Readiness practice
Evidence management: decide the record before the activity happens
Of everything in a readiness programme, evidence is the theme most often left until last and the one that most reliably determines how the final month feels. The organisations that find preparation calm are not the ones with better controls — they are the ones that decided, in advance, what record each activity would leave behind.
Last updated 11 August 2026 · ISAREADY Editorial Team
The problem, stated plainly
A common conversation: the access review happened. Somebody did it. It was thorough. Now, six months later, produce the record. It is in an email thread. The person who ran it has changed roles. Nobody can say exactly what was in scope or what changed as a result.
The control was fine. The evidence was not. And the cost of fixing it afterwards is far higher than the cost of deciding, before the review, that it would produce a one-page record with scope, reviewer, date and outcome.
The evidence map
The core artefact is unglamorous: a table with one row per key activity and four columns.
- Activity — the thing that happens. “Quarterly access review of in-scope production systems.”
- Record — what demonstrates it happened. “Review record listing systems checked, reviewer, date, and changes made.”
- Owner — who produces it. A person.
- Location — where it lives, specifically enough that someone else could find it.
ISAREADY recommendation The evidence map is an ISAREADY construct. No framework requires you to keep one. We recommend it because it converts “we should keep better records” into an assignable piece of work.
What makes a record usable
Three properties, and the third is the one usually missing.
- Dated. When it happened, not when the file was last saved.
- Attributable. Who did it or approved it. “The team” is not attribution.
- Retrievable. Findable by someone who is not the author, within a reasonable time, without a search operation.
Retrievability is where most evidence quietly fails. It exists, technically, in a mailbox or a personal drive. The blunt test: pick a control, ask for representative, current evidence, and see how long it takes. If the answer is “a few days, and I will need to ask two people”, you have found a real gap.
ISAREADY recommendation Our demanding version of that test is “twelve months, within one working day”. Treat those numbers as an ISAREADY stress test rather than a requirement: they are chosen to expose weak spots, and no framework we know of specifies a retention period or a retrieval time in those terms. What is representative depends on how often the activity runs.
What to prepare, by theme
A practical starting set. This is ISAREADY guidance on what typically demonstrates each activity — not a list of official requirements.
- Governance — approved scope statement; role assignments; management decisions on objectives and resources.
- Policies — approved documents with version and date; distribution or acknowledgement records; review records.
- Risk — documented method; register with owners and treatment actions; dated acceptance of residual risk.
- Access — authorisation records; dated review records showing scope and resulting changes; leaver completions.
- Awareness — material, plus participation records by individual.
- Incidents — incident records with classification, actions, timeline and closure, including the minor ones.
- Suppliers — third-party register; agreed requirements; completed assessments; follow-up log showing closure.
- Continuity — test reports with date, scope, result and follow-up.
- Internal audit — programme, checklists, reports, findings log with verified closure.
- Management review — agenda, input pack, minutes with decisions and actions.
The readiness checklist pairs each of these with the activity it belongs to, in a form you can hand to the person who owns it.
Evidence anti-patterns
- The pre-assessment sprint. Producing four weeks of records in four days. It shows, and it is exhausting.
- Evidence that only proves existence. A policy proves a rule exists. It does not prove the rule operates.
- Screenshots of everything. Undated, unattributed, and usually of a screen nobody else can navigate to.
- One person who knows where everything is. A single point of failure dressed as competence.
- Retention with no rule. Either everything is kept forever, or things disappear unpredictably. Both are hard to explain.