GlossaryCompliance operations

Audit evidence

Short answer

Audit evidence is the information an auditor uses to verify that requirements are met and controls work: documents, records, system configurations, logs, screenshots, interviews and direct observation. For ISO 27001, the ENS or SOC 2, the quality of the evidence often decides the result of the audit.

Types of evidence

Documents describe what should happen, such as policies and procedures. Records show what did happen, such as access review results, training completion, incident registers and change approvals. Technical evidence comes from the systems themselves: configurations, exports, logs and screenshots. Interviews and observation confirm that people know and follow the processes.

What auditors look for

Evidence must be relevant to the requirement, reliable, dated and complete for the audit period. Auditors usually take samples, for example a selection of new joiners, leavers or changes, and check each one against the process. A policy without records of it being applied is weak evidence; records that contradict the policy produce a nonconformity.

Point in time and period

A SOC 2 Type I report checks that controls are suitably designed at a specific date. A SOC 2 Type II report tests evidence across an observation period, typically between three and twelve months, so any gap in that period shows up as an exception. ISO 27001 certification audits also expect records showing that the ISMS has been operating, including a completed internal audit and management review.

Collecting it well

Assign an owner to each control, define what evidence it produces and how often, and collect it as part of normal work rather than in the weeks before the audit. Compliance platforms can automate much of the collection from connected systems. Our article on what a certification audit actually tests covers what auditors check in practice.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub