Skip to main content

Guide · 7 min read

Security questions to ask any digitization provider

Ask for artefacts, not assurances. A provider should be able to produce a written chain-of-custody procedure, evidence of personnel vetting, a facility access description, a subcontractor list, encryption details for transfer and storage, a data residency statement, sample destruction certificates, audit rights and an incident response commitment with a notification timeframe. Ask us these too.

Last reviewed

Handing an archive to a scanning provider means letting strangers carry your records out of the building, open every file, and read every page. Personnel files, board papers, contracts, patient records, identity documents. There is no version of this where the risk is small, and there is no proposal that will describe it as anything other than fully secure.

So the questions below are written to be sent out unedited. They are the ones we would want asked of us, and a provider that answers them with documents rather than adjectives is telling you something a brochure cannot.

Chain of custody

  • Show me the written chain-of-custody procedure. At what point does custody formally transfer, and what is signed at that moment?
  • What is the tracking unit: box, file, or batch? Is it barcoded, and at which stages is it scanned?
  • Where do my records physically sit between stages, and how are they segregated from other clients' material?
  • What is the reconciliation report at the end, and what does it prove? Show me one from a comparable project with the client details removed.
  • If a container cannot be reconciled, what is the procedure, and who is notified within what timeframe?

Transport

  • Who collects, in what vehicle, and are they your employees or a courier?
  • Are the vehicles dedicated to document transport, and are loads sealed and tracked?
  • What insurance covers documents in transit, and what is the limit? Send me the certificate rather than the reference.
  • What happens if a collection is interrupted, or if records must be left overnight in the vehicle or at a depot?

Facility and physical access

  • Where is the production floor, and can I visit it before signing? Reluctance is itself an answer.
  • Is the scanning area access-controlled and separated from general office space? Who else can enter it?
  • What is the policy on phones, cameras and personal storage devices on the production floor, and how is it enforced rather than merely stated?
  • Are there CCTV coverage and access logs, how long is each retained, and can I see the coverage plan for the area my records would occupy?
  • How are physical records secured out of hours, and is there a separate secure area for higher-sensitivity material?

Personnel

  • What vetting is carried out before someone works on client documents, and does it differ for permanent staff, temporary staff and agency workers?
  • Are confidentiality undertakings signed by the individuals who handle records, or only by the company?
  • Are those undertakings binding after employment ends, and how is that enforced in practice?
  • How is access revoked when someone leaves, physically and in every system, and how quickly?
  • What security training do operators receive, how often, and what does it actually cover?

Subcontracting and location of work

This is the question most often answered incompletely, and the one where an incomplete answer causes the most damage later. Ask it directly and ask for it in writing.

  • Is any part of this work performed by another company, at another site, or in another country? Include indexing, verification, keying, exception handling and hosting.
  • If yes, name them, name the country, and state which activities they perform and what data they see.
  • Do subcontractors carry the same vetting, confidentiality and security obligations, and how is that verified rather than assumed?
  • Can subcontracting arrangements change during the contract without my consent? The answer should be no, with a written notification obligation.

Systems, transfer and data residency

  • How are images and index data transferred to me, and what encryption protects them in transit? Email attachments and consumer file-sharing links are not answers.
  • Is data encrypted at rest on production systems and on any working copies, and who holds the keys?
  • In which country do my images and index data reside during processing, and where are backups held? Ask about backups specifically, because they are the answer most often overlooked.
  • If a cloud service is involved, which one, in which region, and under whose account?
  • How is access to my data controlled internally? Can any operator see any client's material, or is access scoped to assigned batches?
  • Are removable media permitted on production machines, and what technical control enforces that policy?
  • What logging exists of who accessed which documents, and for how long is it kept?

Retention and destruction of the provider's copies

  • How long do you keep my images and index data after delivery and acceptance, and why?
  • What is the deletion process at the end of that period, and does it cover backups, replicas and previous versions?
  • Will you issue written confirmation of deletion, itemised to what was deleted and when?
  • For physical originals: return, storage or destruction? If destruction, is it witnessed, by what method, and what does the certificate list?

