Skip to content

Evidence request lists

ASIS SPC.1-2009 - Organizational Resilience Standard

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Act

SPC1-4.6
Management Review

Top management reviews the RMS at planned intervals to ensure continuing suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Review minutes
  • Inputs package
  • Actions register
Where this commonly fails
  • Review skipped during turnover
  • No documented outputs
SPC1-A.1
Continual Improvement

Continually improve the effectiveness of the resilience management system through policy, objectives, audit results, and corrective actions.

Artefacts an auditor will ask for
  • Improvement register
  • Trend analysis
Where this commonly fails
  • No improvement metric tracked

Check

SPC1-4.5.1
Monitoring and Measurement

Monitor and measure the performance of resilience activities and controls on a regular basis.

Artefacts an auditor will ask for
  • KPI reports
  • Performance dashboards
  • Measurement procedure
Where this commonly fails
  • No leading indicators
  • Measurement infrequent
SPC1-4.5.2
Evaluation of Compliance

Periodically evaluate compliance with applicable legal and other requirements.

Artefacts an auditor will ask for
  • Compliance review records
  • Findings log
Where this commonly fails
  • No formal review cadence
SPC1-4.5.3
Exercises and Testing

Conduct exercises and tests to validate the resilience management system at planned intervals.

Artefacts an auditor will ask for
  • Exercise schedule
  • Scenarios
  • After-action reports
  • Improvement actions
Where this commonly fails
  • Tabletop only, no functional test
  • No cross-functional exercise
SPC1-4.5.4
Nonconformity, Corrective and Preventive Action

Identify nonconformities and implement corrective and preventive actions to address root causes.

Artefacts an auditor will ask for
  • NC log
  • Root cause analyses
  • CAPA tracker
Where this commonly fails
  • No verification of effectiveness
  • Repeat NCs
SPC1-4.5.5
Records

Establish and maintain records to demonstrate conformity with RMS requirements.

Artefacts an auditor will ask for
  • Records retention schedule
  • Records inventory
Where this commonly fails
  • No retention schedule
SPC1-4.5.6
Internal Audit

Conduct internal audits at planned intervals to determine whether the RMS conforms to requirements and is effectively implemented.

Artefacts an auditor will ask for
  • Audit program
  • Audit reports
  • Auditor competence records
Where this commonly fails
  • No independence
  • Audit scope too narrow

Checking and Corrective Action

4.5.1
Performance Monitoring and Measurement

Organisation shall establish procedures to monitor and measure OR management system performance on a regular basis.

Artefacts an auditor will ask for
  • Incident response plan with playbooks per scenario
  • SIEM log retention and alerting configuration
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
Where this commonly fails
  • Tabletop exercises not run in last 12 months
  • Detection coverage not mapped to MITRE ATT&CK
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Audit findings without closure dates
4.5.2
Evaluation of Compliance

Organisation shall periodically evaluate compliance with applicable legal and other requirements.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • CAPA register with root cause and verification
  • Improvement programme tracker
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Root cause analysis is symptomatic only
4.5.3
Corrective and Preventive Action

Organisation shall establish procedures for taking corrective and preventive action to address nonconformities.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • CAPA register with root cause and verification
  • Improvement programme tracker
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Root cause analysis is symptomatic only
  • Effectiveness checks not performed
  • Evidence is point in time rather than ongoing
4.5.4
Control of Records

Organisation shall maintain records to demonstrate conformity to the OR management system requirements.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • CAPA register with root cause and verification
  • Improvement programme tracker
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Root cause analysis is symptomatic only
  • Effectiveness checks not performed
  • Evidence is point in time rather than ongoing
4.5.5
Internal Audit

Organisation shall conduct internal audits at planned intervals to confirm the OR management system is effectively maintained.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • CAPA register with root cause and verification
  • Improvement programme tracker
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Root cause analysis is symptomatic only

Context

SPC1-4.1
Resilience Management System Scope

Define the scope of the organizational resilience management system including boundaries, locations, and activities.

Artefacts an auditor will ask for
  • RMS scope document
  • Site/asset inventory
  • Exclusion justification
Where this commonly fails
  • Scope omits third-party sites
  • No documented boundary rationale

Implementation and Operation

4.4.1
Resources, Roles, Responsibility, and Authority

Organisation shall ensure availability of resources and define roles, responsibilities, and authorities for resilience management.

