Regulated Customer Contract Checker
Every agreement type · Master and framework agreements

Public sector contract

Public contracts carry statutory terms the supplier cannot vary; the clock and the audit right are often the authority's own.

How the register reads it

Also calledgovernment contract, state contract
FamilyMaster and framework agreements
Normally carriesProcessing terms, a security schedule, an audit right, a liability cap.
ICT service arrangementYes: DORA Art. 28 to 30 and CPS 230 para 50 read it, and a security schedule is expected by the regimes that ask for one.

What each customer's regimes expect of it

six customers, personal data named

On a register, the regimes are pulled on by the customer's sector and country; the terms are the checklist boxes the row is read against. Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

With an EU bankPulled on: GDPR, DORA, ISO 27001, ISO 27701.
Expected on the row: processor terms, DORA terms, security schedule, audit right, breach clock.
GDPR Art. 28 · GDPR Art. 29 · GDPR Art. 32 · GDPR Art. 33 · DORA Art. 19 · DORA Art. 28 · DORA Art. 30 · ISO 27001 A.5.19 · ISO 27001 A.5.20 · ISO 27001 A.5.21 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.2.2.2 · ISO 27701 A.2.4.3 · ISO 27701 A.2.5.7 · ISO 27701 A.2.5.8 · ISO 27701 A.2.5.9 · ISO 27701 A.3.10 · ISO 27701 A.3.12
With a UK insurerPulled on: UK GDPR, ISO 27001, ISO 27701.
Expected on the row: processor terms, security schedule, audit right, breach clock.
UK GDPR Arts. 24 to 43 · GDPR Art. 28 · GDPR Art. 33 · ISO 27001 A.5.19 · ISO 27001 A.5.20 · ISO 27001 A.5.21 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.2.2.2 · ISO 27701 A.2.4.3 · ISO 27701 A.2.5.7 · ISO 27701 A.2.5.8 · ISO 27701 A.2.5.9 · ISO 27701 A.3.10 · ISO 27701 A.3.12
With a US hospitalPulled on: HIPAA, ISO 27001, ISO 27701.
Expected on the row: BAA, security schedule, audit right, breach clock.
HIPAA 164.308(a)(6)(ii) · HIPAA 164.308(b)(1) · HIPAA 164.308(b)(2) · HIPAA 164.308(b)(3) · HIPAA 164.314(a)(1) · HIPAA 164.314(a)(2)(i) · HIPAA 164.314(a)(2)(iii) · ISO 27001 A.5.19 · ISO 27001 A.5.20 · ISO 27001 A.5.21 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.2.2.2 · ISO 27701 A.2.4.3 · ISO 27701 A.2.5.7 · ISO 27701 A.2.5.8 · ISO 27701 A.2.5.9 · ISO 27701 A.3.10 · ISO 27701 A.3.12
With a California retailerPulled on: CCPA, ISO 27001, ISO 27701.
Expected on the row: processor terms, security schedule, audit right, breach clock.
CCPA CCR §7050 · CCPA §1798.100(d) · CCPA §1798.150 · ISO 27001 A.5.19 · ISO 27001 A.5.20 · ISO 27001 A.5.21 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.2.2.2 · ISO 27701 A.2.4.3 · ISO 27701 A.2.5.7 · ISO 27701 A.2.5.8 · ISO 27701 A.2.5.9 · ISO 27701 A.3.10 · ISO 27701 A.3.12
With an Australian superannuation fundPulled on: CPS 230, CPS 234, ISO 27001, ISO 27701.
Expected on the row: CPS 230 terms, security schedule, audit right, breach clock.
CPS 230 para 40 · CPS 230 para 45 · CPS 230 para 50 · CPS 230 P33 · CPS 230 P42 · CPS 230 P59 · CPS 234 para 16 · CPS 234 para 27 · CPS 234 para 35 · CPS 234 P22 · ISO 27001 A.5.19 · ISO 27001 A.5.20 · ISO 27001 A.5.21 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.2.2.2 · ISO 27701 A.2.4.3 · ISO 27701 A.2.5.7 · ISO 27701 A.2.5.8 · ISO 27701 A.2.5.9 · ISO 27701 A.3.10 · ISO 27701 A.3.12
With an EU energy utilityPulled on: GDPR, NIS2, ISO 27001, ISO 27701.
Expected on the row: processor terms, security schedule, audit right, breach clock.
GDPR Art. 28 · GDPR Art. 29 · GDPR Art. 32 · GDPR Art. 33 · NIS2 Art. 21(2)(d) · NIS2 Art. 21(3) · NIS2 Art. 23(1) · NIS2 Art. 23(4)(a) · NIS2 Art. 23(4)(b) · ISO 27001 A.5.19 · ISO 27001 A.5.20 · ISO 27001 A.5.21 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.2.2.2 · ISO 27701 A.2.4.3 · ISO 27701 A.2.5.7 · ISO 27701 A.2.5.8 · ISO 27701 A.2.5.9 · ISO 27701 A.3.10 · ISO 27701 A.3.12

