Audit Evidence
What is Audit Evidence?
Records, statements of fact, or other information that is relevant and verifiable, used by an auditor to determine whether audit criteria are being fulfilled. Audit evidence can be qualitative or quantitative.
Frameworks that govern audit evidence
What the standards actually require on audit evidence
Requirements naming audit evidence across 3 standards, quoted from the control text.
Suppliers must maintain auditable evidence of Def Stan 05-138 implementation and make it available to the MOD or its representatives on request.
DEFSTAN-AUDIT · Assurance and Audit Evidence Maintenance →Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...
X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records →Independent personnel make certification decisions based on audit evidence and competence review.
27006-8.1 · Certification Decision →Questions people ask about audit evidence
What is Audit Evidence?
Why is Audit Evidence important for compliance?
Which compliance frameworks address Audit Evidence?
Where can I learn more about Audit Evidence?
See how Audit Evidence applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.