Evidence demonstrates that the system operates
ISO 27001 evidence is the objective information that supports a claim about the ISMS or a control. It can take many forms: system configuration, logs, reports, tickets, approvals, meeting records, training records, supplier reviews, test results, screenshots and other operational artefacts. The important question is not whether something “looks like evidence” but what assertion it supports.
For example, a policy requiring quarterly access reviews demonstrates the requirement, not that the reviews occurred. Evidence of completed reviews, decisions and resulting access changes demonstrates operation.
A file should not be collected simply because it was collected last year. Define the control assertion first, then choose evidence that demonstrates it.
Good evidence is attributable, relevant and current
Useful evidence should make it reasonably clear where it came from, what period it relates to and how it supports the control or requirement. A screenshot with no date or context may be difficult to rely on later. A report generated from an authoritative system, stored with the review decision and linked to the relevant control, provides stronger traceability.
Frequency should reflect the control. Some evidence is event-driven, some monthly or quarterly, and some can remain valid until a material change occurs. Treating every evidence item as an annual upload creates unnecessary work and can leave important controls unmonitored between audits.
Evidence should support management before it supports the auditor
The most valuable evidence model helps the organisation detect issues itself. Missing backups, incomplete training, stale access reviews or unresolved vulnerabilities are management information before they are audit findings. Evidence collection should therefore support current assurance rather than exist only as a certification archive.
When evidence is linked to controls, owners and review dates, gaps become easier to identify and audit preparation becomes a by-product of operating the system well.
Make this easier to manage in OrcaComply
OrcaComply keeps the decisions, owners, documents, controls and evidence behind your ISMS connected so the work is easier to manage and easier to explain.
Explore evidence management →