The clauses, quoted

46 across the six customers
CCPA CCR §7050 Service Provider and Contractor Obligations

A service provider or contractor shall only process PI on behalf of a business for a business purpose specified in the written contract. It shall not retain, use, or disclose PI for any purpose other than the business purpose, sell or share PI, or combine PI received from one business with PI received from another business or from its own interactions with consumers (with limit...

Evidence an auditor accepts: Service provider acknowledgement of restrictions in contract; Subcontractor flowdown agreements; Consumer request assistance procedure (forwarding requests, providing data extracts)
Where it usually falls short: Service provider commingles client data
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors

A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection...

Evidence an auditor accepts: Service provider/contractor agreements containing all required CCPA clauses; Third party data sharing agreements; Vendor inventory classifying each recipient (service provider, contractor, third party)
Where it usually falls short: Legacy vendor contracts missing CPRA-required clauses
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.150 Private Right of Action for Data Breaches

A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring a civil action for statutory damages of USD 100 to 750 per consumer per inciden...

Evidence an auditor accepts: Reasonable security program documentation (encryption, access control, monitoring); Incident response plan including 30-day cure handling; Breach notification procedure
Where it usually falls short: Encryption not applied to sensitive elements
CCPA/CPRA and its regulations in The Art of Service standards library
CPS 230 para 40 Mandatory Minimum Classification of Material Service Providers

Unless it can justify otherwise the entity must classify as material service providers at least those supplying credit assessment, funding and liquidity management and mortgage brokerage for an ADI, underwriting, claims management, insurance brokerage and reinsurance for an insurer, fund administration, custodial services, investment management and arrangements with promoters a...

Evidence an auditor accepts: Classification decisions against the mandatory minimum list; Documented justification for any exclusion; Entity type specific coverage evidence
Where it usually falls short: Internal audit or risk management providers not classified as material
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 para 45 APRA Access Provisions in Formal Agreements

Formal agreements must also give APRA access to documentation, data and other information relating to the service, give APRA the right to conduct an on site visit to the provider, and secure the provider agreement not to impede APRA in performing its duties as prudential regulator.

Evidence an auditor accepts: Contract clauses granting APRA access, on site visit rights and non impedance; Clause coverage review across all material arrangements; Remediation plans for legacy agreements lacking the clauses
Where it usually falls short: Legacy contracts never uplifted
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 para 50 Formal Agreement Content for Material Arrangements

Every material arrangement must be covered by a formal legally binding agreement specifying the services and service levels, the rights, responsibilities and expectations of each party including asset ownership, data ownership and control, dispute resolution, audit access, liability and indemnity, provisions securing the entity legal and compliance obligations, notification of ...

