Overview
ISO 17068:2017 - Information and documentation: Trusted third party repository (TTPR) for digital records - defines requirements for a trusted third party repository to support authorized custody of clients’ digital records. The standard focuses on safeguarding provable integrity and authenticity of digital records so they can serve as reliable evidence during legally mandated retention periods in both the public and private sectors. Note: the standard limits authorized custody relationships to between the TTPR and the client.
Key topics and technical requirements
ISO 17068:2017 prescribes high-level and practical requirements covering:
- TTPR concept and trustworthiness: rationale, trust mechanisms, characteristics and essential components of a TTPR.
- Services and subservices: acquisition, repository storage, access and use, issuance (authenticity certificates), conversion, delivery/migration, disposal, and certification services (including remote certification).
- Technological requirements: secure digital record repository, transmitter/receiver, network systems, time-stamping, audit trails, access control, network security, backup and disaster recovery, and systems for certificate issuance/validation.
- Operational requirements: client management, administrator roles, network and security operations, digital records management, audit records, backup/recovery, migration and receipt handling, and client system management.
- Service agreements: Service Level Agreements (SLA) and required agreement items specifying roles, responsibilities and evidentiary assurances.
These topics emphasize preserving long-term integrity and authenticity (beyond the typical validity of digital signatures) and producing auditable evidence of custody and preservation.
Applications and who should use it
ISO 17068:2017 is relevant for organizations and professionals concerned with long-term evidentiary preservation of digital records:
- Trusted third party repository providers (TTPRs) designing or certifying custody services
- Records managers and archivists implementing retention and preservation solutions
- Legal, compliance and risk teams requiring defensible evidence retention practices
- IT architects and security teams building secure digital repositories (time-stamping, audit trails, backups)
- Auditors, regulators and evaluators assessing reliability and admissibility of digital records
Practical benefits include improved legal admissibility of records, clear custody evidence, mitigation of disputes, and standardized service agreements for retention obligations.
Related standards
ISO 17068:2017 complements records management and electronic communications guidance, notably:
- ISO 30300 / ISO 30301 / ISO 30302 - Management systems for records (fundamentals, requirements, implementation)
- UNCITRAL 2007 - United Nations Convention on the Use of Electronic Communications in International Contracts
Using ISO 17068 helps organizations and service providers establish trusted, auditable custody arrangements for digital records to meet legal and business retention requirements.