Evidence

Organizing evidence by control

A well-organized evidence repository makes your audit go smoothly. Here's how to keep things clean and auditor-ready.

The evidence repository page

Go to Evidence in the left sidebar to see all uploaded files across your entire workspace. This page shows:

  • Every file, which control it belongs to, who uploaded it, and when
  • A search bar to find specific files quickly
  • A "Controls needing evidence" section — implemented controls with no files attached
  • Stats: total files, controls covered, and controls still missing evidence

Naming your files clearly

Use descriptive filenames before uploading. Auditors see the original filename, so make it meaningful:

  • Access-Control-Policy-v2-July2026.pdf
  • MFA-Settings-Screenshot-AWS-July2026.png
  • document1.pdf
  • screenshot.png

How many files per control?

There's no fixed rule, but as a guide:

  • Policy controls (CC1.1, CC2.1, etc.) — One well-written policy document is usually sufficient.
  • Technical controls (CC6.1, CC7.1, etc.) — A policy plus at least one screenshot showing the control is configured.
  • Process controls (CC6.2, CC6.3, etc.) — A procedure document plus a sample record showing the process was followed (e.g., an onboarding checklist, an access removal ticket).

Audit-ready check: For every control marked Implemented, open the Evidence page and confirm at least one file is attached. The "Controls needing evidence" section flags these automatically.

Keeping evidence current

For Type II audits, auditors review evidence over the entire audit period (typically 6–12 months). Update your evidence regularly — don't just upload once at the start and forget about it. A dated log showing the control operated consistently throughout the period is much stronger than a single snapshot.