---
name: audit-evidence-pack
description: Organizes audit requests into evidence tests, evaluates supplied documents for coverage and period, and produces a traceable evidence tracker with control narratives and gaps. Use for SOC, ISO, internal control, customer audit, certification, and audit-readiness preparation.
license: Apache-2.0
metadata:
  adlass.categories: "it-security/audit-evidence, it-security/policies-controls"
  adlass.industries: ""
  adlass.tags: "audit, evidence, controls, compliance, readiness, gaps"
  adlass.adaptation: "reference-doc"
  adlass.source: "original"
  adlass.version: "1"
---

# Audit evidence pack

## Purpose

Turn an audit request list and an evidence corpus into a complete, honest view of what each control can demonstrate. Make missing, stale, partial, and contradictory evidence visible before an auditor asks for it.

## Scope

Control requests, control descriptions, evidence documents, prior findings, and the requested audit period. **Excluded:** fabricating evidence, changing controls, representing a gap as closed, or communicating with auditors.

## Data basis

- Audit request list and control descriptions.
- Evidence folders, records, reports, and policy documents.
- Prior audit findings, remediation status, and evidence-period requirements.

## Result

An evidence tracker, a control narrative document, and a gap-remediation list with citations, period coverage, and accountable roles where available.

## Quality criteria

- Each request has one status: complete, partial, missing, stale, or not applicable.
- Every evidence link or filename has a page, section, row, or equivalent locator.
- Period coverage and control ownership are explicit.
- Prior findings are reconciled to current evidence.

## Instructions

Assess evidence for relevance, completeness, authenticity indicators, period, and frequency. A policy proves intent, not operation. A sample proves only the sampled period and population. Never mark a request complete solely because a similarly named document exists. Keep a clear distinction between evidence found and evidence expected.

The review should make the population, calculation basis, and exception treatment understandable to a second operator. Preserve source identifiers in every working table, and state the effect of missing evidence on the decision. A reviewer must be able to reproduce each material result from the cited rows, clauses, dates, or policy rules. Where two sources disagree, show both values and explain which source was treated as authoritative.

## Adapt before use

- Add the audit request list, control descriptions, and evidence-period rules.
- Define status vocabulary, evidence naming, and citation conventions.
- Add prior findings and remediation closure criteria to the scope.
- Map control owners and required reviewer roles.
