Guide

Evidence auditors accept, and evidence they merely tolerate

A screenshot proves a setting was correct on the day somebody remembered to take it. Most compliance evidence is exactly that, and everyone involved knows it.

The problem with the screenshot

The standard artefact in most compliance programmes is an image of a configuration screen, pasted into a document, dated by whoever took it. It shows one setting, at one moment, as rendered to one person — and it is trivially staged, accidentally or otherwise.

Auditors accept them because the alternative has historically been nothing. That is tolerance, not confidence, and it is why the same control gets re-evidenced every single year.

What better evidence has

  • It is reproducible. Anyone with access can re-run it and get the same answer, rather than trusting an image.
  • It covers a period, not an instant. "This held every day for twelve months" is a different claim from "this was true in March".
  • It knows what it could not check. Evidence that reports "not assessed" where it lacked access is more credible than evidence that quietly reports a pass.
  • It is tamper-evident. A record that can be shown not to have been edited after the fact is worth more than one that merely has not been.
  • It maps to the control, not to a product feature — so it can satisfy overlapping requirements in several frameworks at once.

What cannot be automated, however good the tool

This is where most compliance vendors get vague, so plainly: a large share of any framework is not technical and never will be. Board oversight. Whether people took the training and understood it. Whether your risk assessment reflects reality. Physical security. Whether the vendor review actually happened or a box was ticked.

For a sense of scale from a real catalogue: GDPR runs to 91 controls of which roughly 2 can be proved from configuration. It is a process regime with a technical footnote, and any tool claiming to make you GDPR compliant is selling you something that does not exist.

Conversely, ISO 27001 and cloud-specific baselines sit near half automatable, because they are written about systems. Knowing which half you are looking at is most of the skill.

A practical split

  1. Automate everything that lives in configuration, and re-run it continuously rather than annually.
  2. Attest the rest deliberately, with a named owner and an expiry date, so an attestation cannot outlive its truth.
  3. Never let a gap score as a pass. A control you could not assess is a control you do not have evidence for, and recording it as green is how programmes rot.
  4. Keep the security finding visible after the waiver. Waiving a control changes the report; it does not change the estate.

The test to apply

For any control in your programme, ask: if my auditor asked me to demonstrate this right now, live, could I? If the answer is "I would have to go and take a screenshot", that control is evidenced by memory and goodwill rather than by proof.

Start with a free assessment and find out what evidence you already have.

See what your scans already prove