Frameworks are written in the language of controls; audits are conducted in the language of artefacts. The gap between the two is where preparation goes wrong — teams implement the control, then discover during fieldwork that it produces nothing an auditor can sample.
The matrix
Evidence expectations by control domain across the four frameworks most organisations face. Where a cell says the same thing, that is the point: one artefact usually satisfies several frameworks at once, provided it is stored once and mapped to each.
| Domain | ISO 27001 | SOC 2 | NCA ECC | PCI DSS |
|---|---|---|---|---|
| Access management | Access review records; joiner/leaver tickets; SoA entry | Sampled provisioning and termination tickets; access review export | Review records; MFA configuration evidence | Quarterly review; MFA into the CDE; unique IDs per user |
| Change management | Change records showing approval separate from author | Sampled changes with approval, testing and rollback | Change procedure plus records | Change records; segregation of test and production |
| Vulnerability management | Scan reports; remediation within stated SLA | Scan cadence plus remediation tickets | Scan reports; defined remediation timelines | Quarterly internal and external scans; authenticated scanning; ASV scans |
| Backup and recovery | Backup config; restore test records | Backup monitoring; restore evidence | Backup policy; restore test evidence | Backup procedures; secure storage |
| Logging and monitoring | Log retention config; evidence logs are reviewed | Alerting configuration; sampled alert handling | Retention period; monitoring evidence | Daily log review (automated); one year retention, three months searchable |
| Incident management | Incident register; post-incident reviews | Sampled incident tickets end to end | Incident procedure; regulator notification records | Incident plan; annual test evidence |
| Supplier / third party | Supplier register; assurance reviewed; contract clauses | Vendor assessments; subservice carve-out disclosures | Contract security requirements; supplier reviews | Service provider list; written agreements; monitoring |
| HR security | Screening records; policy acknowledgements; training completion | Background checks; onboarding evidence; awareness training | Screening; awareness records | Screening for CDE personnel; annual awareness |
| Governance | Management review minutes; internal audit reports; risk register | System description; management assertion | Approved strategy; governance evidence | Approved policy; assigned responsibilities per requirement |
Store evidence once, satisfy every framework
GRC Copilot files each artefact against every control it satisfies across your frameworks, so one access review export answers four requirements.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The evidence nobody has ready
Across all four frameworks, the same artefacts are missing at fieldwork:
- Restore test records. Backups run; almost nobody evidences a tested restore.
- Evidence that logs are reviewed — retention is configured, review is not demonstrated.
- Policy review records where nothing changed. "Reviewed, no changes required" with a date and a name is valid; silence is a finding.
- Approval evidence for the policy itself — the document claims board approval, the minutes do not mention it.
- Supplier assurance reports that were actually read, rather than filed.
What cannot be produced late
Anything dated. Four quarterly access reviews take four quarters. Training completion records exist only if training happened. An incident register cannot be reconstructed. This is why the audit timeline has a floor that budget cannot lower — and why starting evidence collection is more urgent than finishing remediation.
Making one artefact count four times
The practical discipline: store evidence in one place, name it so it is findable, date it, and map it to every requirement it satisfies. Organisations that keep a folder per framework end up regenerating the same export three times and maintaining three sets that drift apart.
Frequently asked questions
Are screenshots acceptable?
Weakly, for configuration. They are undated and croppable. System exports and tickets are far stronger; if you must screenshot, capture the whole screen including the timestamp.
How long should evidence be retained?
Through the current certification cycle plus the previous one — commonly three years — subject to data protection limits pulling the other way.
Can one export satisfy several frameworks?
Yes, and it should. The same quarterly access review answers ISO, SOC 2, the ECC and most customer questionnaires simultaneously.
What is the single most requested artefact?
Access review records. It is the most sampled control in every framework in this table.
Key takeaways
- Auditors sample artefacts, not controls — a control with no output cannot be tested.
- Restore tests and log-review evidence are the most consistently missing.
- Dated evidence cannot be produced retrospectively; start collecting first.
- Map one artefact to every requirement it satisfies instead of duplicating folders.