Skip to content
SecuriFii

Evidence

What an auditor wants to see about incidents

Organisations sometimes hope a quiet incident log looks good. To an auditor it usually reads as an organisation that is not detecting anything.

Facts checked2026-09-11

What incident evidence does an auditor want?

A defined process with severity levels and who decides them; a log of incidents with dates, classification, actions and closure; and evidence that the process was followed on real ones — including the small ones, which are the ones that demonstrate the process works routinely rather than heroically.

A lessons-learned step matters more than its length. Two lines recording what changed because of an incident is evidence of a functioning system; a perfect process document with an empty log is evidence of a document.

The bottom line

Log the small incidents. An empty register does not read as a safe year, it reads as no detection.

Related insights