A well-organized evidence repository makes your audit go smoothly. Here's how to keep things clean and auditor-ready.
Go to Evidence in the left sidebar to see all uploaded files across your entire workspace. This page shows:
Use descriptive filenames before uploading. Auditors see the original filename, so make it meaningful:
Access-Control-Policy-v2-July2026.pdfMFA-Settings-Screenshot-AWS-July2026.pngdocument1.pdfscreenshot.pngThere's no fixed rule, but as a guide:
Audit-ready check: For every control marked Implemented, open the Evidence page and confirm at least one file is attached. The "Controls needing evidence" section flags these automatically.
For Type II audits, auditors review evidence over the entire audit period (typically 6–12 months). Update your evidence regularly — don't just upload once at the start and forget about it. A dated log showing the control operated consistently throughout the period is much stronger than a single snapshot.