Download Google Cloud compliance documents

Audit Manager lets you download the most recent Google Cloud compliance documents that third-party auditors create when they audit our environment. You can use these documents to better understand how Google addresses its responsibilities to meet the requirements of various regulatory frameworks. The documents include Google's business continuity plan (BCP), disaster recovery testing (DiRT) report, audit reports, certifications, statements of applicability, and vendor risk assessments.

Examples of regulatory frameworks include the following:

  • Cloud Computing Compliance Criteria Catalogue (C5:2020)
  • Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) Registry
  • Federal Risk and Authorization Management Program (FedRAMP) Customer Responsibility Matrix (CRM)
  • Information Security Registered Assessors Program (IRAP), Protected level
  • International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) 27001:2022 and 27018:2019
  • Portugal Gabinete Nacional de Segurança (GNS)
  • Spain Esquema Nacional de Seguridad (ENS)

Downloads are in ZIP format. The ZIP file that's downloaded typically contains one or more PDFs.

Before you begin

To get the permissions that you need to download compliance documents, ask your administrator to grant you the Audit Manager Auditor (roles/auditmanager.auditor) IAM role on your organization. For more information about granting roles, see Manage access to projects, folders, and organizations.

You might also be able to get the required permissions through custom roles or other predefined roles.

Download compliance documents

Complete the following actions to download the Google Cloud compliance documents:

  1. In the Google Cloud console, go to the Audit Manager page.

    Go to Audit Manager

  2. Click Compliance Reports.

  3. Select the documents that you want to download.

  4. Click Downloads.

Audit Manager downloads the documents in a ZIP file to your device. You can extract the PDFs to view the documents.

What's next