Audit rights and incident response

  • Do I have the right to audit, or to appoint an auditor? On what notice, how often, and at whose cost?
  • Will you complete my security questionnaire, and will you accept the resulting commitments as contract terms rather than as a completed form filed away?
  • What is your incident response process, and within what timeframe will you notify me of a suspected breach involving my records? A specific number belongs in the contract.
  • Who is the named contact during an incident, and what happens outside business hours?
  • Has an incident affecting client records occurred, and what changed as a result? A provider that has never had an incident of any kind is either very small, very new, or not counting carefully.
Four questions where the difference between a strong and a weak answer is obvious
QuestionEvidence to requestA weak answer sounds like
How is chain of custody maintained?The written procedure, plus a redacted reconciliation report from a real project"Our staff are very careful and everything is tracked"
Is any of this work subcontracted?A named list with country and activity, and a contractual no-change-without-consent clause"We may use partners for overflow capacity"
Where does my data reside?Country of processing, country of backup, cloud region and account owner"It is stored securely in the cloud"
What certifications do you hold?The certificate, the certified entity, the scope statement, and the last audit dateA logo on a slide, with no scope statement

Using this list without wasting everyone's time

Send the whole list at shortlist stage and read the shape of the response rather than scoring it line by line. Providers who answer in specifics, decline the questions that do not apply to them, and say plainly where a control does not exist are the ones worth continuing with. Uniform confidence across every question usually means the form was completed by someone in sales who did not consult operations.

Then do two things the questionnaire cannot do. Visit the floor, because five minutes in the room tells you more about access control and phone policy than any written answer. And put the answers into the contract, because a security questionnaire that is filed rather than incorporated has no force at all when it matters.

One closing limitation, stated plainly: no provider can eliminate this risk, and any provider that says otherwise has told you something useful about how they handle uncomfortable questions. What a good provider can do is make the controls inspectable, the obligations contractual, and the failure modes something you were told about in advance rather than something you discover.

Frequently asked questions

What is chain of custody in document scanning?

It is the documented, unbroken record of who held your records at every point from collection to return or destruction. In practice it means barcoded containers, logged handovers between stages, segregated storage, and a reconciliation report at the end showing that what was received matches what was processed and returned. Ask to see the written procedure and a sample report.

Should I let a scanning provider subcontract any of the work?

It can be entirely legitimate, particularly for indexing capacity, but only if disclosed. Ask which activities are subcontracted, to whom, in which country, and what data those people see. Require the same vetting and confidentiality obligations to flow down, and a contract clause preventing arrangements from changing without your written consent.

Does a scanning provider need to be ISO 27001 certified?

Certification is useful evidence but not a substitute for inspection. What matters more is which legal entity holds the certificate, which sites and services the scope statement covers, and when it was last audited. A provider describing its processes as aligned to a standard is being more precise than one implying a certification it does not hold.

How long should a provider keep copies of my scanned documents?

Only as long as needed to support delivery and any agreed rework or warranty window, with the period written into the contract. Ask for the deletion process explicitly, confirm it covers backups, replicas and previous versions, and request written confirmation of deletion identifying what was removed and when.

What should be in a certificate of destruction for original documents?

A description of what was destroyed at container or series level, the date, the method, the location, the individual or company that carried it out, and the authority under which it was done. Keep the certificate long after the records are gone. It is frequently the only evidence that disposal was authorised rather than accidental.

Can I audit a digitization provider's facility?

You should be able to, and the right belongs in the contract with agreed notice, frequency and cost. Even a short visit reveals things a questionnaire cannot: whether the production area is genuinely segregated, whether the phone policy is enforced, how batches are tracked between stages, and whether the operation is the size the proposal implied.

About this article

Written and reviewed by the digitization delivery team at Document Digitization Services, the specialist division of Athena Global Technologies LLC. Content is reviewed against how projects are actually run, and updated when that changes.

Tell us what is in your archive.

Send us your page or box estimate and we will come back with a scoped approach, a security plan and a written quotation.

Or call +971 55 430 1681

CallWhatsAppGet Quote