Begin with the claim being checked
A folder full of documents is not automatically useful audit evidence. Start with the review objective: what claim, process or control is being checked, over which system and period?
PCAOB AS 1105, in its financial-reporting audit context, distinguishes the quantity of evidence from its quality, including relevance and reliability.1 These are useful concepts for evidence planning, but its specific requirements should not be applied indiscriminately to every internal or cybersecurity review.
Your responsible reviewer should define the appropriate evidence request and assessment method. The collection checklist below is an original preparation aid that helps owners supply clear records without implying that collection alone proves a conclusion.
Different records answer different questions
Policies and procedures
An approved policy can establish intended responsibilities and rules. A procedure can explain how work should happen. Neither, on its own, demonstrates that every relevant occurrence followed the rule.
Retain version, approval date, applicable scope and owner. If the document changed during the review period, supply the relevant versions rather than replacing the historical record with today's copy.
Operational records
Tickets, approval logs, reconciliations, system exports and review decisions can show what happened. Their usefulness depends on scope, completeness, timing and source integrity.
A record of one approved change may support a question about that change. It does not establish that all changes were approved. To answer the broader question, a reviewer may need the occurrence population and a suitable selection or analysis method.
Interviews and observations
Interviews can explain responsibilities, practices and exceptions. Observation can show an activity at a particular time. Record who participated, what was discussed or observed, and the limits of the method.
Avoid turning a confident verbal explanation into a universal conclusion. Follow up with relevant records or testing where the review requires it.
Tests and re-performance
A controlled test can show how a defined scenario behaves. NIST SP 800-53A identifies examination, interview and testing as assessment methods.2 Select a safe, authorized approach and state the expected outcome before executing it.
A successful synthetic recovery test demonstrates something about the tested data, configuration and conditions. It does not automatically establish recoverability of every production service. Preserve that boundary in the result.
A reusable evidence inventory
| Field | What to record |
|---|---|
| Request ID | Stable reference to the reviewer question |
| Objective | Claim or control the evidence is intended to address |
| Scope | System, entity, location, process and relevant information |
| Period | Dates or point-in-time state covered |
| Source and owner | Originating system and accountable provider |
| Collection method | Export, observation, interview or test |
| Population and selection | What exists and what was supplied or selected |
| Integrity notes | Filters, transformations, redactions and working copies |
| Exceptions | Missing, inconsistent or adverse material |
| Access and retention | Authorized location, reviewers and retention decision |
| Reviewer disposition | Accepted for the purpose, further work required or unresolved |
This record can accompany a file, link or controlled folder. For the wider engagement sequence, see the internal audit planning checklist. The SOC 2 readiness checklist illustrates how evidence fits one specific preparation context. A consistent identifier is more useful than a vague filename such as “final evidence latest.”
Worked example: privileged-access review
This fictional organization claims it reviews privileged access for a customer portal each month. The collector supplies three screenshots with a manager's name, but one screenshot has no date and another covers a different environment.
The reviewer cannot yet determine what was reviewed or whether the supplied records cover the relevant period. The collector returns to the source and identifies the full account exports, review dates, reviewer decisions and actions resulting from those decisions.
| Collection issue | Honest response |
|---|---|
| Screenshot has no date | Supply source context; do not invent a capture date |
| Record covers another environment | Label it accurately and request the relevant environment |
| One month is missing | Record the gap and management explanation |
| An account was removed late | Retain the exception and related correction |
| Export was filtered | Preserve filters and reconcile the covered population |
The package becomes more useful because its limits are visible. Missing evidence should not be filled with a backdated reconstruction presented as an original record. A current reconstruction can be supplied separately, with its actual date and basis.
Check completeness before checking appearance
A polished PDF may still omit relevant occurrences. Ask how the population was identified: which system, date range, status filters and exclusions were used? Can its counts be reconciled to another reliable source?
If a review concerns employee departures, the source may begin with the authorized departure list and reconcile to account-removal tickets. Starting only from completed tickets could miss departures where no ticket was created.
Document the collector's selection separately from the reviewer's sampling. Do not claim statistical confidence or representative coverage without an appropriate method. A small convenience sample can be useful for exploration when labeled honestly, but should not silently become a complete conclusion.
Preserve provenance and adverse results
Keep originals or reliable source references where appropriate. Work on copies for annotations or redaction, and explain changes. Record extraction times, time zones and formats where they affect interpretation.
Retain material that contradicts the claim as well as material that supports it. A failed restoration, late removal or rejected change is part of the review record. Deleting unfavorable evidence undermines the ability to understand what happened.
The IIA's professional framework connects engagement work with findings, conclusions and monitored action plans.3 Evidence should therefore remain linked to the issue and response, rather than being stored as an isolated collection that nobody can interpret later.
Protect the information being collected
Determine whether the evidence contains personal information, customer material, secrets or sensitive operational detail. Use the approved storage and access boundaries for that information. Supply only what the review needs.
Redaction should preserve meaning and be documented. If the reviewer needs to validate an original, arrange controlled access rather than distribute unrestricted copies. Never include passwords or access tokens simply because a screenshot happens to show them.
Agree retention and deletion with the responsible owner and applicable obligations. There is no universal retention period that can safely be inferred from the word “audit.”
A collection checklist before handoff
Confirm each package has a request ID and a clear objective. Check that the system and period match the request. Verify source, owner and collection method. Explain population coverage, exclusions and transformations. Include exceptions and missing items. Test that authorized reviewers can open the records without widening access.
Then mark the package as supplied, not automatically validated. The reviewer decides whether it is relevant and sufficient for the purpose, whether additional work is needed and what conclusion the evidence supports.
Make follow-up easy
When a reviewer requests clarification, preserve the original package and add a dated response. Link replacement records to the earlier version and explain why they changed. If an issue becomes a finding, keep the evidence reference, management response and closure criteria together.
The goal is a clear chain from question to source to analysis to conclusion. That chain makes evidence useful even when it reveals a gap, and makes the resulting action easier to verify later.
Sources and references
-
Public Company Accounting Oversight Board. AS 1105: Audit Evidence. Audit-evidence standard for its financial-reporting context; quality principles are explained as an analogy, not applied indiscriminately to other engagements. ↩
-
NIST. Assessing Security and Privacy Controls, SP 800-53A Revision 5 (2022-01). Describes examination, interview and testing methods; source examples are adapted, not a claim to meet federal requirements. ↩
-
The Institute of Internal Auditors. Global Internal Audit Standards, 2024 edition (2024). Primary professional framework covers governance, objectivity, engagement planning, evidence and action monitoring. ↩

