GRC & Audit Support · Lesson 5 of 8
Collecting audit evidence
Good evidence is relevant to the request, covers the right scope and period, and can be traced to its source. More files do not automatically mean better evidence.
Does the evidence support the whole claim?
Claim: all departures in the quarter were processed on time.
| Evidence | What it supports | What to check |
|---|---|---|
| One screenshot today | One account at one moment | Does not establish quarterly completeness or timeliness |
| Departure population | Who was in scope | Reconcile it with access-removal records |
| Dated removal records | When actions occurred | Compare to the deadline and verify relevant access paths |
Read the visualWhy is the departure population necessary?
Without the in-scope list, you cannot tell whether records are missing.
Confirm the request
Identify the system, period, population, and control being checked before gathering records.
Preserve context
Record collection date, source, owner, and limitations. Redact unrelated sensitive information using the approved process.
Track completeness
Maintain an evidence index and clearly identify gaps. Never alter a record to make it appear compliant.
Put it in context
A screenshot shows one account disabled today. It does not alone prove all departures during the quarter were processed on time. You need the population and relevant records.
Evidence must match the claim, period, and population.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.