A control is only as strong as its evidence
Auditor Joseph Kirkpatrick’s discussion of ISO 27001 reinforces a rule that applies equally to SOC 2: a control must be designed, operated and evidenced. A policy may describe intent, but an auditor needs reliable proof that the activity happened across the review period.
This does not mean creating screenshots for auditors. The best evidence is produced naturally by a well-designed process.
Separate design from operation
Evidence should answer two different questions. First, is the control designed to address the risk? Second, did it operate consistently?
| Control | Design evidence | Operating evidence |
|---|---|---|
| Access review | Procedure, scope, frequency and reviewer | Complete population, review decisions and removals |
| Change management | Workflow and approval criteria | Sampled tickets, testing, approval and deployment logs |
| Vulnerability management | Scanning and remediation standard | Scan results, tickets, exceptions and closure proof |
| Supplier review | Due-diligence method and risk tiers | Assessments, contracts, findings and follow-up |
| Incident response | Plan, roles and severity model | Incident records, exercise results and improvements |
Prove population completeness
A sample is only meaningful when the source population is complete. Before selecting access reviews, changes, incidents or suppliers, retain how the population was generated, the period covered and any filters applied.
Reconcile totals to an independent source where possible. For example, compare the change export to deployment records or the employee list to the identity platform. This prevents a clean sample from hiding omitted items.
Build evidence ownership into the control
Every control should identify its operator, reviewer, frequency, source system, evidence location and exception route. Avoid shared folders filled with unexplained screenshots. Evidence should show who acted, when, on what population and with what result.
Evidence quality test
- Relevant: Does it prove the control objective?
- Reliable: Is the source trustworthy and tamper-resistant?
- Complete: Does it cover the required systems, people and period?
- Timely: Was the control performed at the defined frequency?
- Reviewable: Can another competent person reproduce the conclusion?
Reuse evidence across ISO 27001 and SOC 2 carefully
One access-review record may support both frameworks, but mappings do not remove differences in scope, criteria or reporting period. Maintain one control description and evidence source, then map it to the applicable ISO clauses, Annex A controls and SOC 2 criteria.
Document any gap. A control operating annually may satisfy one internal decision but be too infrequent for the risk or customer commitment being tested.
Create an evidence calendar
Continuous readiness requires scheduled collection and review. Monthly controls should not be reconstructed at year-end. Use a calendar that flags missed operation, incomplete evidence and overdue exceptions while there is still time to correct them.
Priority evidence often includes access reviews, security training, vulnerability remediation, backup tests, incident exercises, supplier reviews, risk treatment, internal audit and management review.
Readiness questions before the auditor arrives
- Is the scope consistent across the ISMS, systems and customer commitments?
- Can each control owner explain the risk and evidence?
- Are populations complete and samples traceable?
- Do exceptions show approval, expiry and remediation?
- Has internal audit challenged effectiveness, not just documentation?
- Has management review made recorded decisions?
ICyberWave perspective
Evidence-first design reduces audit disruption and improves the control environment between audits. ICyberWave supports ISO 27001 implementation, SOC 2 readiness, evidence mapping, internal audit and corrective action. Use our ISO 27001 audit checklist and SOC 2 compliance checklist to assess readiness.

