compliance audit evidence quality checklist
Direct answer. An audit evidence pack is useful only if each item answers the question being asked. Before submission, identify the requirement or control, the period and site, the person or asset involved, and the assertion the record is meant to prove. Then check the item's source, date, completeness, authenticity and any contradictory evidence. A certificate may prove a qualification was awarded; it may not prove the person was authorised for a particular task on a particular day. A signed policy proves acknowledgement, not necessarily that the procedure was followed. Where a gap remains, say so and describe the control or corrective action rather than filling it with an irrelevant attachment.
This is a record-quality decision at the point of review. It is different from building a multi-site audit evidence register, which is covered by the first Next-200 multi-site evidence register guide, and from a client tender pack, which serves a buyer's pre-award request. The question here is whether a proposed piece of evidence supports a specific conclusion.
Start with the claim, not the file
Teams often collect every PDF in a folder and hope the auditor finds the answer. Reverse the process. Translate the request into a testable statement: “This lifting accessory had the required examination before use on 12 September”; “this worker completed the required site induction before entering”; or “this policy version was approved and communicated to the people to whom it applied.” Only then identify the records that support that statement.
One file may answer part of the question. An examination report may establish a test date and findings but not show that a defect was rectified. A training certificate may show course attendance but not current competence or task authorisation. A risk assessment may show planned controls but not whether they were used on the day of work. Where the assertion has several elements, use a chain of evidence: source finding, action, completion proof and verification, for example.
HSE describes management as a cycle of planning, doing, checking and acting, with monitoring and reporting as vital parts of the “check” stage. A document library is not a substitute for checking whether controls operate. HSE, Plan–Do–Check–Act: Check.
Seven quality tests for an evidence item
1. Relevance
Does the item address the exact requirement? A public-liability policy does not establish professional-indemnity cover; a generic induction is not necessarily a site-specific one. If a customer asks for a named worker's qualification, do not send an organisation-wide training policy. Record which part of the requirement the item covers and what remains unproved.
2. Correct scope
Check the legal entity, worker, contractor, property, site, asset, process and task. A certificate for a parent company may not cover a subsidiary. A report for one lift is not evidence for the second lift in the same building. A branch-wide statement may not prove each location's actual implementation.
3. Correct time
Was the evidence valid when the activity occurred and for the period the reviewer is testing? A current certificate does not necessarily prove that a previous lapse never occurred. Conversely, an expired certificate may still be valid historical evidence for a period before its expiry. Keep issue date, effective date, review date, expiry date and activity date distinct.
4. Provenance and authenticity
Who created the record, under what authority, and can the issuing body or source be checked? Inspect the document's complete text, not just a screenshot of a badge. Look for a reference number, scope, signature or other verification route where relevant. Do not assume that the presence of a file in a platform means its contents have been independently verified. For a third-party credential, use the issuer's verification method when that is part of the decision.
5. Completeness
Are all pages, schedules, limitations and findings present? The cover page of an inspection report may show a date while the annex lists defects. A policy may have an endorsement excluding the activity at issue. The record should be readable and retrievable, with any referenced attachment available. If a data export loses context or version history, preserve those fields in the evidence pack.
6. Consistency with other evidence
Does another record contradict the proposed item? A contractor might present a current insurance certificate while the register names a different entity; a training log might say a worker was inducted before their start date; an action may be marked closed while a defect report remains open. Do not suppress contradictory material. Investigate the mismatch and record the resolution, or disclose the gap.
7. Proof of operation
Where the claim is that a control worked, seek evidence of actual use: a completed check, supervisor observation, sampled transaction, maintenance record or effectiveness review. The design of a control and its operation are separate assertions. The ICO says its data-protection audits assess effective controls alongside suitable policies and procedures; its framework asks organisations to test their practices rather than treat a tick-box as guaranteed compliance. ICO audits; audit framework.
These are practical review tests, not a universal statutory checklist. The evidence required by a regulator, certification body, client or particular law may differ. Read the actual request and controlling rules.