Evidence an auditor accepts: Executed agreements for every material arrangement; Clause mapping against the required minimum content; Sub contractor notification and liability clauses
Where it usually falls short: Verbal or intra group arrangements with no formal agreement
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 P33 APRA Notification of Operational Risk Incidents within 72 Hours

The entity must notify APRA as soon as possible and no later than 72 hours after becoming aware of an operational risk incident it determines is likely to have a material financial impact or a material impact on its ability to maintain critical operations.

Evidence an auditor accepts: Notification records with awareness and submission timestamps; Materiality determination criteria and decision records; Escalation path from the incident register to the notification decision
Where it usually falls short: Clock started at incident classification rather than awareness
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 P42 APRA Notification of Disruption Outside Tolerance within 24 Hours

The entity must notify APRA as soon as possible and no later than 24 hours after suffering a disruption to a critical operation outside tolerance, covering the nature of the disruption, the action taken, the likely impact on business operations and the timeframe for returning to normal operations.

Evidence an auditor accepts: Notification records with disruption and submission timestamps; Evidence the notification covered all four required content elements; Tolerance breach detection records feeding the notification
Where it usually falls short: Tolerance breach detected late so the 24 hour clock is missed
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 P59 APRA Notification of Service Agreements and Offshoring

The entity must notify APRA as soon as possible and no more than 20 business days after entering into or materially changing an agreement for a service it relies on to undertake a critical operation, and must notify APRA before entering into any material offshoring arrangement or when a significant change to such an arrangement is proposed, including where data or personnel rel...

Evidence an auditor accepts: Notification records with execution and submission dates; Offshoring notifications evidencing they preceded execution; Identification of arrangements where data or personnel move offshore
Where it usually falls short: Offshoring notified after signature instead of before
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 234 para 16 Assessment of Related Party and Third Party Capability

Where a related party or third party manages information assets, the entity must assess that party information security capability in proportion to the consequences of an incident affecting those assets.

Evidence an auditor accepts: Third party and related party security capability assessments; Register of parties managing information assets; Consequence rating driving assessment depth
Where it usually falls short: Assessment limited to outsourced material business activities
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 27 Internal Audit Assessment of Third Party Control Assurance

Internal audit must assess the control assurance provided by a related party or third party where an incident affecting the assets could materially affect the entity or its customers and internal audit intends to rely on that assurance.

Evidence an auditor accepts: Reliance decisions recorded with supporting assessment; Assessment of the third party assurance reports relied upon; Materiality determination for each reliance
Where it usually falls short: Third party assurance accepted without assessment
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 para 35 APRA Notification of Material Incidents within 72 Hours

APRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.

Evidence an auditor accepts: Notification records with awareness and submission timestamps; Materiality assessment criteria and decision records; Register of notifications made to other regulators
Where it usually falls short: Clock started at incident confirmation rather than awareness
APRA CPS 234 Information Security in The Art of Service standards library
CPS 234 P22 Evaluation of Third Party Control Design

Where a related party or third party manages the entity information assets, the entity must evaluate the design of that party controls protecting those assets.

Evidence an auditor accepts: Design evaluations of third party control sets; Assurance reports reviewed with entity conclusions recorded; Scope evidence covering all parties managing information assets
Where it usually falls short: Reliance on a certificate with no design evaluation
APRA CPS 234 Information Security in The Art of Service standards library
DORA Art. 19 Reporting of major ICT-related incidents

Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.

Evidence an auditor accepts: Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines
Where it usually falls short: Late or missing major-incident reporting
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 28 ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Evidence an auditor accepts: A Register of Information of ICT third-party arrangements reported to the competent authority; Pre-contract risk assessment records
Where it usually falls short: No Register of Information
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 30 Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting crit...

Evidence an auditor accepts: ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security); Enhanced provisions for critical/important-function services
Where it usually falls short: Contracts missing audit/access, termination or exit provisions
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must ...

