Evidence
What an auditor wants to see about incidents
Organisations sometimes hope a quiet incident log looks good. To an auditor it usually reads as an organisation that is not detecting anything.
Facts checked — 2026-09-11
What incident evidence does an auditor want?
A defined process with severity levels and who decides them; a log of incidents with dates, classification, actions and closure; and evidence that the process was followed on real ones — including the small ones, which are the ones that demonstrate the process works routinely rather than heroically.
A lessons-learned step matters more than its length. Two lines recording what changed because of an incident is evidence of a functioning system; a perfect process document with an empty log is evidence of a document.
The bottom line
Log the small incidents. An empty register does not read as a safe year, it reads as no detection.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.