How to Organize Assessment Evidence
Evidence that exists but cannot be found is evidence you will reconstruct. A practical structure for organising records so retrieval takes minutes rather than days.
Most organisations preparing for an assessment do not have an evidence shortage. They have an evidence findability problem — records exist, spread across mailboxes, shared drives, ticket systems and one person's laptop.
The fix is structural and takes about a day to set up.
Index, do not centralise
The instinct is to copy everything into one repository. This creates a second problem: the copy drifts from the source, and now you have two versions of the truth and no way to tell which is current.
What you need is an index, not a warehouse. For each activity: what record demonstrates it, who produces it, and where the authoritative copy lives.
Records mostly stay where they are generated — in the ticket system, the HR system, the access management tool. The index tells you where to look and who to ask.
Centralise only where the source is genuinely unstable: an individual's mailbox, a personal drive, a chat thread. Those are not storage.
Organise by activity, not by requirement number
This is the most consequential structural choice, and it is easy to get wrong.
Filing evidence under catalogue references feels tidy and couples your entire archive to one catalogue version. When the catalogue changes, every folder name is wrong.
Filing by activity — "quarterly access review", "supplier assessment", "management review" — is stable. Activities do not get renumbered. Keep a separate mapping table that says which requirement each activity satisfies, and a version change then costs you an afternoon updating one table.
This is an ISAREADY recommendation rather than a requirement, but it is the recommendation we make most insistently.
Make each record self-contained
A record should answer, on its own, four questions: what happened, when, who did it, and what the outcome was.
That sounds obvious and is routinely violated. A spreadsheet of reviewed accounts with no date, no reviewer and no indication of what changed answers one of the four.
A practical minimum header for any evidence document:
- Activity and scope covered
- Date performed
- Person responsible
- Outcome, including what changed as a result
- Approval, where the activity requires one
Add this once as a template and the problem stops recurring.
Naming that survives other people
Consistent naming matters less than people think and more than nothing. A workable convention:
YYYY-MM-DD_activity_scope
For example: 2026-04-12_access-review_production-systems. Sortable, unambiguous, and legible to someone who did not create it.
The specific convention matters far less than having one and applying it. Two conventions applied inconsistently is worse than one applied imperfectly.
Define retention, then apply it
Two failure modes: everything kept forever, or things disappearing unpredictably.
Both are awkward to explain, and the second is worse — an evidence archive with unexplained holes raises more questions than a sparse one.
Write down a retention rule per record type. Retain long enough to demonstrate the activity across at least one full cycle of whatever it is, consistently with any legal obligation. Then actually apply it, which mostly means periodically checking that nothing important is being deleted by a general storage policy nobody remembers configuring.
Test retrieval on a schedule
The test: pick one control and ask for representative, current evidence. Time how long it takes.
Run it quarterly, on a different control each time. It costs almost nothing, it surfaces single points of failure — the activities where the answer starts "I'll need to ask…" — and it turns evidence readiness from an opinion into a measurement.
We use a deliberately demanding version: twelve months of evidence, retrieved within one working day. That is an ISAREADY benchmark, not a requirement. No framework we are aware of specifies a retention period or a retrieval time in those terms, and you should be sceptical of anyone who tells you otherwise. Pick a period that is representative for how often the activity actually runs.
Handling evidence about people
Awareness participation records, competence matrices and access reviews contain personal data. Organising them well and handling them lawfully are the same exercise, not competing ones.
Keep them within your normal data protection arrangements: the same retention discipline, the same access restrictions, the same records of processing. Where a data protection scope applies to your organisation, connect it to the security programme rather than running it separately — same incident route, same supplier assessment, same reviews.
What good looks like
A short index, mostly pointing at systems rather than folders. Records that carry their own context. A naming convention someone else can follow. A retention rule that is written down and applied. And a quarterly retrieval test whose result nobody has to guess at.
None of it is sophisticated. All of it is the difference between a final month spent reviewing and a final month spent reconstructing.
Our evidence management guide covers what to prepare theme by theme, and the free readiness checklist pairs each activity with its expected record.
- evidence
- organisation
- retention
How ready is your organisation?
The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.
Start Free Assessment