GuideControls & Evidence

Evidence Collection: What Counts and What Doesn't

Practical guidance on collecting and organising evidence that demonstrates your controls are actually working.

Updated 15 Mar 2026

The Evidence Principle

Evidence proves your controls exist and work. Without it, you're just claiming compliance.

What Counts as Evidence

Strong Evidence

System-generated logs (access logs, change management records)
Screenshots with timestamps
Signed documents with dates
Configuration exports from tools
Training completion records from your LMS
Automated scan reports

Weak Evidence

Self-assessments without supporting data
Policies without proof of communication
Meeting agendas without minutes or decisions
"We do this" without proof

Not Evidence

Plans to implement something
Good intentions
A policy nobody has read

Organising Evidence

By Control

Map evidence to specific Annex A controls. One piece of evidence can support multiple controls.

Keep It Current

Evidence should demonstrate ongoing compliance, not just point-in-time. Aim for:

Monthly or quarterly samples for operational controls
Annual evidence for governance controls
Continuous evidence from automated tools

What Auditors Look For

Consistency Does evidence match what policies claim?
Timeliness Is evidence recent and representative?
Completeness Are all applicable controls covered?
Authenticity Can you show this wasn't fabricated?

Pro Tip

Start collecting evidence from day one. The biggest pain in certification prep is backfilling evidence that should have been captured months ago.

Related Modules

Standard Controls
Documents

Related Controls / Clauses

A.5.1
9.1
7.5

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.