eSign Application Service Provider (ASP) Audit

An application service provider is any vendor that provides software that will contain data but is managed and operated in the vendor’s data center and is not controlled or secured by Information Technology. This includes third party software and services vendors.

Audit Requirements:

  • The communication between ASP and ESP(E-sign Service provider) should be digitally signed and encrypted.
  • Communication lines between ASP and ESP should be secured. It is strongly recommended to have leased lines or similar secure private lines between ASP and ESP. If a public network is used, a secure channel such as SSL should be deployed.
  • ASP should have a documented Information Security policy in line with security standards such as ISO 27001.
  • Compliance review of controls as per Information security policy.
  • ASPs should follow standards such as ISO 27001 to maintain Information Security.
  • Compliance to prevailing laws such as IT Act 2000 and applicable Rules and Regulations thereunder should be ensured.
  • Software to prevent malware/virus attacks may be put in place and anti-virus software installed to protect against viruses. Additional networks security controls and end point authentication schemes may be put in place.
  • Resident consent processes must be implemented to obtain consent for every transaction carried out. The user must be asked for willingness to sign it and consent form should be stored.
  • Application Security Assessment of the ASP by Cert-in empaneled auditor.
  • ASP data logging for audit purposes provisioned.
  • ASP should not delegate any obligation to external organizations or applications.
  • Refer the Stakeholders involved in eSign service like end-user, ASP, ESP, CA, e-KYC Provider, and CCA.
  • Audit checklist provided under these guidelines.
  • Demonstration and analysis of the production-ready application, with regard to eSign.
  • Verification of Production environment for its security requirements, compliance and location.


Why Xiarch ?

Xiarch is an ISO 9001:2015 | ISO 27001-2013 licensed Cyber Security Company and IT Services Company with solutions providers in Information Security like VAPT Services, Penetration Testing Services, Vulnerability Assessment Services, Among our consumers we proudly work for Government Organizations, Fortune one thousand Companies and countless start-up companies. We are additionally Value Added Partners, Authorized Re-sellers & Distributor of Leading Web Application Security Testing Tools.

We are headquartered in Delhi and have branch presence in Gurugram, Mumbai and Chennai - India

Contact our sales team @ +91 11-45510033 for further clarifications on above stated service, you can also reach us by an email at [email protected]. We’ll be great full to serve you. Happy Security.

Interested in our eSign Application Service Provider (ASP) Audit?


New Delhi - Head Office

Xiarch Solutions Private Limited

Mumbai - Branch Office

Xiarch Solutions Private Limited