A little learning. A little more confidence.Your next step starts here

GRC & Audit Support · Lesson 5 of 8

Collecting audit evidence

Good evidence is relevant to the request, covers the right scope and period, and can be traced to its source. More files do not automatically mean better evidence.

SEE THE IDEA

Does the evidence support the whole claim?

Claim: all departures in the quarter were processed on time.

Does the evidence support the whole claim?
EvidenceWhat it supportsWhat to check
One screenshot todayOne account at one momentDoes not establish quarterly completeness or timeliness
Departure populationWho was in scopeReconcile it with access-removal records
Dated removal recordsWhen actions occurredCompare to the deadline and verify relevant access paths
Protect evidence and limit access. Use the agreed testing approach instead of assuming every sample proves the whole population.
Read the visualWhy is the departure population necessary?

Without the in-scope list, you cannot tell whether records are missing.

Confirm the request

Identify the system, period, population, and control being checked before gathering records.

Preserve context

Record collection date, source, owner, and limitations. Redact unrelated sensitive information using the approved process.

Track completeness

Maintain an evidence index and clearly identify gaps. Never alter a record to make it appear compliant.

Put it in context

A screenshot shows one account disabled today. It does not alone prove all departures during the quarter were processed on time. You need the population and relevant records.

Evidence must match the claim, period, and population.

Read the sources

Make it stick.

Try one short question to check your understanding and save this lesson to your progress.

YOUR LEARNING SPACE