Glossary
GLOSSARY Governance

Audit Evidence

Last updated 27 Jul 2026

Audit evidence is the material used to support a conclusion about whether something was true or a control operated. Auditors assess it on two axes: sufficiency, meaning enough of it, and appropriateness, meaning relevant and reliable.

Security teams rarely fail on sufficiency. They produce volume. They fail on reliability and on the ability to reproduce evidence after the fact.

Reliability, ranked

Evidence generated by a system beats evidence generated by a person.

Evidence obtained directly from the source beats a summary prepared by the party being assessed.

Evidence created at the time beats evidence assembled afterwards for the assessment.

Evidence that cannot be edited by the party it concerns beats evidence that can.

The screenshot problem

The most common security evidence artifact is a screenshot pasted into a document.

It has no verifiable date. It shows one moment rather than a period. Its scope cannot be checked. It could have been taken from any environment. And it was produced by the team being assessed, specifically for the assessment.

It is accepted constantly because the alternative takes longer to produce. It is also the first thing challenged when an assessment gets serious.

Evidence for manual measurements

Where a figure is recorded by a person, the evidence attached to it is the entire basis of its reliability. See manual data entry.

A quarterly training completion figure typed into a system with the source report attached, the author recorded and the date fixed is evidence. The same number without those is testimony.

How long to keep it

Long enough to cover the examination cycle that will ask about it, which is usually longer than the retention policy people set by default.

And retrievable, which is a separate property. Evidence that exists somewhere in a shared drive but cannot be located against a specific reported figure is functionally absent.