ISO 27566 Clause 9 - Audit and Testing Requirements
Conduct regular independent audits and testing of age assurance systems covering accuracy, security, privacy, bias, and governance with documented remediation of findings
Where this comes from
Provision: Clause 9 - Audit and Testing Requirements
Instrument: ISO/IEC 27566-1:2025
Citation: ISO/IEC 27566-1:2025, Age assurance systems -- Framework, Clause 9: Audit and Testing Requirements
Text version: ISO/IEC 27566-1:2025
Who it applies to
…unless:
- Age verification method: No age verification
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Compliance-relevant events are logged automatically with timestamp, actor/subject, and event type
- Logs are append-only / tamper-evident and retained for the required period
- Logs are retrievable and filterable for a regulator request or incident review
- Logs exclude unnecessary sensitive payloads (data minimization in logging)
- A sample export of records for a chosen date range is produced and reviewed
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.