Access is the biggest bucket: complete user listings from every in-scope system, quarterly access-review records, provisioning and deprovisioning tickets for a sample of joiners and leavers, and the MFA and SSO configurations behind them. Change management follows — pull-request history with approvals, pipeline checks, and a sample of production changes traced from ticket to deploy.
People and vendor evidence covers onboarding and offboarding checklists, background-check confirmations, security-training completions, policy acknowledgments, and a vendor inventory with risk ratings and review artifacts. Operational evidence rounds it out: monitoring and alerting configurations, incident tickets with post-mortems, backup jobs and restore tests, vulnerability scans, the penetration test report, and the annual risk assessment. Which items apply depends on scope — Security alone asks for less than Security plus Availability and Confidentiality.
Mechanically, the request arrives as a PBC list weeks before fieldwork, numbered by control area. Auditors work population-first: they ask for the complete listing, then choose their own samples from it — which is why exports need to be system-generated and complete, not curated. For the underlying discipline, see evidence collection.
Four properties, consistently: generated inside the period under audit, timestamped, showing its source (the URL, account, or console it came from), and unedited. Cropped or undated screenshots bounce back; a raw export from the system of record almost never does. A well-connected GRC platform gathers much of this automatically — the human work is keeping the collectors healthy and closing what automation can’t reach.
Yes, with conditions: the capture must show a timestamp and enough context to identify the system, and it must fall inside the audit period. Exports and API-collected records are preferred because they’re harder to stage and easier to re-verify.
For a Type 1, evidence shows the state of controls as of a single date. For a Type 2, it must span the entire observation period — auditors sample from every month in the window, not just the weeks before fieldwork.