Skip to content

Readiness practice

Evidence management: decide the record before the activity happens

Of everything in a readiness programme, evidence is the theme most often left until last and the one that most reliably determines how the final month feels. The organisations that find preparation calm are not the ones with better controls — they are the ones that decided, in advance, what record each activity would leave behind.

Last updated 11 August 2026 · ISAREADY Editorial Team

The problem, stated plainly

A common conversation: the access review happened. Somebody did it. It was thorough. Now, six months later, produce the record. It is in an email thread. The person who ran it has changed roles. Nobody can say exactly what was in scope or what changed as a result.

The control was fine. The evidence was not. And the cost of fixing it afterwards is far higher than the cost of deciding, before the review, that it would produce a one-page record with scope, reviewer, date and outcome.

The evidence map

The core artefact is unglamorous: a table with one row per key activity and four columns.

  • Activity — the thing that happens. “Quarterly access review of in-scope production systems.”
  • Record — what demonstrates it happened. “Review record listing systems checked, reviewer, date, and changes made.”
  • Owner — who produces it. A person.
  • Location — where it lives, specifically enough that someone else could find it.

ISAREADY recommendation The evidence map is an ISAREADY construct. No framework requires you to keep one. We recommend it because it converts “we should keep better records” into an assignable piece of work.

What makes a record usable

Three properties, and the third is the one usually missing.

  • Dated. When it happened, not when the file was last saved.
  • Attributable. Who did it or approved it. “The team” is not attribution.
  • Retrievable. Findable by someone who is not the author, within a reasonable time, without a search operation.

Retrievability is where most evidence quietly fails. It exists, technically, in a mailbox or a personal drive. The blunt test: pick a control, ask for representative, current evidence, and see how long it takes. If the answer is “a few days, and I will need to ask two people”, you have found a real gap.

ISAREADY recommendation Our demanding version of that test is “twelve months, within one working day”. Treat those numbers as an ISAREADY stress test rather than a requirement: they are chosen to expose weak spots, and no framework we know of specifies a retention period or a retrieval time in those terms. What is representative depends on how often the activity runs.

What to prepare, by theme

A practical starting set. This is ISAREADY guidance on what typically demonstrates each activity — not a list of official requirements.

  • Governance — approved scope statement; role assignments; management decisions on objectives and resources.
  • Policies — approved documents with version and date; distribution or acknowledgement records; review records.
  • Risk — documented method; register with owners and treatment actions; dated acceptance of residual risk.
  • Access — authorisation records; dated review records showing scope and resulting changes; leaver completions.
  • Awareness — material, plus participation records by individual.
  • Incidents — incident records with classification, actions, timeline and closure, including the minor ones.
  • Suppliers — third-party register; agreed requirements; completed assessments; follow-up log showing closure.
  • Continuity — test reports with date, scope, result and follow-up.
  • Internal audit — programme, checklists, reports, findings log with verified closure.
  • Management review — agenda, input pack, minutes with decisions and actions.

The readiness checklist pairs each of these with the activity it belongs to, in a form you can hand to the person who owns it.

Evidence anti-patterns

  • The pre-assessment sprint. Producing four weeks of records in four days. It shows, and it is exhausting.
  • Evidence that only proves existence. A policy proves a rule exists. It does not prove the rule operates.
  • Screenshots of everything. Undated, unattributed, and usually of a screen nobody else can navigate to.
  • One person who knows where everything is. A single point of failure dressed as competence.
  • Retention with no rule. Either everything is kept forever, or things disappear unpredictably. Both are hard to explain.

Frequently asked questions

What counts as evidence?
A record that shows a specific activity happened, when, and who was responsible. A policy is evidence that a rule exists; it is not evidence that the rule is followed. The distinction is the whole subject.
How long should we retain evidence?
Long enough to demonstrate the activity across at least one full cycle of whatever it is, and consistently with your own retention rule and any legal obligations. There is no universal number, and anyone quoting one to you should be asked where it comes from. The important part is having a defined rule and applying it consistently.
Can screenshots be evidence?
Sometimes, and they are weaker than people expect. A screenshot shows a state at an unverifiable moment, usually without attribution. Where a system can export a dated report, use the report. Where it cannot, a screenshot with a clear description of what was captured, by whom and when is a reasonable fallback.
Should evidence be centralised in one repository?
It should be findable, which is not quite the same thing. Centralising everything can create a copy that drifts from the source. What matters is an index: for each activity, where the authoritative record lives and who can produce it.
ISAREADY provides independent assessment-readiness resources and practical information security tools. ISAREADY is not affiliated with, endorsed by, or acting on behalf of ENX Association, VDA, ISO or any TISAX audit provider. Use of ISAREADY resources does not guarantee a TISAX assessment result, TISAX label, ISO certification or regulatory compliance.