Artefacts an auditor will ask for
  • Board or executive committee charter with security or risk remit
  • RACI matrix for accountable owners
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Board reporting cadence not formalised
  • Roles overlap without clear accountable owner
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Evidence is point in time rather than ongoing
4.4.2
Competence, Training, and Awareness

Personnel performing tasks that impact resilience shall be competent based on appropriate education, training, or experience.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Training completion records by role
  • Phishing simulation results
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Role based training not delivered to high risk teams
  • Training metrics not reported to leadership
  • Evidence is point in time rather than ongoing
4.4.3
Communication and Warning

Organisation shall establish procedures for internal and external communication and early warning during incidents.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process owner attestation
  • Tooling configuration export
  • Meeting minutes referencing the control
  • Training material referencing the control
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Evidence is point in time rather than ongoing
  • Control owner unclear or vacant
  • No metric tracks control effectiveness
4.4.4
Documentation

Organisation shall establish and maintain documentation for the OR management system including policy, objectives, and procedures.

Artefacts an auditor will ask for
  • Signed and dated policy set with version history
  • Annual review and approval records
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Policies past their review date
  • No evidence policies were communicated to staff
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Evidence is point in time rather than ongoing
4.4.5
Operational Control

Organisation shall identify operations and activities associated with identified risks and implement controls to manage them.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process maps with defined controls and owners
  • Change control records
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Operational controls not linked to risks
  • Change records missing rollback evidence
  • Evidence is point in time rather than ongoing

Incident Prevention, Preparedness, and Response

4.4.6
Prevention and Mitigation

Organisation shall establish procedures to prevent or mitigate the consequences of disruptive incidents.

Artefacts an auditor will ask for
  • Incident response plan with playbooks per scenario
  • SIEM log retention and alerting configuration
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Tabletop exercises not run in last 12 months
  • Detection coverage not mapped to MITRE ATT&CK
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Evidence is point in time rather than ongoing
4.4.7
Emergency and Incident Response

Organisation shall establish and maintain procedures for responding to emergencies, crises, and disruptive incidents.

Artefacts an auditor will ask for
  • Incident response plan with playbooks per scenario
  • SIEM log retention and alerting configuration
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Tabletop exercises not run in last 12 months
  • Detection coverage not mapped to MITRE ATT&CK
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Evidence is point in time rather than ongoing
4.4.8
Business Continuity and Recovery

Organisation shall establish procedures for continuity and recovery of critical functions during and after disruptive events.

Artefacts an auditor will ask for
  • Incident response plan with playbooks per scenario
  • SIEM log retention and alerting configuration
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Tabletop exercises not run in last 12 months
  • Detection coverage not mapped to MITRE ATT&CK
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Evidence is point in time rather than ongoing
4.4.9
Mutual Aid and Cooperation

Organisation shall establish arrangements for mutual aid and cooperation with external entities during incidents.

Artefacts an auditor will ask for
  • Incident response plan with playbooks per scenario
  • SIEM log retention and alerting configuration
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Tabletop exercises not run in last 12 months
  • Detection coverage not mapped to MITRE ATT&CK
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Evidence is point in time rather than ongoing

Leadership

SPC1-4.2
Resilience Policy

Top management establishes a documented resilience policy appropriate to the organization's risk environment.

Artefacts an auditor will ask for
  • Signed resilience policy
  • Board approval minutes
  • Distribution log
Where this commonly fails
  • Policy not refreshed annually
  • No CEO endorsement

Management Review

4.6.1
Management Review Process

Top management shall review the OR management system at planned intervals to ensure its continuing suitability and effectiveness.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Evidence is point in time rather than ongoing
4.6.2
Review Input

Management review shall include results of audits, evaluations of compliance, stakeholder communications, and incident performance.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Evidence is point in time rather than ongoing
4.6.3
Review Output

Management review outputs shall include decisions and actions related to improvements to the OR management system.

Artefacts an auditor will ask for
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Internal audit programme and findings log
  • Management review meeting minutes with actions
  • Process owner attestation
  • Tooling configuration export
Where this commonly fails
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Audit findings without closure dates
  • Management review skipped one or more cycles
  • Evidence is point in time rather than ongoing

Operation

SPC1-4.4.6
Operational Control

Identify and plan operations associated with significant risks to ensure they are carried out under controlled conditions.

Artefacts an auditor will ask for
  • SOPs
  • Control matrix
  • Records of execution
Where this commonly fails
  • No control mapped to top risks
SPC1-4.4.7
Incident Prevention, Preparedness, and Response

Establish procedures to prevent, prepare for, and respond to incidents and emergencies.

Artefacts an auditor will ask for
  • IR plan
  • Emergency procedures
  • Exercise reports
  • After-action reviews
Where this commonly fails
  • Plans not exercised
  • No lessons-learned process
SPC1-4.4.8
Business Continuity and Recovery

Develop and implement plans for continuity of priority activities and recovery of operations after disruption.

