BS10008-1 is the standard for Evidential weight and legal admissibility of electronically stored information (ESI) and while it’s not common, several highly specialist firms in the UK are certified to this standard enabling them to provide an additional level of assurance to their customers.
Companies running a BS10008-1 system include relevant software developers, print and scanning companies, document management firms and others.
Here we look at some key features of the standard.
It’s a Management System Standard
The first thing that makes this standard all the more usable is that it is a management system standard that follows the Annex SL structure.
This means those with experience of ISO 27001, ISO 9001 or other management systems will instantly recognise its structure and be comfortable to integrate some of the BS10008-1 requirements.
It’s similar to ISO 27001 but not the Same
While BS10008-1 covers a range of information security principles relatable to ISO 27001 the standard for information security, it is by no means a direct alignment.
There is no Annex A of controls within BS10008-1, rather the specific information security controls which include Access Rights, Encryption, Information Backup and Business Continuity; are addressed via sub clauses of clause 8 Operation.
So while there is an efficiency benefit, the two can not be directly aligned.
Authenticity and Integrity (and Availability)
Throughout the BS10008-1 standard two principles commonly occur; Authenticity and Integrity, with Availability often also referenced.
This will be familiar to those with an ISO 27001 where the three principles are Confidentiality, Integrity and Availability.
Interestingly, confidentiality is not mentioned within BS10008-1.
- Authenticity: proving the information is genuine and originates from the claimed source.
- Integrity: demonstrating it has not been altered in an unauthorised way.
- Availability: ensuring it remains accessible throughout its required retention period.
- Trustworthiness – ensuring the organisation can demonstrate confidence in the evidence produced.
The Scope of your BS10008-1 ESI system is Often Limited
While all management systems require you to define the scope of your system, when doing this for BS10008-1 you may find that the boundaries are extremely limited, covering only the staff, processes and equipment directly affecting the Electronically Stored Information (ESI).
In this way, it becomes easier to ring-fencing your secure ESI facilities while the reduction in “effective staff” also brings cost savings during the certification audits.
Ensure you carefully consider the boundary of your BS10008-1 system to ensure your system is effective.
There is More to the Policy section in 5.2
Those familiar with management system standards will recognise clause 5.2 as the usual policy statement, however BS10008-1 takes this much further and requires several specific policy statements to be made.
These include general statements:
- Information Storage Policy Statement
- ESI Transfer Policy Statement
and Information Security specific statements:
- Storage Security Policy Statement
- Transfer Security Policy Statement
- Information Classification
During an audit, these are documented statements that the auditor will expect to see.
Is BS10008-1 Still Relevant?
The current version of the standard was published in 2020 and supported by BS10008-2 (Code of practice for implementation of BS 10008-1) it remains highly relevant as organisations increasingly rely on the authenticity and integrity of their electronically stored information.
Organisations including the health service, universities, insurance companies, lawyers and others can utilise BS10008-1 in their supply chains to manage risks related to electronic information.
If you have a requirement to implement BS10008-1 within your business or have an existing ESI system that needs support, such as internal audits, we would love to talk about how Assent’s consultants can help. Contact Us!

