Skip to content

Evidence request lists

Australia IRAP - Information Security Registered Assessors Program

Evidence request list. 16 controls, 16 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assessment Methodology

IRAP-CAF-1
Stage 1 - Plan and prepare

Plan and prepare the assessment: engage the assessor, agree objectives, and obtain system documentation including the system security plan.

Artefacts an auditor will ask for
  • Engagement/scope agreement
  • System security plan and supporting documentation
  • Assessment plan
Where this commonly fails
  • No documented assessment plan
  • System security plan absent
  • Objectives undefined
IRAP-CAF-2
Stage 2 - Define the assessment boundary

Define the assessment boundary and scope, identifying the assessment objects, controls and system boundary to be assessed.

Artefacts an auditor will ask for
  • Documented assessment boundary and scope
  • Identified assessment objects and applicable controls
  • System boundary diagram
Where this commonly fails
  • Scope/boundary ambiguous
  • In-scope assets not identified
  • Boundary excludes relevant components
IRAP-CAF-3
Stage 3 - Assess the controls

Assess the implementation and effectiveness of controls against the ISM (and other applicable Australian Government frameworks), collecting and reviewing sufficient evidence.

Artefacts an auditor will ask for
  • Controls matrix with effectiveness findings against the ISM
  • Evidence reviewed per control
  • Assessment of implementation effectiveness
Where this commonly fails
  • Controls assessed without sufficient evidence
  • Effectiveness not determined
  • Assessment not tied to the ISM
IRAP-CAF-4
Stage 4 - Produce the IRAP assessment report

Produce the IRAP Security Assessment Report (or Cloud Security Assessment Report) documenting findings, control effectiveness and residual risks.

Artefacts an auditor will ask for
  • IRAP Security Assessment Report / Cloud SAR
  • Controls matrix with findings
  • Residual risk statements
Where this commonly fails
  • No assessment report produced
  • Findings not documented per control
  • Residual risks not stated

Assessment Outcomes

IRAP-OUT-1
Control effectiveness determination

Determine and document the implementation effectiveness of each in-scope control as the basis for the assessment outcome.

Artefacts an auditor will ask for
  • Per-control effectiveness determinations
  • Controls matrix with ratings
Where this commonly fails
  • Effectiveness not determined per control
  • No basis for the outcome
IRAP-OUT-2
Authority to Operate decision support

The assessment informs the system owner's authorisation to operate (ATO) decision; findings and residual risk support the authorising officer.

Artefacts an auditor will ask for
  • Authorisation to operate decision record
  • Residual-risk acceptance by the authorising officer
Where this commonly fails
  • No ATO decision
  • Residual risk not accepted by an authorising officer
IRAP-OUT-3
Continuous monitoring and reassessment

Support ongoing assurance through information security continuous monitoring (ISCM) and periodic reassessment of the system.

Artefacts an auditor will ask for
  • ISCM implementation evidence
  • Periodic reassessment schedule and records
Where this commonly fails
  • No continuous monitoring
  • System not reassessed over time

Evidence and Quality

IRAP-EV-1
Quality of evidence

Aim for the best evidence available, distinguishing excellent, good, fair and poor evidence, with conclusions supported by sufficient-quality evidence.

Artefacts an auditor will ask for
  • Evidence rated by quality (excellent/good/fair/poor)
  • Firsthand examination/testing where possible
Where this commonly fails
  • Conclusions on poor/verbal evidence only
  • Evidence quality not considered
IRAP-EV-2
Evidence gathering and sampling

Gather evidence of sufficient quality and, where sampling is required, apply and clearly explain a sound sampling methodology and sample size.

Artefacts an auditor will ask for
  • Documented sampling methodology and size
  • Representative, genuine (not staged) evidence
  • Historical evidence where relevant
Where this commonly fails
  • Sampling methodology undocumented
  • Unrepresentative or staged samples
  • Sample size inadequate
IRAP-EV-3
Objectivity of findings

Base the assessment on presented evidence and facts, ensuring depth and coverage support an accurate determination of control effectiveness.

Artefacts an auditor will ask for
  • Depth and coverage documented per control
  • Findings substantiated by evidence
Where this commonly fails
  • Findings not substantiated
  • Insufficient depth/coverage
IRAP-EV-4
Document evidence limitations

Where evidence does not adequately support a determination, document the limitation and assessment constraints in the Security Assessment Report and controls matrix.

Artefacts an auditor will ask for
  • Documented evidence limitations/constraints
  • Notation in the controls matrix and report
Where this commonly fails
  • Limitations undocumented
  • Conclusions drawn despite inadequate evidence

IRAP Assessor Program

IRAP-AS-1
ASD endorsement as an IRAP assessor

Only ASD-endorsed IRAP assessors conduct IRAP assessments; endorsement is maintained in accordance with IRAP Policy.

Artefacts an auditor will ask for
  • Evidence of current ASD IRAP endorsement
  • Endorsement maintained per IRAP Policy
Where this commonly fails
  • Assessment conducted by a non-endorsed assessor
  • Endorsement lapsed
IRAP-AS-2
Assessor qualifications and experience

IRAP assessors hold the necessary experience and qualifications in ICT security assessment and risk management, with detailed knowledge of the ISM.

Artefacts an auditor will ask for
  • Assessor CV / qualifications
  • Evidence of ICT security assessment and risk-management experience
  • ISM knowledge
Where this commonly fails
  • Insufficient assessor experience
  • No demonstrated ISM knowledge
IRAP-AS-3
IRAP training and examination

IRAP assessors complete the required IRAP New Starter Training and pass the IRAP assessor examination.

Artefacts an auditor will ask for
  • IRAP New Starter Training completion
  • IRAP examination pass record
Where this commonly fails
  • Training not completed
  • Examination not passed
IRAP-AS-4
Independence and conflict of interest

IRAP assessors declare and manage conflicts of interest and maintain independence from the system being assessed.

Artefacts an auditor will ask for
  • Conflict-of-interest declaration
  • Evidence of independence from the assessed entity
Where this commonly fails
  • Undeclared conflict of interest
  • Assessor not independent of the system
IRAP-AS-5
Objectivity and professional conduct

IRAP assessors present unbiased, evidence-based findings substantiated with sufficient quality evidence, in line with the IRAP code of conduct.

Artefacts an auditor will ask for
  • Evidence-based, substantiated findings
  • Adherence to the IRAP code of conduct
Where this commonly fails
  • Findings not evidence-based
  • Bias or unsupported conclusions
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australia IRAP - Information Security Registered Assessors Program framework page.