Producing an evidence pack
An evidence pack is assembled, not written. Everything in it is already in the register, which means the work happens in the weeks before the auditor arrives rather than the morning they do.
- For
- Assemble an evidence pack from what the register already holds, ready for an auditor.
- Will not
- It does not certify you, fill gaps, scan machines or send anything. Empty reports export as header-only files, and evidence is only what the register holds.
Before you generate anything
The pack will faithfully export a register with holes in it. Ten minutes here is worth more than any amount of formatting afterwards.
Open Compliance and read the coverage badges down the report list. A report reading Partial is telling you that it will generate, and that the evidence behind it is absent or has holes. That is the list of things to fix, in the order the auditor will find them.
Expand any Partial row. The derivation line above the control mapping says what the assessment actually counted, so you are chasing a specific gap rather than a mood. The commonest three are worth knowing in advance.
- Overdue physical verification. The one auditors test hardest, because it is the only line in the register that proves a person saw the machine. Filter Assets to what is past your cadence and walk it.
- Disposals without a chain. A machine marked disposed with no sanitization category, no witness and no certificate is worse than one still marked active: it asserts an event and cannot account for it. See Retiring a machine.
- Orphaned assets. Anything on the books with nobody holding it. Some of these are genuinely in a stockroom, and saying so is the fix.
Generating the pack
One button, one save panel, one file.
Check the header figures
The three counts under Compliance Portal are how many frameworks your profile derived, how many controls across them your evidence covers, and how many reports the programme requires. If a framework you expect is missing, the profile is wrong, not the pack. Fix it in Edit profile first, because re-running setup re-derives the whole programme.
Generate
Generate Audit Evidence Pack opens a save panel and writes a zip. While it assembles, the card carries a spinner; when it lands, a status line names the file. Nothing is sent anywhere: the pack is written to the location you chose and stays there.
Read the manifest before you hand it over
The pack contains a manifest mapping every artifact to the controls it answers. That is the part that turns a folder into an index, and it is also your last check: if an artifact you expected is not listed against the control you expected, you have found the gap before the auditor did.
When the auditor asks for one thing rather than everything, generate that one report from its own row instead. The download button at the end of each row produces that report alone, and an auditor given a single named CSV is better served than one given a zip to search.
Sampling
If they intend to test the register rather than read it, they will draw a sample. You can draw the same one.
Draw Audit Sample… takes a size, a scope and a seed, and writes the sample as a CSV with a manifest beside it recording the seed and the population it was drawn from. The manifest is what makes the draw checkable: the same seed against the same population produces the same machines, for you and for them.
Draw your own sample a week early and walk it. Anything the sample surfaces is something the auditor’s sample can surface too, and a week is enough time to fix a record rather than explain it.
What the pack will not do
Worth saying plainly, because each of these has been asked for.
- It does not certify you. It is evidence, assembled and indexed. The judgement is the auditor’s.
- It does not fill gaps. An empty report exports as a header-only file and says so out loud. That is the correct answer to “show me the breach notification log” when there have been no breaches, and it is deliberately not dressed up as anything else.
- It does not scan your machines. Encryption state, classification and regulatory scope are fields somebody filled in, by hand or through an integration. Nothing here inspects a device.
- It does not send anything. No upload, no portal, no copy kept.