Direct answer: Evidence is an artefact a control produced, with a date, and it goes stale. The structure that survives is a register where every artefact is attached to the controls it proves, has a named owner, and has a refresh date derived from the control's cadence. Collect once and map to every framework that asks, because the same access review record satisfies SOC 2, ISO 27001 and HIPAA at the same time if it is filed somewhere all three can reach.
What counts as evidence
The distinction that matters: a document describing a control is not evidence of the control. A policy saying access is reviewed quarterly evidences nothing. The completed review, dated, naming the reviewer and showing what changed, evidences the control.
Auditors sample. They pick a period, ask for the artefact that control produced during it, and check that it exists, is dated inside the period, and shows the control doing what the description claims. Everything else is context.
The shapes that get accepted are consistent across firms. Exports with timestamps and the person who ran them. Tickets showing a request, an approval and a completion. Signed or acknowledged records for policies and training. Reports from tools with the configuration visible. Screenshots are the weakest form and are accepted mainly where nothing else exists, because they can be taken at any time and show nothing about the period.
Why evidence goes stale
Every artefact has an implicit expiry driven by the cadence of the control it proves. A quarterly access review record covers a quarter. A penetration test report covers a year, and less than that if the environment changed materially. Training completion covers the cycle it was run in, and not the person who joined last month.
Teams get caught because the artefact still exists and looks fine. The file is there, it is titled correctly, and it is fourteen months old. Nothing about the folder tells you it has expired, which is why refresh dates belong on the record rather than in someone's memory.
Structuring the register
Five fields do almost all the work.
The artefact itself, stored somewhere durable rather than in an email thread or a Slack channel with retention limits.
What it evidences, as a list of controls across every framework in scope, not a single one. This is the field that saves the most time later.
Who owns it, by name, meaning who produces the next one.
When it was produced, from the artefact rather than the upload date, because those differ and auditors care about the first.
When it expires, derived from the control cadence, so the register can tell you what is going stale before somebody asks for it.
Collect once, count everywhere
Most companies running two frameworks collect the same evidence twice, in two places, because the two programmes were run by different people at different times. The overlap between SOC 2 and ISO 27001 is substantial, and the overlap between either and HIPAA or PCI DSS on the access, change and monitoring controls is real too.
A quarterly access review record can satisfy SOC 2 CC6.2, ISO 27001 A.5.18 and the HIPAA administrative safeguard on access review in one artefact. Producing it three times is pure waste, and it also produces three slightly different records, which is worse than waste when an auditor notices they disagree.
The mapping is the work. Once it exists, adding a framework becomes an exercise in identifying the genuinely new requirements rather than starting over.
What breaks a register
Evidence collected in a burst before fieldwork, which produces artefacts clustered in one month covering a twelve month period. Auditors notice this immediately and it invites a harder look at everything else.
Artefacts with no owner, which means nobody produces the next one. Free-text titles that differ per framework, which is how you end up with the same document filed twice under different names and a register that cannot tell you your real coverage. And storage that the person who leaves owned personally, which is the most common way evidence is lost outright.
The second audit is the test
The value of a well-kept register does not show in the first audit, where everything was collected recently for the project. It shows in the second, where the auditor asks for evidence covering a twelve month period and the answer is either a register that already holds it, or three weeks of reconstruction that will not fully succeed.
Teams that keep the register current spend fieldwork answering questions. Teams that do not spend it manufacturing a record, which is stressful, expensive, and produces exactly the kind of thin evidence that generates findings.
Our workspace holds the register with the mapping and refresh dates built in, and it is free to use whether or not you work with us. Keeping it current across a year is the part that needs a person, which is what an ongoing retainer covers.
Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.
Talk to usOr talk about a retainer