Most of SOC 2, ISO 27001, and HIPAA overlaps on the same security fundamentals. This is a starting checklist of the evidence auditors most often ask for, grouped by domain. Attach these to the matching controls in your program and you'll close a large share of any framework.
Download the full handbook: the Compliance Program Handbook & Evidence Workbook (PDF) is a complete, ~17-page guide — instructions and fillable forms for every domain below, a page-numbered table of contents, framework reference, and lite/enterprise tracks. Print it or hand sections to owners.
Access control & identity
- MFA enforced on email, VPN, admin consoles, and cloud accounts (screenshot/config export).
- Access control / identity policy (document).
- User access list and last quarterly access review (record with date and reviewer).
- Onboarding and offboarding checklists showing access granted/revoked (completed examples).
- Password / authentication policy and its enforced settings.
Encryption
- Disk / volume encryption enabled on servers and laptops (config export).
- TLS enforced on public endpoints (scan or config).
- Encryption-at-rest for databases and object storage (settings).
- Key management approach (document).
Logging & monitoring
- Central logging enabled and retained (config + retention setting).
- Alerting on security events (sample alert / configuration).
- Evidence someone reviews alerts (a triaged alert or ticket).
Vulnerability & patch management
- Vulnerability scanning configured and running (schedule + sample report).
- Patch/update policy and evidence of patching cadence (ticket or report).
- Remediation of a real finding (before/after or ticket).
Backups & disaster recovery
- Backups configured for critical systems (config).
- A tested restore (record of the test with date and result).
- Business continuity / disaster recovery plan (document).
Incident response
- Incident response plan with roles and steps (document).
- Evidence of a test or tabletop exercise (record).
- A closed incident or ticket showing the process ran (example).
Vendor / third-party risk
- Vendor inventory listing who holds your or your customers' data.
- Security reviews of key vendors (their SOC 2/ISO report or a completed questionnaire).
- Data processing / breach-notification terms in vendor contracts.
HR & security awareness
- Background-check policy and evidence for recent hires.
- Security awareness training completion records.
- Signed acceptable-use / confidentiality agreements.
Governance & risk
- Information security policy set, approved and dated.
- A documented risk assessment and risk treatment/remediation plan.
- Change management process and an example change (ticket).
- (HIPAA) Risk analysis, workforce sanctions policy, and Business Associate Agreements (BAAs).
Tip: Favor dated, system-generated evidence (exports, logs, tickets, completed reviews) over hand-made documents — it's more credible to an auditor and far easier to refresh next year. See what evidence to collect.
