What Counts as ISO 27001 Audit Evidence?
Useful evidence is relevant, reliable and sufficient to support a conclusion about a control or requirement.
Policies show design intent
Policies and procedures prove that the organisation documented expectations. They do not prove those expectations were followed.
Operating records show execution
Examples include access-review records, system logs, tickets, approvals, security reports, training completion, backup restore tests, incident records and supplier reviews.
System exports are stronger when provenance is clear
Record where the export came from, who collected it, when it was collected, what period it covers and whether filters were applied. Screenshots without context can be ambiguous.
Evidence can require corroboration
An interview plus a system export plus an approval record can support a stronger conclusion than any one item alone.
Evidence should map to the test
Do not collect documents because they look security-related. Define the control objective and test procedure first, then collect evidence that answers that test.
Use the Readiness Review to define scope and the first assessment.