Cloud computing has matured from an efficiency-driven technology choice to being the backbone of modern digital infrastructure. For over a decade, the narrative has been dominated by agility, cost and scale. But as geopolitical tensions rise and extraterritorial regulations tighten, a critical question has surfaced: Who actually controls your data, your operations, and your AI pipelines?
This question has forced governments to reconsider the boundaries of national security and digital resilience. Demonstrating this shift, the Dutch government recently tightened its cloud policy to ensure its digital sovereignty. Governmental agencies are now required to establish a cloud strategy before they start using public cloud services. This strategy must include the rationale behind the choice of that specific cloud service, what the associated risks are, and how these will be controlled. For important cloud services, governmental agencies also must establish exit plans that outline which measures have been implemented to ensure service delivery if the cloud service becomes unavailable.
Meanwhile, the market has been flooded with "sovereign" labels. However, much of this is merely “sovereignty-washing”: superficial marketing that masks deep-seated systemic dependencies. From US extraterritorial laws like the CLOUD Act to a global hardware supply chain rooted in Asia, the reality is that "full" sovereignty is an illusion. For IT audit, risk, and security professionals, treating sovereignty as a paper-based compliance exercise only provides their principals with a false sense of security.
Building upon our previous publication, “Cloud Sovereignty: a Board Priority” (ISACA, May 2026), with this article we aim to create awareness across a broader professional audience. In this article we will expand upon our high-level framework and define concrete attention points for the IT auditor. By mapping the external risk vectors to our five-pillar framework, we provide a clear perspective for action, demonstrating exactly where to enforce controls and how to cut through superficial sovereignty-washing. We show how organizations can operate within a deeply globalized infrastructure on terms that safeguard long-term operational autonomy. Using this framework organizations can stop chasing unreachable perfection and start building verifiable operational autonomy.
Our forthcoming article will transition from the idealism of absolute isolation to deliver a more pragmatic, proactive blueprint for securing operational cloud sovereignty.