Evidence
Compliance Evidence and Audit Trails
How to create records that show what happened, who acted and whether controls operated.
Why this matters
How to create records that show what happened, who acted and whether controls operated.
Evidence must answer questions
Useful evidence shows the activity, date, population, reviewer, decision, exceptions and follow-up. A screenshot without context may show a screen but not prove that the full control operated.
System and human evidence
Logs, configuration records and workflow histories may support automated controls. Approvals, checklists, meeting minutes and review notes may support manual controls. Evidence should be retained in a controlled location.
Audit trail integrity
Access, versioning, timestamps and change history matter. Organizations should understand who can create, modify or delete records and whether changes are visible.
Evidence mapping
Map each key control to expected evidence, source system, retention period, owner and retrieval method. This reduces last-minute searches during audits and regulatory reviews.
Avoid evidence theatre
A large volume of documents is not automatically strong evidence. Relevance, completeness, authenticity and traceability matter more than quantity.
Questions to document
- Which obligations and processes are in scope?
- Who owns the activity and who independently reviews it?
- What record demonstrates that the activity operated?
- What happens when the control fails or circumstances change?
Related planning tools
Use the local planning tools to turn the concepts into a structured working note.