Audit Evidence Collection
Turns control tests and auditor requests into tracked assignments with an owner, a due date, and attached evidence.
Tools
Vanta, Drata, AuditBoard, Diligent
Outcomes
Every audit request has an owner and a date • Evidence attached to the control, not a folder • Failed tests tracked through to a fix • Audit questions closed before the deadline
Documentation
Instruction-ready detail below
What breaks: audit season starts as a spreadsheet of questions and ends as a scramble across shared drives. Evidence that exists is hard to find, and evidence that does not exist is usually discovered two weeks before the deadline. Control owners rarely see the result of a failed test, so the same gap returns the following year under a new name. What the workflow does: it turns each control test and each auditor request into a tracked assignment with a named owner, a due date, and a link to the evidence. Failed checks are listed weekly with the specific evidence still missing rather than a generic reminder. When a request has waited past its date, the owner and the auditor contact are both named in the escalation. Once evidence is attached it is filed against the control, so next year's request starts from the same place. What a person still approves: the control owner signs off that the evidence answers the control, and the audit lead decides what goes to the auditor.