A practical workflow for turning EN 319 401 requirements into an audit-ready evidence pack for trust service provider operations.
Use it to organize risk, policy, record, log, continuity, supplier, and legal-compliance evidence. This is implementation guidance, not a conformity certificate; validate it against the applicable service policy, assessment scheme, contracts, and law.
Use this workflow for ETSI EN 319 401 V3.1.1 (2024-06) without confusing an evidence folder with a conformity decision. V3.2.1, published in January 2026, is the current ETSI edition; use this V3.1.1 workflow only when that earlier edition is expressly in scope, and otherwise update the clause map and evidence requests to V3.2.1. Start with the exact trust service, policy, assessment period, systems, locations, and suppliers in scope. Then collect current records for risk, policies and practices, terms, security operations, incidents, evidence retention, continuity, termination, compliance, and supply chain.
1
Section 1
Start the evidence pack with service scope and requirement ownership
EN 319 401 defines policy requirements for operation and management independent of the specific trust service type. Start the pack by naming the provider, trust service, applicable trust service policy, assessment period, systems, facilities, service components, suppliers, and exclusions. Without that boundary, a reviewer cannot tell which evidence supports which service.
Do not treat the pack as a generic spreadsheet. The standard ties evidence to concrete artifacts: a risk assessment, risk treatment decisions, security requirements, operational procedures, a trust service practice statement, terms and conditions, an information security policy, operational records, continuity planning, termination planning, and supplier controls.
Assign one pack maintainer and one accountable owner for each control family. The maintainer controls the index, versions, access, and review state; control owners attest only to records they own. The final reviewer should be able to distinguish evidence that was inspected, evidence supplied but not tested, accepted exclusions, open findings, and records unavailable for the period.
Record the trust service policy or policies supported by the , plus the trust service practice statement that describes how the TSP addresses applicable policy requirements.
Link each evidence request to an accountable owner: management approval, risk owner, security owner, operations owner, legal/compliance owner, continuity owner, and supplier owner.
Separate subscriber- or relying-party documentation from sensitive details. REQ-6.1-05X requires relevant documentation to be available as necessary to demonstrate conformance to the policy, but its note says sensitive aspects need not be disclosed.
Flag any assessment-scope question separately because EN 319 401 says independent-party assessment requirements are addressed outside this standard, with EN 319 403-1 noted for conformity assessment body requirements.
Record an explicit disposition for every requirement: applicable with evidence, applicable with an open gap, conditional and triggered, conditional and not triggered with reasons, or outside the documented service boundary.
Collect the risk and policy evidence before operational records
Start with risk evidence. EN 319 401 requires the to identify, analyse, and evaluate trust service risks; select treatment measures; document the necessary security requirements and operational procedures in the information security policy and practice statement; review and revise the assessment; and obtain management approval and residual-risk acceptance.
Next collect the policy evidence. The needs policies and practices appropriate for the trust services it provides, management approval, communication to relevant employees and external parties, a practice statement covering applicable trust service policy requirements, external-organization obligations, and a defined review process for maintaining the practice statement.
Risk evidence: risk register or assessment, risk treatment decisions, selected control measures, review history, management approval, and residual-risk acceptance.
Practice evidence: current practice statement, policy-to-practice mapping, management approval, publication or communication record, owner list, and review cadence.
Terms evidence: subscriber and relying-party terms, limits on service use, event-log retention period, relying-party information, availability undertaking, and durable publication method.
Security-policy evidence: approved information security policy, operating procedures for facilities, systems and information assets, change-notification procedure, asset inventory review trigger, and the maximum interval between configuration checks documented in the practice statement.
Build the records pack around EN 319 401 collection-of-evidence duties
Clause 7.10 is the core evidence-pack clause. It requires the to record and keep accessible all relevant information concerning data it issued and received for an appropriate period, including after the TSP's activities have ceased, for legal evidence and continuity of service.
The records pack must show both content and control: which service records exist, how current and archived records retain confidentiality and integrity, how operation records are completely and confidentially archived under disclosed business practices, and how records can be produced when required as evidence of correct service operation in legal proceedings. EN 319 401 does not set one universal retention period; the chosen period must support necessary legal evidence and match the period notified in the terms and conditions.
Create a records inventory that identifies issued and received service data, operating records, archive location, retention period, confidentiality control, integrity control, and access path.
Include disclosed business practices that explain how operation records are archived and retained.
Capture significant environmental, key-management, and clock-synchronization events with precise time.
Show that audit-log event time is synchronized with UTC at least once a day.
Document how logged events are protected from easy deletion or destruction during their required retention period, unless reliably transferred to long-term media.
Use a workflow table that keeps every evidence item reviewable
Use this operating workflow when assigning the pack. Each row should produce a named, versioned artifact for the stated service and review period.
1 | Scope and policy intake | Practice statement owner | Trust service policy list, practice statement, external-organization obligations | Does the pack match the trust service and its declared policies?
2 | Risk and control baseline | Risk and security owners | Risk assessment, risk treatment record, information security policy, operating procedures | Are selected controls tied to approved risk treatment?
