Architecture decision records for audits
An auditor will ask why production uses a particular region, key type or backup schedule. An architecture decision record answers with the reasoning, the date and who approved it.
An architecture decision record (ADR) is a short document stating one decision, its context, the options considered, the choice and its consequences. For cloud compliance, ADRs turn choices that otherwise live in someone's head, such as region, key management, logging retention and account structure, into dated, approved records. That makes them evidence for risk assessment and change management, and it makes the next questionnaire faster.
Which cloud decisions deserve an ADR?
- Primary and disaster recovery regions, and the residency reasoning.
- Account, subscription or project structure.
- Provider-managed or customer-managed encryption keys.
- Log destinations and retention periods.
- Identity provider and how cloud access is federated.
- Backup frequency, retention and recovery objectives.
- Choice of native tooling against a compliance platform.
- Any accepted risk, such as a service that cannot use private networking.
A template that works
- Title and number
- "ADR-007: Store production data in ca-central-1 with DR in ca-west-1."
- Status and date
- Proposed, accepted, superseded. With the date accepted and who accepted it.
- Context
- What forced the decision: a customer requirement, a regulation, a cost.
- Options considered
- Two or three, each with its trade-off in a sentence.
- Decision
- The choice, stated plainly.
- Consequences
- What this commits you to, including controls, costs and follow-up work.
- Compliance mapping
- Optional: the SOC 2 criteria or ISO 27001 controls it supports.
Where to keep them
In the infrastructure repository, as Markdown, next to the code they govern. Changes go through pull requests, which gives each ADR the same approval trail as a code change. An auditor sampling change management can then see that a significant change was preceded by a decision record.
How ADRs show up in an audit
| Standard | Where ADRs help |
|---|---|
| SOC 2 | CC3.2 risk identification, CC5.1 control selection, CC8.1 change authorization for significant changes |
| ISO 27001:2022 | Clause 6.1.3 risk treatment decisions, control 5.23 cloud services, 8.27 secure architecture principles |
| Questionnaires | Region, encryption and backup answers backed by a dated decision |
Are architecture decision records required for SOC 2?
No. They are one way to evidence risk-based decisions and change authorization. Many companies pass without them, but they make those criteria easier to evidence and save time answering customer questions.
How long should an ADR be?
One page. If it runs longer, the context belongs in a design document and the ADR should link to it.
What if we made the decision years ago?
Write the ADR now, record the original decision date if you know it, and mark it as documenting an existing decision. That is still better evidence than nothing.
Want your architecture documented for audit?
Firms in the network write the decision records and diagrams auditors ask for.
Get matched