How should teams handle Audit Rights under ISO/IEC 27017?
ISO/IEC 27017:2015 does not create an unrestricted on-site audit right. It says customers should request documented evidence for provider claims. When individual audits are impractical or could increase security risk, the provider should make independent evidence available; a sufficiently transparent independent audit selected by the provider should normally meet the customer's review interest. If independent audit is impractical, the provider should disclose its self-assessment process and results.
Put the enforceable assurance route in the agreement before service approval. Define the report or certification, covered entities and services, locations, period, exclusions, customer controls, access to supporting material, treatment of exceptions, bridge evidence, remediation follow-up, confidentiality limits, cost, notice, and escalation when evidence is insufficient. If binding law, regulation, or an existing customer commitment requires access that the provider will not supply, negotiate a compliant route or do not approve that use; risk acceptance cannot remove the underlying duty.
- Name the accountable owner and reviewer for Audit Rights.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate if the offered assurance cannot support a legal, regulatory, contractual, or risk requirement; ISO guidance does not override those requirements.
Primary ISO listing for cloud-service security control guidance.
The identical 2015 recommendation describes independent evidence and self-assessment when individual customer audits are impractical; it does not state an unrestricted customer audit right.