Compliance Evidence: What Assessors and Auditors Ask to See

Compliance is judged on evidence, not intentions. See which documents, logs and records to collect so audits of your security controls go smoothly.

3 min readBy Ironfield Cyber Team

Many companies work hard on security and still struggle in an audit or assessment. The reason is rarely that they did nothing. It is that they cannot prove what they did. Whether the review involves CMMC, a utility's obligations under NERC CIP, pipeline security requirements, or a customer's questionnaire, the reviewer's job is to verify claims with evidence.

Understanding what counts as evidence, and collecting it as you go, saves enormous effort later.

Three kinds of evidence

Assessors generally rely on three methods, and it helps to prepare for each.

  • Examine. They look at documents, configurations, records, and logs.
  • Interview. They ask people how things are done.
  • Test. They observe a control in action or try it.

Your evidence should line up across all three. If a policy says one thing, a configuration shows another, and staff describe a third, the result is a finding.

Documents that matter

Keep current, approved versions of these.

  1. Policies that state what the organization requires
  2. Procedures that show how tasks are performed
  3. System descriptions and network diagrams showing boundaries and data flows
  4. Asset inventories of hardware, software, and where sensitive data lives
  5. Risk assessments and records of decisions made about them
  6. Incident response plans and records of tests
  7. Training records showing who was trained, when, and on what

Policies without procedures are weak. Procedures nobody follows are worse. Write what you actually do, then do what you wrote.

Records that prove the control operates

Beyond documents, assessors want records created by the control itself.

  • Access review records, showing who reviewed accounts and what was removed
  • Screenshots or exports of configuration settings, with dates
  • Patch and vulnerability scan reports
  • Backup logs and restore test results
  • Logs showing authentication events and administrative actions
  • Change records with approvals
  • Visitor and badge logs for physical protections
  • Vendor and third-party access records

Dated, repeatable records are the strongest. A single screenshot from last week is weaker than a series showing the control working for months.

Build an evidence library

Do not wait until an assessment is announced.

Organize by control or requirement

Create a structure that maps each requirement to its evidence. A simple folder tree or a spreadsheet listing the requirement, the evidence, the location, the owner, and the last updated date is enough.

Assign owners

Each piece of evidence should have a person responsible for keeping it current. Owners should know how often it needs refreshing.

Schedule collection

Set a recurring calendar for quarterly or monthly evidence capture. For example, a first-of-the-month task to export the user list, a quarterly access review, and an annual incident response exercise.

Protect the library

Evidence can contain sensitive configuration details. Limit access, keep backups, and avoid scattering copies in email.

Prepare your people

Interviews can be nerve-racking. Prepare staff by:

  • Explaining the purpose of the review and what to expect
  • Asking them to answer honestly and specifically, based on what they do
  • Telling them it is fine to say they do not know and will find out
  • Making sure the person described in a procedure actually performs it

Be honest about gaps

Assessors generally respond better to a company that knows its weaknesses than to one that hides them. A documented gap with an owner and a schedule for fixing it shows maturity. Where a program allows a formal plan of action for limited gaps, use it correctly and do not overstate completion.

A hypothetical example

Consider a hypothetical regional pipeline services firm preparing for a customer security review. It could assemble a one-page index listing each requirement area, the policy that covers it, the system that enforces it, and the most recent evidence with a date. When the reviewer asks about access removal for departed employees, the firm can produce the policy, the offboarding checklist, and the last three quarterly access reviews in minutes.

Common mistakes

  • Creating documents the week before the audit
  • Using templates without tailoring them
  • Relying on one person's memory
  • Leaving evidence undated
  • Ignoring third parties who hold your data

Where Ironfield Cyber helps

Ironfield Cyber helps contractors and energy companies build compliance programs that produce evidence as a normal byproduct of good operations. If you are preparing for a customer review or assessment, we can help you organize what you have and identify what to collect.