What should we document for compliance during an email migration?

2 replies 8,730 views
Elena V.Original post

Compliance Officer · May 8, 2026

We are a healthcare-adjacent business and our auditor will ask about this migration at our next review. I am not a systems person. What do I need to be able to show them, and what should I be asking our IT vendor for now rather than a year from now?

Marcus T.Staff

Migration Specialist · May 8, 2026

Good instinct to ask now — most of this is difficult or impossible to reconstruct after the fact. Ask your vendor for these five things, in writing, before the migration runs:

  • A per-item audit record. Not 'mailbox migrated successfully' but a record for each message: what was read, what was written, when, and its final state. This is what turns 'we think everything moved' into something you can actually show an auditor.
  • A written statement of encryption in transit. All connections to both source and destination should be TLS. Ask them to state the minimum TLS version.
  • The access scope actually requested. This is the one people skip. A migration needs permission to read the source and write the destination — nothing more. If a vendor asks for broad administrative permissions across your tenant, ask them to justify each one specifically.
  • Credential lifecycle. How are credentials stored during the migration, and when are they destroyed afterward? 'Encrypted at rest and purged on completion' is the answer you want, with a stated retention period.
  • A retained final report. An exportable record of the completed migration, including any failed items and their reasons. Export it and store it with your compliance records — do not leave it living only in a vendor dashboard you may lose access to.

One thing I would add, since you mentioned healthcare: confirm whether your vendor will sign a BAA if PHI may exist in those mailboxes. That is a business and legal question rather than a technical one, and it needs to be settled before any data moves, not after.

Elena V.

Compliance Officer · May 9, 2026

This is genuinely useful — the access-scope point in particular. Our previous vendor asked for global admin and nobody questioned it. Taking this list to our IT committee.

complianceauditgdprhipaasecurity

This discussion is part of our curated migration knowledge base. Planning a move of your own? Our team answers within 48 hours.

Ask our migration team