Documentation

Compliance Workspace · Reference

Evidence checklist

A practical, framework-agnostic checklist of the evidence auditors ask for — by domain (access, encryption, logging, backups, incident response, vendor risk, HR, policies) — with a downloadable PDF.

Most of SOC 2, ISO 27001, and HIPAA overlaps on the same security fundamentals. This is a starting checklist of the evidence auditors most often ask for, grouped by domain. Attach these to the matching controls in your program and you'll close a large share of any framework.

Download the full handbook: the Compliance Program Handbook & Evidence Workbook (PDF) is a complete, ~17-page guide — instructions and fillable forms for every domain below, a page-numbered table of contents, framework reference, and lite/enterprise tracks. Print it or hand sections to owners.

Access control & identity

  • MFA enforced on email, VPN, admin consoles, and cloud accounts (screenshot/config export).
  • Access control / identity policy (document).
  • User access list and last quarterly access review (record with date and reviewer).
  • Onboarding and offboarding checklists showing access granted/revoked (completed examples).
  • Password / authentication policy and its enforced settings.

Encryption

  • Disk / volume encryption enabled on servers and laptops (config export).
  • TLS enforced on public endpoints (scan or config).
  • Encryption-at-rest for databases and object storage (settings).
  • Key management approach (document).

Logging & monitoring

  • Central logging enabled and retained (config + retention setting).
  • Alerting on security events (sample alert / configuration).
  • Evidence someone reviews alerts (a triaged alert or ticket).

Vulnerability & patch management

  • Vulnerability scanning configured and running (schedule + sample report).
  • Patch/update policy and evidence of patching cadence (ticket or report).
  • Remediation of a real finding (before/after or ticket).

Backups & disaster recovery

  • Backups configured for critical systems (config).
  • A tested restore (record of the test with date and result).
  • Business continuity / disaster recovery plan (document).

Incident response

  • Incident response plan with roles and steps (document).
  • Evidence of a test or tabletop exercise (record).
  • A closed incident or ticket showing the process ran (example).

Vendor / third-party risk

  • Vendor inventory listing who holds your or your customers' data.
  • Security reviews of key vendors (their SOC 2/ISO report or a completed questionnaire).
  • Data processing / breach-notification terms in vendor contracts.

HR & security awareness

  • Background-check policy and evidence for recent hires.
  • Security awareness training completion records.
  • Signed acceptable-use / confidentiality agreements.

Governance & risk

  • Information security policy set, approved and dated.
  • A documented risk assessment and risk treatment/remediation plan.
  • Change management process and an example change (ticket).
  • (HIPAA) Risk analysis, workforce sanctions policy, and Business Associate Agreements (BAAs).

Tip: Favor dated, system-generated evidence (exports, logs, tickets, completed reviews) over hand-made documents — it's more credible to an auditor and far easier to refresh next year. See what evidence to collect.

Need a hand with Compliance Workspace?Talk to our team →