3 | Subscriber and relying-party disclosures | Legal/compliance owner | Terms and conditions, limitations, event-log retention statement, relying-party instructions | Are disclosed practices consistent with evidence retention and service operation?
4 | Operational records and logs | Operations/security owner | Service records inventory, archive controls, UTC synchronization evidence, significant event logs | Can the show correct service operation and protect records during retention?
5 | Continuity, termination, and suppliers | Continuity and supplier owners | Continuity plan, backup test results, termination plan, supplier register, agreements and SLAs | Will evidence remain accessible after disaster, service cessation, or supplier change?
6 | Quality review and release | Pack maintainer and independent reviewer | completeness check, exception log, sensitivity label, release record, and approved evidence index | Is the pack ready for its named recipient and purpose, or must it be released with stated gaps?
Attach a source clause, owner, artifact name, repository location, retention rule, and next-review trigger to every evidence item.
Use change triggers for practice-statement changes, information-security-policy changes, asset inventory changes, supplier changes, incidents, and continuity-test findings.
Record exceptions and unavailable evidence as open findings with an owner and disposition; do not replace missing evidence with an assertion.
A requirement identifier ending in X marks a requirement added, changed, renumbered, or moved since V2.3.1. It is not an optionality marker.
Keep assessment claims narrow: the pack can support review and conformity-assessment preparation, but it is not itself an EN 319 401 conformity decision.
Release the pack as ready, ready with stated gaps, or not ready. Record the reviewer, date, purpose, recipient, evidence cut-off, unresolved findings, and next trigger instead of using a bare complete label.
Add continuity, termination, compliance, and supplier evidence
The pack should not stop at logs. EN 319 401 also requires evidence around continuity planning, backup resources, recovery testing, crisis management, termination, legal compliance, personal-data protection, and supply-chain controls.
Records must stay usable when the service changes, a disaster occurs, the ceases activities, or a supplier manages or archives TSP information. Treat these areas as dependencies for clause 7.10 instead of separate paperwork.
Continuity evidence: maintained continuity plan, backup plans, backup integrity checks, documented recovery tests, corrective actions from findings, and crisis-management test or review records.
Termination evidence: up-to-date termination plan, procedures for notifying subscribers, relying parties and relevant authorities, subcontractor authorization termination, and arrangements for maintaining information needed to evidence operation.
Compliance evidence: legal-requirements mapping, evidence of how applicable legal requirements are met, accessibility feasibility decisions, and personal-data protection controls.
Supplier evidence: supply-chain policy, ICT acquisition security requirements, supplier criteria, component criticality records, monitoring method, supplier agreements, SLAs or audit mechanisms, and a maintained supplier-agreement register.
A pack that describes intent but cannot show operation is incomplete. EN 319 401 repeatedly calls for documented, approved, maintained, reviewed, available, archived, tested, or recorded artifacts. If a claim cannot be tied to an artifact and review period, record the gap instead of presenting the claim as proved.
Avoid implying that a public guide, internal checklist, or exported folder is a conformity certificate. EN 319 401 provides the general policy requirements baseline; independent assessment context and assessor requirements are separate.
Does EN 319 401 prescribe a fixed evidence retention period?
No. REQ-7.10-07 requires service records to be held for a period appropriate to necessary legal evidence and notified in the 's terms and conditions. Determine the period from the service, applicable law, policy, contracts, and assessment scheme, then keep the public terms and internal retention schedule aligned.
Can sensitive evidence be withheld from subscribers and relying parties?
EN 319 401 requires the practice statement and other relevant documentation to be available as necessary to demonstrate conformance to the trust service policy, but the note to REQ-6.1-05X says sensitive aspects need not be disclosed. Keep a controlled assessor version and a suitable subscriber- or relying-party version, and record why information was restricted.
Do not cite EN 319 401 for service-specific certificate rules unless the applicable service-specific ETSI standard is also in scope.
Do not publish sensitive practice-statement details merely because some documentation must be available to subscribers and relying parties.
Do not keep record-retention periods only in an internal ticket; the standard links retention to the 's terms and conditions.
Do not leave UTC synchronization, significant key-management events, backup recovery tests, supplier agreement registers, or termination-plan evidence outside the pack.
Do not use stale private filenames, unpublished drafts, redirected private URLs, or source links without the required Sorena reference parameter.
Clauses 1, 6, and 7.9 through 7.14 support the warnings about evidence traceability, retention, logs, continuity, suppliers, and assessment boundaries.
Requirements REQ-7.10-01 through REQ-7.10-08 cover record accessibility, archive confidentiality and integrity, legal-evidence availability, event timing, daily UTC synchronization, disclosed retention, and deletion resistance.
Clauses 5 and 6 require the risk assessment, treatment and approval evidence, trust service practice statement, terms and conditions, information security policy, and related reviews.
Clauses 3.4, 5, 6, and 7.10 through 7.14 ground the workflow, explain the X change indicator, and cover records, continuity, termination, compliance, and suppliers.