Types of evidence
Documents describe what should happen, such as policies and procedures. Records show what did happen, such as access review results, training completion, incident registers and change approvals. Technical evidence comes from the systems themselves: configurations, exports, logs and screenshots. Interviews and observation confirm that people know and follow the processes.
What auditors look for
Evidence must be relevant to the requirement, reliable, dated and complete for the audit period. Auditors usually take samples, for example a selection of new joiners, leavers or changes, and check each one against the process. A policy without records of it being applied is weak evidence; records that contradict the policy produce a nonconformity.
Point in time and period
A SOC 2 Type I report checks that controls are suitably designed at a specific date. A SOC 2 Type II report tests evidence across an observation period, typically between three and twelve months, so any gap in that period shows up as an exception. ISO 27001 certification audits also expect records showing that the ISMS has been operating, including a completed internal audit and management review.
Collecting it well
Assign an owner to each control, define what evidence it produces and how often, and collect it as part of normal work rather than in the weeks before the audit. Compliance platforms can automate much of the collection from connected systems. Our article on what a certification audit actually tests covers what auditors check in practice.




