How should teams handle Provider Evidence under ISO/IEC 27017?
List the provider claims that affect service approval, such as implementation of named controls, compliance with applicable contractual or legal requirements, data location, isolation, backup, incident handling, or continuity. Request a document that substantiates each claim. Clause 18.1.1 says the provider should identify the jurisdictions governing the service and provide current compliance evidence when requested; the customer should consider both provider and customer jurisdictions.
Apply the clause 18.2.1 evidence sequence. A relevant independent audit selected by the provider is normally acceptable when it gives sufficient transparency and individual customer audits are impractical or could increase security risk. If an independent audit is impractical, the provider should conduct a self-assessment and disclose its process and results. Certification is one possible form of evidence, not the only route and not proof beyond its stated scope.
Check the provider legal entity, named services and tiers, locations, assessment criteria, control period or point-in-time date, exclusions, upstream or subservice organizations, auditor opinion, exceptions, and complementary customer controls. For any gap between the evidence period and the current decision, ask what later events or changes the provider attests to and record the limits. A certificate, audit report, self-assessment, or bridge letter supports only the claims its wording and scope cover.
- Name the service owner, supplier-assurance reviewer, control specialists, owner of each complementary customer control, and authorized risk acceptor.
- Record each provider claim, required evidence, document scope and date, review result, limitation, exception, customer action, approval date, evidence location, and next reassessment trigger.
- Reject or escalate evidence that omits the service, period, material exceptions, or customer controls needed for the decision.
ISO lists edition 1, published in December 2015, as guidance for cloud service customers and providers and identifies a revision under development.
The identical 2015 recommendation says customers should request documented evidence for provider claims and describes independent audit and self-assessment routes when individual audits are impractical.