GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-020 Independent Security Review

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

An independent assessment report on the information security posture exists for each defined interval and after each significant change to the estate or the operating model. The report names the assessor, who is either an internal audit function separate from the security function or an external third party. It carries a management response recording, for each finding, an owner and a target date.

Rationale

Self-assessment by the team that built the controls cannot give management or a customer the assurance they are asking for, because the blind spots are shared. Independence is the property under test, so the report names the assessor and the reporting line that keeps them clear of the function assessed. GOV-011 is the internal audit cycle and GOV-021 the policy that governs both; independent assessment of an AI system specifically is AIG-008.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredrole duty

The independent assessment is what a financial entity reads under Art. 28(4), point (d) and RTS 2024/1773 Art. 6(3). Art. 8(3) then bars it from relying on that report alone over time, so the report is the entry ticket rather than the whole answer.

HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(8) has a second trigger the periodic audit does not answer: an environmental or operational change affecting the security of the data. GOV-020's change-driven independent assessment is what carries it.

NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 2.3.2 defines independence by line of authority rather than by employment and requires the reviewers to hold appropriate audit competence, with alternative impartiality measures where the entity is too small to separate the line. Point 2.3.3 routes results to the management bodies and resolves each one to corrective action or to a residual risk accepted against the entity risk acceptance criteria.

Framework Mappings (21)

A&A-02Independent Assessmentsfull
A&A-03Risk Based Planning Assessmentpartial
A&A-02Independent Assessmentsfull
A&A-03Risk Based Planning Assessmentpartial
DORA-Art.28.4Assessments before entering a contractual arrangementinformative
DORA-Art.28.5Information security standards of the ICT third-party service providerinformative
DORA-Art.28.6Exercise of access, inspection and audit rightsinformative
DORA-RTS-2024/1773-Art.6.1Due diligence assessment of the prospective providerinformative
DORA-RTS-2024/1773-Art.6.3Assurance elements used in due diligenceinformative
COP-S-7.4External reportsinformative
HIPAA-164.306.eMaintenanceinformative
HIPAA-164.308.a.8Evaluationfull
5.35Independent review of information securityfull
NIS2-CIR-2.3Independent Review of Information and Network Securitypartial
NIS2-CIR-7Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measuresinformative
CA-1Policy and Proceduresinformative
CA-2Control Assessmentsinformative
CA-2(1)Control Assessments | Independent Assessorsfull
CA-7(1)Continuous Monitoring | Independent Assessmentfull
GV-3.2-001Human-AI Configuration Roles | GV-3.2-001informative
MEASURE 1.3Independent AI Risk Assessmentinformative

Evidence (2)

reportdocumentmanual

Third-party assessment report or external audit report providing independent assurance of the organisation's information security controls.

Example: SOC 2 Type II report, ISO 27001 audit report, penetration test report, or third-party security assessment report (PDF), issued within the last 12 months by an accredited or qualified independent assessor.

Test: Request the most recent independent security assessment report. Verify: (1) the assessor is independent of the security function being assessed (different team or external firm), (2) the report is dated within the defined assessment interval, (3) scope covers the organisation's production environment and key controls, (4) findings are addressed to management and include a management response.

recorddocumentmanual

Management response record showing findings from the independent review are tracked to remediation.

Example: Management letter responses (PDF) or remediation tracker (Jira / GRC platform) linked to the assessment report findings, with named owners and target dates.

Test: Request the management response or remediation tracker for the most recent independent assessment. Verify: (1) all findings from the report are represented, (2) each finding has a named owner and target remediation date, (3) critical or high findings are assigned the shortest target dates, (4) closed items have documented evidence of remediation.

Questions (2)

boolean

Does your organisation undergo independent security assessments (internal audit teams independent of the security function, or external third-party assessors) at defined intervals?

The assessor must be independent of the function being assessed. Reports should be dated within the defined interval and addressed to management.

select

What form does your most recent independent security assessment take?

Third-party SOC 2 Type II auditISO 27001 certification auditExternal penetration testThird-party security risk assessmentInternal audit by a team independent of the security functionNo independent assessment has been conducted

A SOC 2 Type II report or ISO 27001 audit provides the strongest third-party assurance for enterprise customers. All options above should include a management response to findings.