.

Records must stay usable when the service changes, a disaster occurs, the ceases activities, or a supplier manages or archives TSP information. Treat these areas as dependencies for clause 7.10 instead of separate paperwork.

  • Continuity evidence: maintained continuity plan, backup plans, backup integrity checks, documented recovery tests, corrective actions from findings, and crisis-management test or review records.
  • Termination evidence: up-to-date termination plan, procedures for notifying subscribers, relying parties and relevant authorities, subcontractor authorization termination, and arrangements for maintaining information needed to evidence operation.
  • Compliance evidence: legal-requirements mapping, evidence of how applicable legal requirements are met, accessibility feasibility decisions, and personal-data protection controls.
  • Supplier evidence: supply-chain policy, ICT acquisition security requirements, supplier criteria, component criticality records, monitoring method, supplier agreements, SLAs or audit mechanisms, and a maintained supplier-agreement register.
Section 6

Common evidence-pack mistakes to avoid

A pack that describes intent but cannot show operation is incomplete. EN 319 401 repeatedly calls for documented, approved, maintained, reviewed, available, archived, tested, or recorded artifacts. If a claim cannot be tied to an artifact and review period, record the gap instead of presenting the claim as proved.

Avoid implying that a public guide, internal checklist, or exported folder is a conformity certificate. EN 319 401 provides the general policy requirements baseline; independent assessment context and assessor requirements are separate.

Does EN 319 401 prescribe a fixed evidence retention period?

No. REQ-7.10-07 requires service records to be held for a period appropriate to necessary legal evidence and notified in the 's terms and conditions. Determine the period from the service, applicable law, policy, contracts, and assessment scheme, then keep the public terms and internal retention schedule aligned.

Can sensitive evidence be withheld from subscribers and relying parties?

EN 319 401 requires the practice statement and other relevant documentation to be available as necessary to demonstrate conformance to the trust service policy, but the note to REQ-6.1-05X says sensitive aspects need not be disclosed. Keep a controlled assessor version and a suitable subscriber- or relying-party version, and record why information was restricted.

  • Do not cite EN 319 401 for service-specific certificate rules unless the applicable service-specific ETSI standard is also in scope.
  • Do not publish sensitive practice-statement details merely because some documentation must be available to subscribers and relying parties.
  • Do not keep record-retention periods only in an internal ticket; the standard links retention to the 's terms and conditions.
  • Do not leave UTC synchronization, significant key-management events, backup recovery tests, supplier agreement registers, or termination-plan evidence outside the pack.
  • Do not use stale private filenames, unpublished drafts, redirected private URLs, or source links without the required Sorena reference parameter.
Primary sources

References and citations

etsi.org
Referenced sections
  • Clauses 1, 5, 6, and 7 establish the TSP baseline, evidence-bearing documents, sensitive-information qualification, and independent-assessment boundary.
etsi.org
Referenced sections
  • Requirements REQ-7.10-01 through REQ-7.10-08 cover record accessibility, archive confidentiality and integrity, legal-evidence availability, event timing, daily UTC synchronization, disclosed retention, and deletion resistance.
etsi.org
Referenced sections
  • Clauses 5 and 6 require the risk assessment, treatment and approval evidence, trust service practice statement, terms and conditions, information security policy, and related reviews.
etsi.org
Referenced sections
  • Clauses 3.4, 5, 6, and 7.10 through 7.14 ground the workflow, explain the X change indicator, and cover records, continuity, termination, compliance, and suppliers.
etsi.org
Referenced sections
  • Current ETSI edition; use it unless the evidence request or assessment criteria expressly retain V3.1.1.
Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.