Artefacts an auditor will ask for
  • BCP
  • Recovery plans
  • Strategy options
  • Validation results
Where this commonly fails
  • RTOs misaligned with BIA
  • No alternate site test

Planning

SPC1-4.3.1
Risk Assessment and Impact Analysis

Conduct risk assessment and business impact analysis to identify likelihood and consequences of disruptive events.

Artefacts an auditor will ask for
  • Risk register
  • BIA report
  • Threat scenarios
  • RTO/RPO matrix
Where this commonly fails
  • BIA not refreshed after material change
  • No quantitative consequence rating
SPC1-4.3.2
Legal and Other Requirements

Identify and access applicable legal, regulatory, and other requirements related to resilience.

Artefacts an auditor will ask for
  • Legal obligations register
  • Jurisdictional mapping
  • Review log
Where this commonly fails
  • No owner assigned
  • Stale register
SPC1-4.3.3
Objectives and Targets

Establish measurable resilience objectives and targets at relevant functions and levels.

Artefacts an auditor will ask for
  • Objectives register
  • KPI dashboard
  • Target tracking
Where this commonly fails
  • Objectives not measurable
  • No link to risks
SPC1-4.3.4
Resilience Programs

Establish programs to achieve resilience objectives covering prevention, mitigation, response, continuity, and recovery.

Artefacts an auditor will ask for
  • Program charters
  • Resource allocation
  • Timelines
Where this commonly fails
  • Programs lack assigned owner
  • No timeline tracking

Policy and Planning

4.3.1
Risk Assessment and Impact Analysis

Organisation shall identify and assess risks and impacts from potential internal and external events affecting critical operations.

Artefacts an auditor will ask for
  • Risk register with likelihood, impact, and treatment plans
  • Risk assessment methodology document
  • Signed and dated policy set with version history
  • Annual review and approval records
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
Where this commonly fails
  • Risk register not refreshed on a defined cadence
  • Inherent vs residual risk scoring not documented
  • Policies past their review date
  • No evidence policies were communicated to staff
  • Recovery objectives not tested end to end
4.3.2
Legal and Other Requirements

Organisation shall identify and have access to applicable legal and other requirements related to resilience management.

Artefacts an auditor will ask for
  • Signed and dated policy set with version history
  • Annual review and approval records
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Scope statement signed by management
  • Stakeholder and interested party register
Where this commonly fails
  • Policies past their review date
  • No evidence policies were communicated to staff
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Scope boundaries unclear for cloud services
4.3.3
Objectives and Programs

Organisation shall establish documented resilience objectives and programs at relevant functions and levels.

Artefacts an auditor will ask for
  • Signed and dated policy set with version history
  • Annual review and approval records
  • BCP and DR plan with documented RTO and RPO
  • Backup restore test reports
  • Consent capture and withdrawal logs
  • Data subject request workflow and SLA tracker
Where this commonly fails
  • Policies past their review date
  • No evidence policies were communicated to staff
  • Recovery objectives not tested end to end
  • Backups not verified for integrity
  • Consent records lack timestamp or version

Support

SPC1-4.4.1
Resources, Roles, Responsibility, and Authority

Define and document roles, responsibilities, accountabilities and authorities for resilience activities.

Artefacts an auditor will ask for
  • RACI matrix
  • Job descriptions
  • Authority delegations
Where this commonly fails
  • Role overlap
  • No deputy named
SPC1-4.4.2
Competence, Training, and Awareness

Ensure personnel are competent through education, training, or experience and maintain awareness records.

Artefacts an auditor will ask for
  • Training matrix
  • Completion records
  • Competency assessments
Where this commonly fails
  • No competency baseline
  • Gaps in records
SPC1-4.4.3
Communication and Warning

Establish procedures for internal and external communication including warnings and alerts during disruptions.

Artefacts an auditor will ask for
  • Comms plan
  • Warning protocols
  • Contact tree
  • Test logs
Where this commonly fails
  • Untested call tree
  • Stakeholder list outdated
SPC1-4.4.4
Documentation

Maintain documentation of the resilience management system in any media form.

Artefacts an auditor will ask for
  • RMS manual
  • Document index
  • Version log
Where this commonly fails
  • Multiple versions in circulation
SPC1-4.4.5
Control of Documents

Control RMS documents to ensure they are approved, current, identifiable, and available where needed.

Artefacts an auditor will ask for
  • Document control procedure
  • Approval records
  • Distribution list
Where this commonly fails
  • No retention schedule
  • Obsolete docs not removed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.