Skip to content

Audit Evidence

What is Audit Evidence?

Records, statements of fact, or other information that is relevant and verifiable, used by an auditor to determine whether audit criteria are being fulfilled. Audit evidence can be qualitative or quantitative.

Audit

What the standards actually require on audit evidence

Requirements naming audit evidence across 3 standards, quoted from the control text.

Suppliers must maintain auditable evidence of Def Stan 05-138 implementation and make it available to the MOD or its representatives on request.

DEFSTAN-AUDIT · Assurance and Audit Evidence Maintenance

Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...

X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records

Independent personnel make certification decisions based on audit evidence and competence review.

27006-8.1 · Certification Decision

Questions people ask about audit evidence

What is Audit Evidence?
Records, statements of fact, or other information that is relevant and verifiable, used by an auditor to determine whether audit criteria are being fulfilled. Audit evidence can be qualitative or quantitative.
Why is Audit Evidence important for compliance?
Audit Evidence is a key concept in Audit. Understanding audit evidence helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Audit Evidence?
Audit Evidence appears in the requirement text of UK Defence Standard 05-138 - Cyber Security for Defence Suppliers, ITU-T X.805 - Security Architecture for End-to-End Communications, ISO/IEC 27006:2024. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Audit Evidence?
Explore our compliance framework pages to see how audit evidence applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Audit Evidence applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.