GRC

Evidence integrity: why hashed evidence matters

Most compliance tools store evidence. Few can prove it is the same file that was collected. Here is why that distinction matters in an audit, and what to ask before you trust a platform with your record.
6 min read · Certifyi compliance team · Updated September 2026
Short answer. Evidence integrity means a record can be shown to be unchanged since it was created or collected. Auditors sample evidence to form an opinion; if the evidence could have been edited afterwards, the opinion rests on trust rather than proof. A compliance record that hashes each file on arrival, timestamps it, keeps superseded versions readable and logs every access gives the auditor a chain they can verify.

The question auditors and regulators actually ask

Not “do you have a policy?” but “can you show me the policy that was in force on that date, and prove it has not been altered since?” The same applies to access reviews, configuration exports and tickets. Screenshots in a shared drive fail this test: anyone with access can replace them, and there is no record of when they were taken.

What integrity by construction looks like

Why it changes the audit

With integrity in place the auditor can sample the whole population rather than the files you chose to show, verify each digest, and rely on the collection timestamps for the observation period. Fieldwork shortens because fewer interviews are needed to corroborate what the record already proves. At the next audit, the prior period is still verifiable, which is what makes surveillance audits routine.

Why it matters beyond the audit

Regulators, enterprise due-diligence teams and, increasingly, courts ask the same question. A supplier attestation recorded in the supplier’s own name on a date is a statement they made; a spreadsheet cell your team typed is not. In Certifyi, suppliers and auditors work in their own workspaces on the same record, so every statement has an author and a time.

Questions to ask any compliance platform

Frequently asked questions

No. Encryption protects confidentiality; a hash is a fingerprint that proves a file is unchanged. Evidence should have both: encrypted at rest, hashed for integrity.

Increasingly, yes, especially where evidence is collected automatically. Even when they do not verify every digest, the existence of the trail changes how much they rely on interviews.

Collected copies are hashed on arrival, and the collection timestamp and source are recorded. That is stronger than a screenshot, because the platform, not a person, took the copy.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top