Evidence an auditor accepts: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract
Where it usually falls short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 29 Processing under the authority of the controller or processor

The processor, and any person acting under the authority of the controller or of the processor who has access to personal data, must not process that data except on instructions from the controller, unless required to do so by Union or Member State law.

Evidence an auditor accepts: The documented instructions issued to each processor, and the mechanism by which they are kept current; Employment or contract terms binding staff and contractors to process personal data only as instructed; Access controls that make the technical scope of access match the instructions actually given
Where it usually falls short: Instructions existing only as the original contract, never updated as the processing changed over years of service
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 32 Security of processing

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the...

Evidence an auditor accepts: The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation; Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate; Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome
Where it usually falls short: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 33 Notification of a personal data breach to the supervisory authority

On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor ...

Evidence an auditor accepts: The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each; The awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment; Notifications as submitted, checked against the four content elements Article 33(3) requires
Where it usually falls short: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
HIPAA 164.308(a)(6)(ii) Response and Reporting (Required)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

Evidence an auditor accepts: Incident ticket log; Post-incident reports; Breach risk assessments per 164.402
Where it usually falls short: Incident closure without root cause
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.

Evidence an auditor accepts: BA inventory; Executed BAAs; Vendor risk assessments
Where it usually falls short: BA inventory incomplete
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(2) Subcontractor Arrangements

A business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with 164.314(a), that the subcontractor will appropriately safeguard the information.

Evidence an auditor accepts: Inventory of subcontractors that create, receive, maintain or transmit electronic protected health information on the business associate's behalf; Executed written agreements with each subcontractor containing the satisfactory assurances required; Evidence the assurances obtained are equivalent to those the business associate provided to the covered entity
Where it usually falls short: Assurances obtained from the immediate subcontractor while its own downstream subcontractors handling the same data are unaddressed
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(3) Written Contract or Other Arrangement

Document the satisfactory assurances required by paragraph (b)(1) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of 164.314(a).

Evidence an auditor accepts: Standard BAA template aligned to 164.314(a); Executed BAAs stored in contract repository; Alternative arrangement documentation where BA is a government entity
Where it usually falls short: BAAs missing required Security Rule clauses
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)

The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.

Evidence an auditor accepts: BAA template addressing all required 164.314(a)(2) elements; Government arrangement documentation where applicable; Special arrangement records (group health plan, plan sponsor)
Where it usually falls short: Older BAAs missing post-Omnibus requirements
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(i) Business Associate Contract Required Provisions

The contract between a covered entity and a business associate must provide that the business associate will comply with the applicable Security Rule requirements, ensure subcontractors comply, report security incidents including breaches, and authorize termination by the covered entity if the business associate violates a material term.

Evidence an auditor accepts: BAA template with required clauses traceable to 164.314(a)(2)(i); Incident reporting requirements and SLAs; Subcontractor flow-down clause
Where it usually falls short: Incident reporting SLA missing or longer than reasonable
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(iii) Business Associate Contracts with Subcontractors

The requirements of paragraph (a)(2)(i) of this section apply to the contract or other arrangement between a business associate and a subcontractor required by 164.308(b)(4) in the same manner as such requirements apply to contracts or other arrangements between a covered entity and business associate.

Evidence an auditor accepts: Subcontractor BAA template aligned to 164.314(a)(2)(i); Executed subcontractor BAAs; Subcontractor inventory with ePHI scope
Where it usually falls short: Subcontractor inventory incomplete
HIPAA Security Rule in The Art of Service standards library
ISO 27001 A.5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: Supplier risk assessment; Contractual security requirements; Supplier security monitoring
Where it usually falls short: Treating all suppliers as low risk
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: Contract security clauses; Supplier risk assessment; Security incident reporting
Where it usually falls short: missing explicit security clauses
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: Supplier security requirements; Contractual security clauses; Supply chain risk assessments
Where it usually falls short: Treating supplier security as one-off check
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

Evidence an auditor accepts: Incident response plan; Role assignment matrix; Training and awareness records
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Evidence an auditor accepts: Legal register; Contractual obligations; Regulatory filing records
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Evidence an auditor accepts: Privacy policy; Data inventory; Processing agreements
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27701 A.2.2.2 Customer agreement

Where relevant, the contract to process personal data must address the organization's role in assisting the customer with the customer's own obligations, taking account of the nature of processing and the information available to it, covering as relevant privacy by design and by default, achieving security of processing, notifying breaches to a supervisory authority and to cust...

