Back to blog
Audit

The compliance evidence matrix: what each framework actually asks you to produce

Auditors do not ask for controls, they ask for artefacts. A control-domain-by-framework matrix of the evidence ISO 27001, SOC 2, the NCA ECC and PCI DSS expect - and the ones organisations never have ready.
GRC Copilot Team
The compliance evidence matrix: what each framework actually asks you to produce

Frameworks are written in the language of controls; audits are conducted in the language of artefacts. The gap between the two is where preparation goes wrong — teams implement the control, then discover during fieldwork that it produces nothing an auditor can sample.

The matrix

Evidence expectations by control domain across the four frameworks most organisations face. Where a cell says the same thing, that is the point: one artefact usually satisfies several frameworks at once, provided it is stored once and mapped to each.

DomainISO 27001SOC 2NCA ECCPCI DSS
Access management Access review records; joiner/leaver tickets; SoA entry Sampled provisioning and termination tickets; access review export Review records; MFA configuration evidence Quarterly review; MFA into the CDE; unique IDs per user
Change management Change records showing approval separate from author Sampled changes with approval, testing and rollback Change procedure plus records Change records; segregation of test and production
Vulnerability management Scan reports; remediation within stated SLA Scan cadence plus remediation tickets Scan reports; defined remediation timelines Quarterly internal and external scans; authenticated scanning; ASV scans
Backup and recovery Backup config; restore test records Backup monitoring; restore evidence Backup policy; restore test evidence Backup procedures; secure storage
Logging and monitoring Log retention config; evidence logs are reviewed Alerting configuration; sampled alert handling Retention period; monitoring evidence Daily log review (automated); one year retention, three months searchable
Incident management Incident register; post-incident reviews Sampled incident tickets end to end Incident procedure; regulator notification records Incident plan; annual test evidence
Supplier / third party Supplier register; assurance reviewed; contract clauses Vendor assessments; subservice carve-out disclosures Contract security requirements; supplier reviews Service provider list; written agreements; monitoring
HR security Screening records; policy acknowledgements; training completion Background checks; onboarding evidence; awareness training Screening; awareness records Screening for CDE personnel; annual awareness
Governance Management review minutes; internal audit reports; risk register System description; management assertion Approved strategy; governance evidence Approved policy; assigned responsibilities per requirement

Store evidence once, satisfy every framework

GRC Copilot files each artefact against every control it satisfies across your frameworks, so one access review export answers four requirements.

The evidence nobody has ready

Across all four frameworks, the same artefacts are missing at fieldwork:

  • Restore test records. Backups run; almost nobody evidences a tested restore.
  • Evidence that logs are reviewed — retention is configured, review is not demonstrated.
  • Policy review records where nothing changed. "Reviewed, no changes required" with a date and a name is valid; silence is a finding.
  • Approval evidence for the policy itself — the document claims board approval, the minutes do not mention it.
  • Supplier assurance reports that were actually read, rather than filed.

What cannot be produced late

Anything dated. Four quarterly access reviews take four quarters. Training completion records exist only if training happened. An incident register cannot be reconstructed. This is why the audit timeline has a floor that budget cannot lower — and why starting evidence collection is more urgent than finishing remediation.

Making one artefact count four times

The practical discipline: store evidence in one place, name it so it is findable, date it, and map it to every requirement it satisfies. Organisations that keep a folder per framework end up regenerating the same export three times and maintaining three sets that drift apart.

Frequently asked questions

Are screenshots acceptable?

Weakly, for configuration. They are undated and croppable. System exports and tickets are far stronger; if you must screenshot, capture the whole screen including the timestamp.

How long should evidence be retained?

Through the current certification cycle plus the previous one — commonly three years — subject to data protection limits pulling the other way.

Can one export satisfy several frameworks?

Yes, and it should. The same quarterly access review answers ISO, SOC 2, the ECC and most customer questionnaires simultaneously.

What is the single most requested artefact?

Access review records. It is the most sampled control in every framework in this table.

Key takeaways

  • Auditors sample artefacts, not controls — a control with no output cannot be tested.
  • Restore tests and log-review evidence are the most consistently missing.
  • Dated evidence cannot be produced retrospectively; start collecting first.
  • Map one artefact to every requirement it satisfies instead of duplicating folders.
#evidence #matrix #iso-27001 #soc-2 #nca-ecc #audit-preparation