Build a simple claim-to-evidence matrix
For each audit question, record the requirement source, claim, relevant entity/site/period, primary evidence, supporting evidence, reviewer, result and gap. Use one row per material assertion, not one row per attachment. A single document can be linked to several rows if it truly supports each; many documents may support one row.
An example:
| Claim | Primary record | Supporting record | Review decision |
|---|---|---|---|
| Worker was inducted before first shift at Site A | Dated Site A induction record | Start-date/roster record | Match worker identity and timing |
| Defect was made safe pending repair | Defect report and isolation instruction | Supervisor log/photo | Confirm control was in place for relevant period |
| Permanent repair was effective | Engineer repair report | Return-to-service test or competent review | Do not infer effectiveness from a purchase order |
The matrix makes omissions visible. It also reduces over-sharing: reviewers can provide the relevant record rather than a whole folder of personal or commercially sensitive material.
Review sensitive and third-party material before sharing
Audit evidence often contains names, addresses, health information, incident details, customer contracts or price terms. Confirm who is entitled to receive what, redact or restrict where appropriate, and keep a record of the disclosure route. Do not make a public link to a worker's qualification file simply because a customer asked for evidence. Where a supplier has given a document for a specific purpose, check the contractual and data-protection basis for sharing it more widely.
The ICO's records management framework recommends documented responsibilities and processes for records. Its current data-protection audit framework is under review after the Data (Use and Access) Act, so check the live guidance at publication. This article does not prescribe a universal retention period or lawful basis.
If the auditor can inspect a controlled system rather than receive a bulk copy, that may preserve context and access limits. Agree scope and practical method before a deadline. A “share all” export can be both less useful and more risky than a targeted response.
What to do when evidence is missing or weak
Do not backdate a record, recreate a signature or label a draft as approved. Record what is known, what cannot be evidenced and whether any other reliable source can corroborate the event. Decide whether the underlying control is currently effective and act on any present risk. Assign a corrective action to fix the process that caused the gap, with an owner and deadline; keep the audit response factually separate from the future fix.
For example, if an inspection was performed but its report cannot be found, obtain the issuer's original record if available. If it was not performed, arrange the required inspection and decide whether the affected equipment can remain in use meanwhile. A later inspection does not erase the historical gap. This distinction is essential to credible assurance.
Common mistakes
- Sending a file because its name matches the query without checking its contents.
- Using today's valid certificate to claim continuous historic coverage.
- Treating policy approval as evidence that staff followed the policy.
- Uploading only a report's front page and missing the limitations or defects annex.
- Marking an action done because a contractor invoice was paid, with no completion verification.
- Ignoring records that contradict the preferred answer.
- Creating duplicate copies of sensitive material instead of controlled links and limited access.
- Claiming that a software “verified” badge is an independent decision without understanding how it was produced.
How software can help, and what it cannot decide
A good evidence system should make it easier to link a record to its obligation, site, asset or worker; see the record's dates and version; restrict access; export a targeted pack; and record a review decision. Ask a vendor to demonstrate these functions with a real question and a deliberately contradictory document. The existing permissions and audit-trail buyer guide can help frame that test.
Complys can be evaluated as a place to organise compliance documents and their context. This draft does not assert that the current product authenticates every third-party record, judges legal sufficiency or automatically reconciles contradictory evidence. Those are human or specialist decisions unless a particular verified workflow says otherwise.
Next step: pick one recent audit question and trace the proposed evidence through the seven tests. If the record proves only part of the claim, narrow the claim or find the missing evidence before submission.
Primary sources
- HSE, Plan–Do–Check–Act: Check and risk assessment steps.
- ICO, audits, data-protection audit framework and records management framework. The framework is under review as noted by ICO.
Reviewed 4 October 2026. The actual audit scope and applicable regulator or scheme determine what evidence is required; financial-audit terminology is not assumed to govern every operational compliance review.
Organise the records this involves
Complys gives you one place to store, track and share the compliance records and evidence described here. Legal and assessment decisions stay with you and the relevant authority.
Explore →