Evidence is proof that a control operated — over the whole period, across the whole population, not just on a good day. Auditors sample: they’ll pick a handful of hires and ask for onboarding records, pick terminated employees and ask for the offboarding trail, pick a quarter and ask for that access review. System-generated records beat manual attestations, and a complete population matters as much as any single artifact. The fuller picture is in our evidence collection glossary entry.
The good news hiding in that definition: a lot of evidence gets generated whether or not anyone collects it. Cloud audit logs, identity-provider sign-in and MFA events, code review history, ticket timelines, HR records — those systems have been recording all along. The distance between “we never collected evidence” and “we never operated controls” is the whole game, and it determines how bad your week actually is.
Recoverable: anything a system of record kept for you. Infrastructure and access logs, merged pull requests, closed tickets, HR onboarding records, email trails — exportable today with historical timestamps intact, subject to retention windows (some tools keep only a few months, so harvest before anything ages out). Point-in-time evidence is recoverable too: current configuration exports, encryption settings, and screenshots prove present state, which is most of what a readiness assessment or a Type 1 examination needs.
Not recoverable: recurring activities that never happened. An access review that was never performed, a restore test never run, training never completed, a management review that never met — there is no export for those. Timestamps don’t lie: running the missed review today produces evidence dated today. That still helps — it shows the control operating for the remainder of the period — but it cannot manufacture the quarter you skipped.
Which leads to the one hard rule: never backdate. Fabricating a date turns a scheduling problem into an integrity problem. Auditors cross-check metadata against system logs, and a caught fabrication doesn’t just fail one control — it undermines every other artifact you’ve handed them. Disclose the gap instead. Deviations are a routine part of audit reports; fabrication ends engagements.
Do these in sequence — the early steps tell you whether the later ones are even needed.
Push through when the gaps are narrow and disclosable — most missing items harvestable, missed activities limited to a slice of the period, and a deal or renewal waiting on the report. A Type 2 report with a few documented deviations is normal and usable; enterprise buyers read the exceptions, not just the opinion line.
Consider moving when operation itself lapsed for key controls across most of the period. Options are better than they feel: shift the observation window later, shorten a first-year Type 2 period — short windows are common for first reports — or take a Type 1 now on present-state design and schedule the Type 2 behind it. Raise it with your auditor early; they replan windows routinely and would far rather resequence than discover mid-fieldwork. Moving a date you control beats defending a report you can’t.
This triage is what Agency’s engineers do for clients in exactly this position: take the request list, run the harvest across your systems, stand up automated collection, execute the overdue controls with you, and draft the exception documentation — then handle the auditor requests as they land. It’s the crisis version of the weekly evidence discipline described in managed Vanta and the antidote to the scramble we describe in audited compliance.
The other half of the engagement is making sure there’s never a second rescue. Once collection runs continuously, evidence stops being a season — that steady state is where clients bank 200+ hours saved per year. The first audit gets saved; the second one gets boring, which is the goal.
No. If the control genuinely operated, real artifacts exist somewhere — logs, tickets, emails, calendar records — and the recovery move is finding those, not creating new ones with old dates. A newly created artifact dated in the past is fabrication regardless of what actually happened, and auditors check metadata.
No. Auditors weigh severity and pervasiveness: isolated gaps typically surface as noted exceptions or deviations, not a qualified opinion. What tips reports toward qualification is broad, undisclosed failure of key controls — which is exactly why early disclosure and visible remediation matter.
It depends on what kind of behind you are. If most gaps are harvestable system records, days of focused work can close them even close to fieldwork. If key controls simply didn’t operate for most of the window, the honest answer is a window adjustment — and your auditor can confirm which case you’re in quickly.
Yes, and early. Auditors can resequence fieldwork, adjust sampling, or replan the window when they know in advance — every one of those is better than stalled requests mid-audit. The conversation costs less than the discovery, every time.
Yes. Agency prepares evidence, manages the request list, and remediates findings alongside whichever independent firm you’ve chosen — we coordinate the audit, we don’t perform it, so independence is never in question.