Complies
CROSS-FRAMEWORK GUIDES

Audit Evidence Examples: What Auditors Actually Ask For

APRIL 2026 · 10 MIN READ · BY THE COMPLIES TEAM

Audit evidence is the artifact trail proving a control actually ran: signed access reviews, change tickets linked to deploys, onboarding checklists, backup restore results, and vendor review records. Below are concrete examples grouped by control area, with the freshness rules auditors apply and how to collect each artifact once and reuse it across frameworks.

What counts as evidence

Auditors distinguish between a control existing and a control operating. A policy proves intent; evidence proves execution. Good evidence has four properties: it is dated (when the control ran), attributed (who ran it), specific (what was checked and what the result was), and system-generated where possible (an export beats a screenshot, a screenshot beats a verbal assurance). In a SOC 2 Type 2 or an ISO 27001 stage 2 audit, auditors sample these artifacts across the period; a missing sample becomes a written exception or nonconformity.

Audit evidence examples by control area

Access control

  • Quarterly user access review: a dated export of accounts per system with a reviewer's sign-off and a record of accounts removed as a result
  • SSO and MFA configuration: an identity-provider policy export showing MFA enforced for all users
  • Privileged access list: who holds admin rights and the documented business justification
  • Offboarding records: a completed checklist per departure showing all access revoked, with timestamps

Change management

  • A sample of merged pull requests showing peer review approval before deploy
  • CI/CD pipeline logs showing tests passed prior to release
  • Change tickets for infrastructure changes with approval and rollback notes
  • The emergency change record, including retroactive approval, for any hotfix that bypassed the normal path

HR and personnel

  • Onboarding checklists: signed code-of-conduct acknowledgment, security policy acceptance, background check where applicable
  • Security awareness training completion logs with dates per employee
  • Annual policy re-acknowledgment records

Operations and resilience

  • Backup job logs plus, critically, a dated restore test with its result: auditors ask for the restore, not just the backup
  • Monitoring and alerting configuration, and an example alert with its response
  • Incident records: detection time, actions, resolution, and postmortem
  • Business continuity or disaster recovery test results, even tabletop exercises, with attendees and findings

Vendor management

  • The vendor inventory with risk tier per vendor
  • Annual vendor security reviews: the vendor's SOC 2 report or ISO certificate on file, with a dated internal review note
  • Signed DPAs where vendors process personal data (a GDPR Article 28 requirement that doubles as vendor-management evidence)

Risk and governance

  • The current risk assessment with scores, owners, and treatment decisions (see compliance risk assessment for the format)
  • Management review minutes (mandatory for ISO 27001) and internal audit reports with remediation tracking
  • Policy approval records showing who approved each document and when

Freshness: evidence expires

Evidence has a shelf life tied to its control's frequency. A quarterly access review from five months ago does not cover this quarter; last year's restore test does not prove this year's backups restore. Practical freshness rules:

  • Quarterly controls (access reviews, control self-assessments): evidence older than ~90 days is stale.
  • Annual controls (training, policy reviews, vendor reviews, risk assessment, BC/DR tests): stale after ~12 months.
  • Continuous controls (MFA enforcement, logging): auditors want current configuration exports, typically pulled at fieldwork time, plus period samples.
  • Point-in-time artifacts (pen test reports): customers commonly expect one from the last 12 months.

This is why evidence collection is a scheduling problem before it is a filing problem: each artifact needs an owner and a due date ahead of its expiry, or the gap is discovered during fieldwork, when it is too late to fix inside the window. The timeline cost of that failure is quantified in how long SOC 2 takes.

Collect once, reuse everywhere

The same quarterly access review satisfies SOC 2 CC6, ISO 27001:2022 Annex A access control requirements, GDPR Article 32, and, where in scope, HIPAA and PCI DSS access requirements. The same restore test serves SOC 2 availability, ISO 27001 continuity controls, and GDPR Article 32's resilience language. Teams that file evidence per framework collect everything twice and drift out of sync; teams that file evidence per control, with the control cross-mapped to every framework that references it, hand both auditors the same folder. That single design decision is most of why a second framework commonly costs a fraction of the first.

The standard boundary applies here too: complete, fresh evidence gets you ready, but it does not decide the outcome. The auditor forms the opinion; your evidence determines how routine that process is.

Making the evidence run itself

In Complies, every control carries its evidence requests with an owner, a due date, and a freshness window, cross-mapped across SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS so each artifact is collected once and counted everywhere, with a live readiness score showing exactly which artifacts are current, expiring, or missing. It is self-serve, with published prices from $79 per month. See how compliance evidence collection replaces the shared-drive scramble, and get started before the next quarterly review comes due.

RUN IT, NOT JUST READ IT

Turn this into tracked rows with owners

Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.