Clear criteria. Traceable evidence.Atlant Security
Cyber/AuditBY ATLANT SECURITY
Build your scope Audit brief builder

AUDIT EVIDENCE

Build an audit evidence request list people can actually fulfil

Tie evidence requests to criteria, owners, periods and secure handling instead of collecting everything.

Discuss your requirements
Illustrative enterprise setting for build an audit evidence request list people can actually fulfil

For the engagement owner. A useful request explains why a record is needed, who owns it and what period it must cover.

Begin with the criterion

An evidence request should be traceable to an assessment objective. “Send all security documents” creates volume without explaining the conclusion the assessor needs to support. A better request names the control, the required record, the relevant population and the period. For an access-lifecycle review, ask for the approved disablement target, the leaver population and the relevant directory status history. These records answer a defined question. They also make it easier for an evidence owner to identify limitations before fieldwork begins.

A request with a purpose. Criterion: Name the control expectation.; Record: Specify the source and period.; Owner: Assign one accountable respondent.
Working model 01A request with a purposeIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Criterion
Name the control expectation.
Record
Specify the source and period.
Owner
Assign one accountable respondent.

Separate populations from samples

Obtain the population before choosing records to inspect. A list hand-picked by the control owner may omit unusual cases and cannot automatically be treated as representative. Record how the population was produced, its date boundaries and any exclusions. Then document the sample selection rationale: criticality, system variation, time coverage or specific risk. A judgemental sample can be useful, but its limitations should be stated. Do not turn a percentage of sampled exceptions into an estate-wide estimate without an appropriate statistical design.

Illustrative architectural staircase representing a structured evidence and review process
Operational perspectiveA clear route from evidence collection to management action.Generated illustrative setting; not a client location.

Make each request operational

Use a compact register with a request identifier, purpose, requested period, owner, due date and status. Add handling requirements where records contain personal information or sensitive configuration. Ask for stable pseudonymous identifiers when names are unnecessary. Keep the source and collection date with each export. Screenshots can explain a setting, but they often omit the surrounding scope, timestamps or query conditions. Where practical, pair them with structured exports and a short explanation of how the record was generated.

Population before sample. Population: Complete records within the boundary.; Selection: Document the risk-based method.; Exception: Track condition and corroboration.
Working model 02Population before sampleIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Population
Complete records within the boundary.
Selection
Document the risk-based method.
Exception
Track condition and corroboration.

Handle missing evidence honestly

Missing evidence is a fact to assess, not an invitation to reconstruct history. A control owner may be able to provide a different corroborating source or explain a retention limit. Record that explanation and evaluate what it actually supports. A newly created procedure may show improved design today; it does not prove the process operated last quarter. Separate confirmed exceptions, evidence limitations and controls that were not assessed. This helps management choose between remediation, better record keeping and additional assessment.

Evidence quality checks. Source: Record system and collection date.; Context: Keep query, scope and limitations.; Integrity: Preserve approved evidence references.
Working model 03Evidence quality checksIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Source
Record system and collection date.
Context
Keep query, scope and limitations.
Integrity
Preserve approved evidence references.

Control the transfer and the follow-up

Agree the secure channel, authorised recipients, access expiry and retention before collecting detailed material. Do not put credentials, production secrets or unnecessary personal records into initial web forms. Track superseded evidence so reviewers can reproduce the conclusion. After factual review, preserve the approved evidence references and record subsequent changes separately. This avoids quietly replacing a record that supported the original finding. Related guidance from the same Atlant Security portfolio: verifying remediation evidence and measuring security service delivery. Use these when an audit recommendation needs a separately scoped technical test or a clearly owned operational improvement.

Prepare a useful first conversation

Use the audit scoping brief builder to record your objectives, control areas, platforms and evidence period. Review its draft before sending it to Atlant Security through the contact form. You can attach an NDA or RFP for human review. Begin with non-sensitive context and approximate counts; confidential control evidence belongs in an agreed secure channel. The brief does not authorise system access, accept an NDA or establish an assurance opinion.

Missing evidence decisions. Alternative: Can another source corroborate it?; Limitation: What conclusion is no longer supported?; Action: Improve records or extend assessment.
Working model 04Missing evidence decisionsIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Alternative
Can another source corroborate it?
Limitation
What conclusion is no longer supported?
Action
Improve records or extend assessment.

Primary sources

General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.

This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.

Published by Atlant Security. Sources, editorial policy and corrections.

PUT THE GUIDANCE TO WORK

Choose your next step.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your audit objectives, control boundaries and evidence period. A useful starting point for your assessment.

Discuss your requirements