Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
4 to work through
-
beginner Multiple choice
Your assurance report covers a twelve-month observation window ending 31 March. In February the assessor asks for the pipeline record of every production deploy in that window. CI build logs are kept 90 days and the cloud audit trail 90 days. What do you fix?
3 min answer -
intermediate
An audit requires evidence that controls operated throughout the period. How should that evidence be produced?
2 min answer -
intermediate
Your organisation is preparing for its first SOC 2 audit. The security team is asking engineers for screenshots of configurations. What would you change, and what is the architectural argument?
2 min answer -
advanced
Preparing for an audit consumes weeks of engineering time every cycle. What should change architecturally?
1 min answer
4 terms in this topic
Audit Evidence
Durable, tamper-resistant records demonstrating that a control operated as described, for every instance in the period under review.
practiceEvidence by Construction
Designing systems so that operating them produces the audit evidence automatically, rather than reconstructing it from screenshots when an assessment…
practiceEvidence By-Product
Audit evidence produced automatically by the control operating, rather than assembled by engineers before each audit.
conceptEvidence Retention Window
The span for which control evidence has to stay reproducible - the assurance period plus report lag plus the next cycle - which is routinely far long…
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.