Evidence
Change management that an auditor can sample
Most engineering teams already review and test changes. The audit question is whether that leaves a record somebody can sample six months later.
Facts checked — 2026-09-11
How do you evidence change management?
The artefacts usually exist: a pull request with an approver who is not the author, a pipeline that ran tests, a deployment record. What is often missing is the link — being able to take a change an auditor picks and show its approval, its testing and its deployment in one trail.
Emergency changes are where the sample tends to land, because that is where the normal path is bypassed. A defined emergency route with retrospective approval is fine; an undocumented one is the finding.
The bottom line
Make sure a single change can be traced end to end. Auditors sample one and follow it.
Related services
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.