Internal Auditor

Do you request evidence, or do you download it?

If the audited party assembles the evidence, what you receive is not evidence. It is a selection.

How this question is answered today

The audit plan is set, a sample is drawn, evidence is requested from the relevant team. The team gathers it and you wait.

What arrives is screenshots, printed emails and hand prepared spreadsheets. All of it may be accurate. None of it is independent.

The sample is kept small, because gathering evidence for each item costs the team a week. A small sample means narrow assurance.

What that answer costs

Independence is compromised. The audited party selects the evidence and you review what was selected.
If the rules changed, old records are read incorrectly. Yesterday's action cannot be judged by today's rule.
Without a reason for a skipped approval step, you cannot tell whether the exception was legitimate.
You have to raise a finding because no record shows the control was working. It may well have been.

What governance changes

Evidence is not gathered afterwards. The action produces it. That also lowers the burden on the audited team, so both sides gain.

Every record carries the rule set that was in force that day. Even after the rules change, an old action is read against the rules of its own day.

Every skipped step is recorded with its reason. An exception stops being invisible and becomes reviewable.

The evidence file can be verified independently of the system that keeps it. You perform the verification rather than being told the result.

You download the evidence instead of requesting it, and the sample no longer has to be kept small.

How you perform the verification

That sentence means nothing without a mechanism behind it, so here it is. Every package delivered to you is a zip containing the data itself, an identity file listing the SHA-256 digest of every file in the package, the RSA signature over that identity file, the public key that checks the signature, and a verification script.

The verification runs on your machine. Nothing connects to the product, nothing goes over the network, nothing is requested from the organisation. The PowerShell that ships with Windows, or openssl, is enough.

Neither check needs the organisation's audit key, because that key never leaves them. The first shows the records are linked to each other. The second compares a value from an anchor delivered to you earlier against today's records; that is where the evidential weight sits, and it depends on your having received the anchor before audit day.