Audit logs and evidence for procurement

ComplianceUpdated 2026-07-26

Procurement and audit reviewers ask for the same handful of evidence items on almost every cycle, and Arino One's audit log plus a short pack of standing documents covers all of them. Export the log for the period under review, attach the retention and consent configuration, and pair it with the DPA and sub-processor list to assemble a complete response without a back-and-forth.

What the platform records

Every instance keeps an audit log of the actions that matter to a reviewer, not just system errors:

CategoryExamples captured
Administrative actionsChannel connections/changes, user additions or role changes, retention-setting changes
Data-subject request runsErasure and export executions, with actor and the scope affected
Messaging complianceTemplate submissions and their approval status
Operational activityCampaign executions, including who ran them and when

Each entry records the actor, the timestamp, and the specific target affected — enough to reconstruct what happened without needing to interview whoever did it.

Assembling the evidence pack

A typical pack a reviewer asks for has five parts, and only one of them (the log itself) needs generating fresh each time:

  • Executed DPA with the current sub-processor list — a standing document, kept current.
  • Data-flow description and instance region — where the client's data is processed and stored.
  • Retention policy per data class, with justification — pulled from the settings described in retention policies.
  • Access-control model and the most recent user access review — who can see what, and when that was last checked.
  • Incident-response and breach-notification process — the standing procedure, not an incident-specific document.

Export the audit log for the exact period the reviewer specifies and attach it as the sixth item. Sending this pack unprompted at renewal, or ahead of a new enterprise customer's procurement stage, routinely closes the review a cycle earlier than waiting to be asked line by line.

Exporting the log

Go to Settings → Audit log, set the date range for the period under review, and export. Filter by category first if the reviewer has asked about a specific type of action (for example, only erasure runs, or only administrative changes) — a scoped export is easier for a reviewer to work through than the full log.

How this differs by instance type

What the audit log records is consistent across every instance type. What differs is who can pull the export directly and who owns producing the other four items in the pack.

Connection statusWho exports the audit logWho owns retention/consent config as evidenceWho owns the DPA and sub-processor relationship
Connected ($50/month Arino Core connection)Client, directly, or Arino on requestClient configures directly; Arino assists as part of the connectionArino, as Processor, for the Arino Core platform layer only; client separately manages any DPA obligations arising from their own Infobip/Meta accounts
UnconnectedClient, entirelyClient owns and evidences configuration end to endClient is solely responsible; there is no Arino processing relationship to cite for the underlying accounts

In every case the client is the Data Controller answering to their own customers or regulators, and, when connected, Arino is the Data Processor providing platform-level evidence within the scope Arino actually operates. Since every client owns their own Infobip account and keys regardless of connection status, be careful not to cite Arino's DPA or sub-processor list as covering activity that happens directly inside the client's own Infobip account or Meta Business Manager — that activity sits outside what Arino processes and needs its own evidence trail from the client.

Steps at a glance

  1. Identify the review typeEstablish whether the request is a customer security questionnaire, a regulator enquiry, or an internal audit, since each expects a slightly different pack.
  2. Export the audit log for the periodIn Settings → Audit log, filter by date range and export the log covering administrative actions, erasure/export runs, template submissions and campaign executions.
  3. Attach the retention and consent configurationInclude the current retention periods per data class and a description of how consent is captured and enforced, both taken from your instance settings.
  4. Attach the DPA and sub-processor listInclude the executed Data Processing Agreement with Arino and the current sub-processor list, alongside your data-flow description and instance region.
  5. Send the pack unprompted where possibleAssemble the standard pack ahead of a renewal or a new enterprise customer's procurement review, rather than waiting to be asked item by item.

Frequently asked

What does the audit log actually capture?

Administrative actions such as channel, user and retention changes; every erasure and export run with actor and scope; message-template submissions and their approval status; and campaign executions. Each entry records who took the action, when, and what it affected.

Can I export the audit log myself, or does Arino have to do it?

You export it yourself from Settings → Audit log — every client has console access regardless of connection status. If you'd prefer Arino to produce the export on your behalf, that's available on request for instances with an active $50/month Arino Core connection.

What goes in an evidence pack for a customer's security questionnaire?

Typically the executed DPA with current sub-processor list, a data-flow description and the instance's data region, the retention policy per data class with its justification, the access-control model and most recent user access review, the incident-response and breach-notification process, and the audit log export for the period under review.

Does Arino One hold any security certifications we can cite?

Cite only what has actually been issued to Arino or to the underlying infrastructure providers at the time of your review — check current status directly rather than assuming a certification exists, since none should be claimed here without verification.

Who is responsible for producing evidence — us or Arino?

The client, as Data Controller, is responsible for responding to their own customers' or regulators' evidence requests. Arino, as Data Processor, provides the platform-level evidence (audit log, DPA, sub-processor list, region) that the client needs to compile their own response.

How far back does the audit log go?

The audit log covers the life of the instance from when audit logging began recording actions; for evidence purposes, export the specific date range the reviewer has asked about rather than the entire history.

Next step

Apply this to your own deployment

This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.