What useful evidence looks like
Evidence proves to someone who was not there that a control was performed: when, by whom and with what result. If someone has to explain it, it is not good evidence.
Useful evidence meets five conditions:
- It is dated: with the date of the control, not the day someone saved the file.
- It says who: the person who performed the control and, if applicable, who reviewed it.
- It is tied to its control: you know which control and which period it belongs to, without guessing from the file name.
- It shows the result: passed, passed with findings or not applicable, and what was done about each finding.
- It cannot change without a trace: if it is modified, there is a record of what changed, who changed it and when.
Examples of controls and their evidence
| Control | Weak evidence | Useful evidence |
|---|---|---|
| Quarterly user access review | “Reviewed” in a spreadsheet | The user list exported that day, with removals marked and the reviewer’s signature |
| Disaster recovery test | An email that says “all good” | The test report: what was tested, how long recovery took and what failed |
| Annual vendor assessment | A list of “approved” vendors | One record per vendor with the criteria, the score, the date and who assessed it |
| Warehouse safety walk | A signature on a paper log | The checklist with a photo and time for each point, and the open findings |
| Internal policy acknowledgment | The email it was sent in | Each person’s signature, with its date, and a list of who is still missing |
The difference repeats: weak evidence says someone did it. Useful evidence shows it.
Who signs
It helps to separate two roles:
- The person who performs the control signs off on what they did and what they found.
- The person who reviews it signs off that the control was done as planned. For sensitive controls, it should not be the same person.
The type of signature also depends on the control. For many internal controls, a reliable record of who and when is enough. For others, a regulation or a contract may require more.
Electronic signature levels, and what strengthens a simple signature, are covered in whether an e-signature on a work order is valid.
Due dates: make the control come to you
A control that depends on someone remembering gets done late or not at all. Every periodic control needs four things:
- A written frequency: monthly, quarterly, yearly or when something happens.
- An owner with a name, not a department.
- A reminder before the due date, with enough lead time to do it properly.
- An escalation if it is missed: who gets notified if it was not done.
Things that expire outside the company count too: insurance policies, licenses, permits and contracts. Treating them as dated controls saves you from finding out the day after.
How long to keep the evidence
There is no single answer. The retention period depends on the regulations that apply to you, your contracts and your internal policy. It can differ from one control to the next.
What holds in every case:
- Set the retention period by control type, in writing and with your legal advisors.
- Keep the evidence with the control, not in the folder of whoever did it. When that person leaves, their folder often leaves with them.
- Make it findable years later without knowing the file name: by control, by date and by owner.
- Plan how to delete it when the period ends, especially if it contains personal data.
An audit prepared in one afternoon
If evidence is kept this way, preparing for an audit means pulling a list:
- The controls for the period, with their owner and planned date.
- For each one, the date it was done and its evidence.
- The ones that were late or not done, with the reason.
- The findings that came up and their current status.
As with an SLA, showing the failures with their explanation builds more trust than a perfect list nobody believes.
A control without evidence is, for practical purposes, a control that was not done. And useful evidence costs about the same as weak evidence, if you collect it at the time.
Last updated: