Evidence Collection
Evidence collection is the gathering of proof that your controls actually operate: configuration exports, access lists, review records, scan reports, tickets, training logs. It’s the physical substance of every audit — when people say compliance is painful, the pain they mean is usually this.
The two species of evidence
System-generated: configurations, logs, scan results — anything a machine can export with a timestamp. This species automates completely, which is the honest core of the compliance-platform value proposition: connected integrations collect it continuously and map it across frameworks. Judgment artifacts: risk decisions, access review determinations, incident post-mortems, vendor evaluations. Machines can assemble and chase these, but a human with authority has to decide — and the decision record is the evidence.
What separates good evidence
Contemporaneity (captured when the control ran, not reconstructed — auditors read timestamps), completeness across the observation window (gaps become exceptions), and provenance (exported from the system of record, not a screenshot of a screenshot).
The operating insight
Programs fail evidence at the seams: automation covers the system-generated species, and the judgment artifacts pile up unowned. That split is exactly the platform-plus-people thesis — the machine collects, operators run the cadences that produce the judgment half.
Audit Trail — An audit trail is the tamper-evident record of who did what, when, in your systems — the evidence layer every framework samples and every incident needs.
Access Review — An access review is the periodic check that everyone's system access matches their role — the most-sampled SOC 2 control and the most common exception.
Continuous Monitoring — Continuous monitoring is the automated, ongoing testing of security controls — replacing point-in-time evidence scrambles with always-current audit readiness.