ISO 27001 · Evidence
How do you prepare evidence for an ISO 27001 audit?
Preparing evidence for an ISO 27001 audit means attaching, to each applicable control, an artefact that shows it operated during the period, with a capture date the auditor can read. The goal is a record the auditor can review, not a folder to search.
What counts as evidence?
Anything that shows a control operated, not that it was intended: an access review with decisions recorded, a completed training register, a change ticket with its approval, a screenshot of a configuration with the date visible, a signed policy acknowledgement. A policy on its own is a claim; the acknowledgement campaign is the evidence.
Why does the capture date matter?
Because a control that passed eleven months ago and a control that passes now are different facts. Every artefact should carry when it was captured, and an automated check that has not run recently should be shown as stale rather than passing. Auditors trust automated evidence exactly until they catch last year’s success presented as a current pass.
How do you organise it?
- One artefact, many controls. Upload once and link it to every control it supports; do not duplicate.
- Keep withdrawn evidence. If something is superseded, record why and keep the old version, so the record of what the last auditor saw survives.
- Separate internal notes from responses. A comment explaining why a control is weak is a different kind of text from the answer the auditor reads.
- Map connected checks to named controls. A passing check with a control reference and a freshness date is evidence; an unmapped one is a dashboard.
What should be ready before fieldwork?
Findings from the previous visit closed or formally tracked, internal audit and management review minutes, the current Statement of Applicability and risk register, and evidence refreshed for controls that operate on a cycle: access reviews, supplier reassessments, awareness training, backup tests. Then confirm readiness with the certification body and agree the sampling plan.
Where you stand
Score your own readiness in one sitting
The free self-assessment walks through the controls an auditor samples, gives you a scored report, and takes about fifteen minutes. No account needed.
Related questions
How much evidence is enough?
Enough for the auditor to conclude on each sampled control without asking. One clear artefact per control per period beats twenty screenshots.
Can we use screenshots?
Yes, with the date and the system visible. They are weaker than an exported record or a connected check because they capture a moment rather than a period.
Does Certifyi collect evidence automatically?
Connected sources such as AWS and Tenable, plus Nessus and CSV imports, are mapped to the controls they satisfy and synchronised on a schedule. Evidence from people and process is uploaded once and reused across frameworks.