Evidence an auditor accepts: Customer contracts carrying the assistance provisions relevant to the engagement; Where the jurisdiction requires it, contract terms stating subject matter, duration, nature, purpose, data types and categories of individuals; Operational capability behind each assistance commitment, not the commitment alone
Where it usually falls short: Assistance promised in contract with no operational capability behind it, discovered only when the customer first asks
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.4.3 Return, transfer or disposal of PII

The organization must provide the ability to return, transfer or dispose of personal data securely and must make its policy available to the customer, managing the capability securely whether the outcome is return to the customer, transfer to another organization or controller, deletion, destruction, de-identification or archiving, providing the assurance the customer needs tha...

Evidence an auditor accepts: Documented return, transfer and disposal policy, made available to customers; Assurance evidence that erasure reaches backups, continuity copies and subcontractors; Stated post termination retention period before disposal, with its rationale
Where it usually falls short: Erasure certified for primary systems while backups retain the data for the full backup cycle, which the customer is not told
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.7 Disclosure of subcontractors used to process PII

The organization must disclose to the customer any use of subcontractors to process personal data before that use, with provisions included in the customer contract, disclosing that subcontracting is used and the names of the relevant subcontractors, the countries and international organizations to which they can transfer data, and the means by which they are obliged to meet or...

Evidence an auditor accepts: Current subcontractor list with names, the countries they can transfer to, and how their obligations are secured; Evidence of disclosure before use, not after; Contract provisions covering subcontractor disclosure
Where it usually falls short: Subcontractors disclosed only on request, with customers never told the information exists
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.8 Engagement of a subcontractor to process PII

The organization must engage a subcontractor to process personal data only according to the customer contract, obtaining written authorization from the customer before the subcontractor processes the data, whether through appropriate clauses in the customer contract or a specific one off agreement, holding a written contract with every such subcontractor that addresses implemen...

Evidence an auditor accepts: Written customer authorization for each subcontractor, whether general or specific; Written contract with every subcontractor carrying the processor control obligations; Justification for any processor control not required of a subcontractor
Where it usually falls short: Subcontractor engaged on the strength of a general authorization that does not in fact cover it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.2.5.9 Change of subcontractor to process PII

Where it holds a general written authorization, the organization must inform the customer of any intended change involving the addition or replacement of a subcontractor that processes personal data, giving the customer the opportunity to object, and where it changes the subcontractor carrying out some or all of the processing, written authorization from the customer is require...

Evidence an auditor accepts: Change notification procedure with the notice period and the objection route; Records of notifications given and objections received, with outcomes; Evidence that new subcontractors did not begin processing before authorization
Where it usually falls short: Notification given at the point of change or after, so the objection right is theoretical
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.10 Addressing information security within supplier agreements

Agreements with suppliers shall specify whether PII is processed and the minimum technical and organizational measures the supplier must meet for the organization to meet its information security and PII protection obligations, shall clearly allocate responsibilities between the organization, its partners, suppliers and applicable third parties taking account of the type of PII...

Evidence an auditor accepts: Supplier agreements stating whether PII is processed and the minimum measures required; Responsibility allocation clauses by type of PII; Audit or assurance clause and the independent evidence obtained under it
Where it usually falls short: Supplier contracts silent on PII while the supplier processes it
ISO/IEC 27701:2025 in The Art of Service standards library
ISO 27701 A.3.12 Response to information security incidents

For a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notif...

