What should ISO/IEC 27018 audit evidence prove?
ISO/IEC 27018 audit evidence should let a customer identify the edition, audited entity and service, processor scope, criteria, audit date or period, sampling method, exclusions, findings, corrective-action status, report restrictions, and who performed the work. The customer then compares that scope with its own service, processing, locations, subprocessors, contract, and legal duties.
The 2019 edition recognizes independent evidence as a practical response when individual customer audits are impractical or would increase security risk in a multi-tenant cloud. It says a relevant independent audit selected by the processor should normally be acceptable only when sufficient transparency is provided. That guidance does not erase contractual audit rights or binding legal requirements.
- Match the customer service, processing locations, and subprocessors to the assurance boundary.
- Confirm whether the evidence is a certification, attestation, audit report, or provider assertion; the labels are not interchangeable.
- Record gaps between the assurance scope and the customer's contract or legal requirements.
Primary ISO listing for the 2025 edition of ISO/IEC 27018.
ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.