Skip to main content
All articles

Audit Readiness

What Counts as Audit Evidence? Examples and an Evidence-Collection Checklist

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

What Counts as Audit Evidence? Examples and an Evidence-Collection Checklist: original RiskSensai editorial cover

Begin with the claim being checked

A folder full of documents is not automatically useful audit evidence. Start with the review objective: what claim, process or control is being checked, over which system and period?

PCAOB AS 1105, in its financial-reporting audit context, distinguishes the quantity of evidence from its quality, including relevance and reliability.1 These are useful concepts for evidence planning, but its specific requirements should not be applied indiscriminately to every internal or cybersecurity review.

Your responsible reviewer should define the appropriate evidence request and assessment method. The collection checklist below is an original preparation aid that helps owners supply clear records without implying that collection alone proves a conclusion.

Different records answer different questions

Policies and procedures

An approved policy can establish intended responsibilities and rules. A procedure can explain how work should happen. Neither, on its own, demonstrates that every relevant occurrence followed the rule.

Retain version, approval date, applicable scope and owner. If the document changed during the review period, supply the relevant versions rather than replacing the historical record with today's copy.

Operational records

Tickets, approval logs, reconciliations, system exports and review decisions can show what happened. Their usefulness depends on scope, completeness, timing and source integrity.

A record of one approved change may support a question about that change. It does not establish that all changes were approved. To answer the broader question, a reviewer may need the occurrence population and a suitable selection or analysis method.

Interviews and observations

Interviews can explain responsibilities, practices and exceptions. Observation can show an activity at a particular time. Record who participated, what was discussed or observed, and the limits of the method.

Avoid turning a confident verbal explanation into a universal conclusion. Follow up with relevant records or testing where the review requires it.

Tests and re-performance

A controlled test can show how a defined scenario behaves. NIST SP 800-53A identifies examination, interview and testing as assessment methods.2 Select a safe, authorized approach and state the expected outcome before executing it.

A successful synthetic recovery test demonstrates something about the tested data, configuration and conditions. It does not automatically establish recoverability of every production service. Preserve that boundary in the result.

A reusable evidence inventory

FieldWhat to record
Request IDStable reference to the reviewer question
ObjectiveClaim or control the evidence is intended to address
ScopeSystem, entity, location, process and relevant information
PeriodDates or point-in-time state covered
Source and ownerOriginating system and accountable provider
Collection methodExport, observation, interview or test
Population and selectionWhat exists and what was supplied or selected
Integrity notesFilters, transformations, redactions and working copies
ExceptionsMissing, inconsistent or adverse material
Access and retentionAuthorized location, reviewers and retention decision
Reviewer dispositionAccepted for the purpose, further work required or unresolved

This record can accompany a file, link or controlled folder. For the wider engagement sequence, see the internal audit planning checklist. The SOC 2 readiness checklist illustrates how evidence fits one specific preparation context. A consistent identifier is more useful than a vague filename such as “final evidence latest.”

Worked example: privileged-access review

This fictional organization claims it reviews privileged access for a customer portal each month. The collector supplies three screenshots with a manager's name, but one screenshot has no date and another covers a different environment.

The reviewer cannot yet determine what was reviewed or whether the supplied records cover the relevant period. The collector returns to the source and identifies the full account exports, review dates, reviewer decisions and actions resulting from those decisions.

Collection issueHonest response
Screenshot has no dateSupply source context; do not invent a capture date
Record covers another environmentLabel it accurately and request the relevant environment
One month is missingRecord the gap and management explanation
An account was removed lateRetain the exception and related correction
Export was filteredPreserve filters and reconcile the covered population

The package becomes more useful because its limits are visible. Missing evidence should not be filled with a backdated reconstruction presented as an original record. A current reconstruction can be supplied separately, with its actual date and basis.

Check completeness before checking appearance

A polished PDF may still omit relevant occurrences. Ask how the population was identified: which system, date range, status filters and exclusions were used? Can its counts be reconciled to another reliable source?

If a review concerns employee departures, the source may begin with the authorized departure list and reconcile to account-removal tickets. Starting only from completed tickets could miss departures where no ticket was created.

Document the collector's selection separately from the reviewer's sampling. Do not claim statistical confidence or representative coverage without an appropriate method. A small convenience sample can be useful for exploration when labeled honestly, but should not silently become a complete conclusion.

Preserve provenance and adverse results

Keep originals or reliable source references where appropriate. Work on copies for annotations or redaction, and explain changes. Record extraction times, time zones and formats where they affect interpretation.

Retain material that contradicts the claim as well as material that supports it. A failed restoration, late removal or rejected change is part of the review record. Deleting unfavorable evidence undermines the ability to understand what happened.

The IIA's professional framework connects engagement work with findings, conclusions and monitored action plans.3 Evidence should therefore remain linked to the issue and response, rather than being stored as an isolated collection that nobody can interpret later.

Protect the information being collected

Determine whether the evidence contains personal information, customer material, secrets or sensitive operational detail. Use the approved storage and access boundaries for that information. Supply only what the review needs.

Redaction should preserve meaning and be documented. If the reviewer needs to validate an original, arrange controlled access rather than distribute unrestricted copies. Never include passwords or access tokens simply because a screenshot happens to show them.

Agree retention and deletion with the responsible owner and applicable obligations. There is no universal retention period that can safely be inferred from the word “audit.”

A collection checklist before handoff

Confirm each package has a request ID and a clear objective. Check that the system and period match the request. Verify source, owner and collection method. Explain population coverage, exclusions and transformations. Include exceptions and missing items. Test that authorized reviewers can open the records without widening access.

Then mark the package as supplied, not automatically validated. The reviewer decides whether it is relevant and sufficient for the purpose, whether additional work is needed and what conclusion the evidence supports.

Make follow-up easy

When a reviewer requests clarification, preserve the original package and add a dated response. Link replacement records to the earlier version and explain why they changed. If an issue becomes a finding, keep the evidence reference, management response and closure criteria together.

The goal is a clear chain from question to source to analysis to conclusion. That chain makes evidence useful even when it reveals a gap, and makes the resulting action easier to verify later.

Sources and references

  1. Public Company Accounting Oversight Board. AS 1105: Audit Evidence. Audit-evidence standard for its financial-reporting context; quality principles are explained as an analogy, not applied indiscriminately to other engagements. ↩

  2. NIST. Assessing Security and Privacy Controls, SP 800-53A Revision 5 (2022-01). Describes examination, interview and testing methods; source examples are adapted, not a claim to meet federal requirements. ↩

  3. The Institute of Internal Auditors. Global Internal Audit Standards, 2024 edition (2024). Primary professional framework covers governance, objectivity, engagement planning, evidence and action monitoring. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • Audit Evidence
  • Evidence Collection
  • Controls
Connecting to your conversation workspace…