GRC
Evidence integrity: why hashed evidence matters
Most compliance tools store evidence. Few can prove it is the same file that was collected. Here is why that distinction matters in an audit, and what to ask before you trust a platform with your record.
6 min read · Certifyi compliance team · Updated September 2026
Short answer. Evidence integrity means a record can be shown to be unchanged since it was created or collected. Auditors sample evidence to form an opinion; if the evidence could have been edited afterwards, the opinion rests on trust rather than proof. A compliance record that hashes each file on arrival, timestamps it, keeps superseded versions readable and logs every access gives the auditor a chain they can verify.
The question auditors and regulators actually ask
Not “do you have a policy?” but “can you show me the policy that was in force on that date, and prove it has not been altered since?” The same applies to access reviews, configuration exports and tickets. Screenshots in a shared drive fail this test: anyone with access can replace them, and there is no record of when they were taken.
What integrity by construction looks like
- A digest on arrival. Every uploaded or collected file is hashed the moment it lands. The hash is stored with the record; re-hashing the file later confirms it is unchanged.
- Timestamps from the system, not the user. Collection time is recorded by the platform, so “when” is not editable.
- Versions, not overwrites. A new version supersedes the old one; the old one stays readable with its own hash. Past positions remain answerable.
- Withdrawal with a reason. Assurance is withdrawn with a note and a date, never deleted silently out from under a finding.
- An access trail. Who viewed, uploaded or changed a record, and when, including failed sign-in attempts.
Why it changes the audit
With integrity in place the auditor can sample the whole population rather than the files you chose to show, verify each digest, and rely on the collection timestamps for the observation period. Fieldwork shortens because fewer interviews are needed to corroborate what the record already proves. At the next audit, the prior period is still verifiable, which is what makes surveillance audits routine.
Why it matters beyond the audit
Regulators, enterprise due-diligence teams and, increasingly, courts ask the same question. A supplier attestation recorded in the supplier’s own name on a date is a statement they made; a spreadsheet cell your team typed is not. In Certifyi, suppliers and auditors work in their own workspaces on the same record, so every statement has an author and a time.
Questions to ask any compliance platform
- Is evidence hashed when collected, and can I see the digest?
- Are earlier versions kept readable, or overwritten?
- Can evidence be deleted, and if so, is the deletion logged with a reason?
- Is there a complete activity log, including administrative sign-ins?
- Can the auditor verify integrity themselves, from inside the platform?
Frequently asked questions
Is hashing the same as encryption?
No. Encryption protects confidentiality; a hash is a fingerprint that proves a file is unchanged. Evidence should have both: encrypted at rest, hashed for integrity.
Do auditors actually check hashes?
Increasingly, yes, especially where evidence is collected automatically. Even when they do not verify every digest, the existence of the trail changes how much they rely on interviews.
What about evidence that lives in other systems?
Collected copies are hashed on arrival, and the collection timestamp and source are recorded. That is stronger than a screenshot, because the platform, not a person, took the copy.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.