Collect evidence without chasing anyone
The four kinds of evidence an auditor asks for, and how to keep all four current between audits.
Evidence is the part of compliance that people dread, because it is usually collected by asking colleagues for screenshots two weeks before an audit. It does not have to work that way. This guide covers the four kinds of evidence an auditor asks for, and how to keep all four current between audits.
What counts as evidence
An auditor is testing two things: that a control was designed to do the job, and that it kept operating through the whole period. So evidence needs a source, a date, and a control it belongs to. A screenshot with none of the three is a picture, not evidence.
The four kinds
Policies and procedures
The documents that say how the organization operates: information security, access control, incident response, business continuity, vendor management. Auditors look for an approval, a publication date, and acknowledgments from the people who have to follow them.
Technical configuration
The state of the systems themselves: encryption settings, network rules, logging and alerting, backup jobs, endpoint posture. This is the category that goes stale fastest, because the systems keep changing after the screenshot was taken.
Access and identity
Who has access to what, how they got it, and when it was taken away: user lists, role assignments, multi-factor enrollment, joiner and leaver records, and the access reviews themselves with the reviewer named.
Operational records
Proof that the program ran: security training completions, incident tickets and their resolutions, change approvals, vendor assessments, risk assessments, and the tests of your backups and recovery plan.
Five habits that hold up in an audit
- Collect on a schedule, not on request. Evidence gathered once, at the end, only proves the last day of the window. A Type II asks about all of it.
- File by control, not by system. An auditor works down a control list. If your folders follow your tooling, someone has to translate, and that usually happens the night before.
- Keep the timestamp and the source. Where it came from and when is what turns an artifact into evidence.
- Keep the history. Do not overwrite last quarter with this quarter. Continuity across the period is the thing being tested.
- Write down the exceptions. When a control did not hold, record what happened and what compensated for it. An auditor can work with a documented exception; a gap they discover is a different conversation.
How the agents do it
Zero2Do connects read-only to the cloud accounts, code hosting and identity provider you already run, then collects on a heartbeat rather than on a deadline. Each artifact lands against the control it satisfies, timestamped, with its source and the run that fetched it. The previous version stays where it was, so the period reads as a continuous record.
The 422 cross-mappings do the filing twice: one access review, collected once, is filed against its SOC 2, ISO 27001 and HIPAA controls at the same time. Where a control cannot be evidenced automatically, the agents raise it as a ranked gap with the surrounding work already finished, instead of leaving a silent hole.
Audit day
Nothing gets assembled the night before. Evidence, test results and current policies sit in the audit room organized by control; you export the package. See what the agents do, or the SOC 2 checklist for the controls this evidence has to answer.