Evidence an auditor accepts: Breach determination records for incidents involving PII; Breach register carrying every field the standard names; Notifications made to authorities, PII principals or customers with timing against the legal limit
Where it usually falls short: Incidents closed as security events with no PII breach determination
ISO/IEC 27701:2025 in The Art of Service standards library
NIS2 Art. 21(2)(d) Supply chain security, covering the relationship with each direct supplier and service provider

The Directive scopes this deliberately at direct suppliers and service providers, which makes the first artefact an inventory of who those parties are and which of them touch the network and information systems behind the service. From there the entity has to manage the security-related aspects of each relationship: what the supplier may access, what security obligations bind i...

Evidence an auditor accepts: Inventory of direct suppliers and service providers, flagged for access to in-scope systems; Risk assessment per supplier proportionate to the access and criticality involved; Contractual security clauses, including incident notification obligations and audit or assurance rights
Where it usually falls short: Inventory built from the procurement system, so shadow and free-tier services are missing
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 21(3) Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

Deciding what supply chain measures are appropriate is not left to general judgement. The entity has to take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of those parties' products and cybersecurity practices including their secure development procedures. Separately, it must take into account the results of the ...

Evidence an auditor accepts: Per-supplier assessment records that address that supplier's own vulnerabilities and secure development practice; A watch process for Union coordinated supply chain risk assessments and the outputs it has captured; Decision records showing how each relevant coordinated assessment was reflected in supplier measures
Where it usually falls short: Supplier assessment reduced to a questionnaire score with no view of that supplier's actual weaknesses
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(1) Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

The core reporting duty attaches to any incident with a significant impact on the provision of the entity's services. Article 23(3) fixes the threshold: an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, or if it has affected or is capable of affecting other natural or legal person...

Evidence an auditor accepts: The documented significance test, expressed against the Article 23(3) limbs including capable of causing; The determination record for each candidate incident, including reasoned decisions not to report; Notifications as submitted, with timestamps, and the identity of the receiving CSIRT or authority
Where it usually falls short: Threshold applied only to realised impact, so contained incidents capable of severe disruption go unreported
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(a) Submit an early warning within 24 hours of becoming aware of a significant incident

The first stage of the layered reporting regime falls due without undue delay and in any event within 24 hours of becoming aware of the significant incident. The early warning is deliberately light: where applicable it indicates whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact. It is not a full assess...

Evidence an auditor accepts: The definition of becoming aware and the evidence trail that fixes that moment per incident; Submitted early warnings with timestamps, measured against the 24-hour limit; Out-of-hours submission capability, including named authorised submitters and their credentials
Where it usually falls short: Awareness treated as the moment of executive briefing rather than of qualified detection
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(b) Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise

Within 72 hours of becoming aware, the entity updates the early warning and provides an initial assessment of the significant incident covering its severity and impact, together with indicators of compromise where those are available. The 72 hours runs from awareness, not from the early warning, so the two clocks start together. Trust service providers are held to a shorter dea...

Evidence an auditor accepts: Submitted notifications with timestamps measured from the awareness moment; The initial severity and impact assessment as submitted, and the basis for it; Indicators of compromise shared, and the telemetry and tooling they were derived from
Where it usually falls short: 72 hours counted from the early warning rather than from awareness
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
UK GDPR Arts. 24 to 43 Controller and Processor (Articles 24-43)

Per UK GDPR Articles 24-43: controller + processor + DPO + RoPA + DPIA + Privacy by Design + Records + breach notification.

Evidence an auditor accepts: UK GDPR evidence for UKGDPRREG-3
Where it usually falls short: DPO + DPIA + ICO partial
UK GDPR (summary of the articles held) in The Art of Service standards library

Read every agreement on your list

Paste the list of customer agreements and each one comes back with the regimes its customer pulls on, the terms ticked or open, the clock, the audit right and the renewal. Eight agreements free, no account.

Check my contract list

Public framework agreement and call-off · AI services and model licence