Sovereignty programmes produce a great deal of paper and very little evidence. An architecture diagram, a vendor attestation, a hosting page screenshot and a policy statement are all assertions about a state of affairs; an auditor asking whether personal data left the jurisdiction in October wants something that was generated by the system at the time and could not have been written afterwards. That distinction is where most sovereignty reviews come apart, and it is entirely avoidable.
A vendor attestation tells you what the vendor believes. An access log tells you what happened, and only one of those survives contact with an auditor
Here is the evidence that actually holds up, and how to arrange for it to exist before someone asks.
The four artefacts that count
Access logs showing who reached the data, from where. Not the theoretical access model — the record of actual administrative sessions, with source and identity. This is the single most persuasive artefact and the one most often unavailable, because support access frequently occurs through a vendor-side channel the customer cannot see. Key custody records. Who holds the encryption keys, where they are generated, who can authorise use, and evidence of the rotation history. If the operator cannot decrypt without your cooperation, that fact is demonstrable rather than asserted, and it carries more weight than any location claim. Processing location records for the actual workload, including inference. Region configuration plus a contemporaneous statement of where requests were served. Vendors that cannot produce this are telling you something. Support routing evidence. Where escalations went, which entity handled them, and whether data was viewed in the process. Tier-three support is the most common route by which data leaves a jurisdiction that was carefully arranged to keep it in.
What auditors reject, and why
Policies and architecture documents, because they describe intent. Vendor marketing and compliance portals, because they describe a general product rather than your tenancy. Point-in-time screenshots, because they prove a configuration existed on the day it was captured. And self-assessment questionnaires completed by the vendor, which are hearsay with a logo. The common failure is not that organisations have no evidence. It is that they have the wrong kind and discover the difference in the fieldwork.
| Question | Record to seek |
|---|---|
| Who accessed the tenancy? | Administrative identity and session records |
| Who could use keys? | Custody, authorisation and rotation records |
| Where was work processed? | Workload-specific processing records |
| Where did support go? | Escalation and data-access routing records |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Arranging for the evidence to exist
Three things, all of which must be done before the period being examined rather than after. Contract for log access, specifically including vendor-side administrative and support access to your tenancy. Most agreements do not include this and most vendors will provide something if asked at renewal. Retain the logs yourself for the period your auditor will examine, because provider retention defaults are usually shorter than an audit cycle. And record the decisions — which data classes are localised, why, who approved it — with dates. Auditors accept a documented judgement far more readily than a perfect architecture with no reasoning behind it.
Practical Guidance for Sovereignty Evidence Review
- Contract for access to vendor-side administrative logs.
- Retain logs yourself beyond the provider's default period.
- Document key custody including generation and rotation.
- Capture inference location, not just storage region.
- Get support routing in writing for tier-three escalation.
- Date your decisions and record who approved them.
- Run a dry-run request before the real audit.
- Stop relying on attestations as primary evidence.
The Regional Angle
The first point is that Gulf supervisory practice tends to want a named individual behind the evidence, not just the evidence. Financial and sectoral regulators in Saudi Arabia, the Emirates and Qatar are accustomed to asking who is accountable for an outsourcing arrangement and expecting a person rather than a function, which means your evidence pack should carry the approval trail — who decided this data class could be processed here, on what date, under what authority. Organisations that produce technically excellent logs with no named approver find the conversation continues longer than they expected. The second concerns the multi-jurisdiction reality of regional groups and what it does to an evidence pack. A group operating across several Gulf states will face separate enquiries from separate authorities, each about its own country's data, and an evidence set organised by system rather than by jurisdiction cannot answer any of them cleanly. Organise the records so that you can answer, for one country at a time, where that country's data was processed and who touched it. That is a data model decision about your logging, and it is much cheaper to make at the start than to reconstruct during a supervisory enquiry. The third is the one regional organisations are least prepared for: the administrator is frequently a third party. Where a systems integrator or managed service provider operates the environment — which is the norm here — the access logs that matter are generated inside that partner's operation, often by engineers located outside the jurisdiction entirely. Unless the contract requires those logs to be delivered to you and retained, your evidence has a gap exactly where the interesting activity happened. Fix that at the next statement of work rather than at the next audit.
The objection worth taking seriously
The strongest objection is that this is compliance for its own sake. Nobody's data is safer because the logs were retained for twelve months rather than three, and the effort of contracting for vendor-side log access, building a retention pipeline and organising records by jurisdiction is substantial work that improves documentation rather than security. Organisations that spend it are generally the ones whose actual risk is already low, while the real exposures — unpatched systems, over-privileged accounts, weak identity — go unfunded because the sovereignty programme absorbed the budget. That trade-off is real and the prioritisation critique is often right. The response is that two of these artefacts are not documentation, they are detection. Access logs showing who reached your data from where, and support routing records, are the only way you would ever discover that administrative access to your environment is being exercised from somewhere you did not expect — which is a security finding, not a compliance one, and one several organisations have made while assembling exactly this evidence. Key custody records are similarly load-bearing: the exercise of documenting them is how most organisations discover that the operator can decrypt after all. Build these because they tell you things you do not currently know. That they also satisfy an auditor is a convenient second use.
Common Questions
Are vendor compliance reports useless?
No, but they evidence the vendor's general control environment rather than your tenancy. They support your position; they cannot be the whole of it.
How long should we retain logs?
Longer than your audit cycle, which almost always means longer than the provider's default. Decide this before you need the earlier months.
What if the vendor will not provide access logs?
Record the refusal and its date. That is itself evidence, and it usually changes at renewal when the request is made commercially rather than technically.
What should we expect over the next twelve months?
Expect supervisory enquiries in this region to move from policy review toward evidence requests. Expect inference location to enter the standard question set. Expect providers to improve customer-visible administrative access logging under pressure. And expect third-party operator access to be the gap most organisations find first.
Sovereignty Evidence Review — we make sure the records exist before the period an auditor will ask about, not after.
