Elevaire Systems
Compliance Evidence Collection: Why Audit Prep Shouldn't Take Three Months
← Back to Insights
SecuritycompliancesecurityIT strategy

Compliance Evidence Collection: Why Audit Prep Shouldn't Take Three Months

Elevaire Systems·

The audit date is set. The auditor's request list arrives, and it asks for access reviews, onboarding and offboarding records, change approvals, backup test results, training completion, and vendor assessments covering the entire audit period. Someone in IT, or the COO, or an operations manager with a second job, opens a blank spreadsheet and starts hunting through inboxes, ticket queues, and admin consoles. Three months later the evidence is assembled, and the company has spent a full quarter of senior attention proving that it did things it already did.

That cost is not an audit problem. It is an evidence problem. Most growing companies do the underlying security work reasonably well. What they lack is a system that captures proof of that work at the moment it happens.

Why Audit Prep Takes So Long

Audit prep stretches for the same few reasons at nearly every company in the 25-200 employee range.

Evidence is gathered backward. The team starts from the auditor's request list and works toward the past, trying to reconstruct what happened on a given date. A control that ran correctly in March but left no record is, to an auditor, a control that cannot be shown to have run.

Nobody owns the evidence. Controls are owned informally. The person who approved a firewall change in May may have moved to a different role by the time the audit asks about it. Without a named owner per control, requests bounce between people and stall.

Evidence lives in too many places. A single access review might touch the identity provider, the HR system, a handful of SaaS admin consoles, and an email thread where a manager said "looks fine." Pulling it together by hand is slow, and it is error-prone.

The scope is fuzzy. Teams collect everything because no one has decided what the framework actually requires. The auditor needs a defined set of evidence for each control. Without that definition, the team over-collects in some areas and misses others.

What Auditors Actually Need From You

The details differ by framework, but the structure is consistent: a control, a frequency, an owner, and proof that the control operated as described.

For SOC 2, the AICPA's Trust Services Criteria (updated in the 2017 edition, with revised points of focus issued in 2022) define what an auditor evaluates. A Type II report covers an observation period, which sources commonly describe as three to twelve months. The auditor tests whether controls operated effectively across that window, which in practice means sampling instances of a control from the period and asking for evidence of each one. A control that runs weekly gives the auditor many instances to sample. A control that runs once a year gives them one, and it had better be well documented.

For HIPAA, the Security Rule requires covered entities and business associates to retain required documentation for six years, measured from the date of creation or the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)). The eCFR text of the rule is short and worth reading directly. That retention period turns evidence collection from an audit-season task into a records-management obligation.

ISO 27001 works on a cycle. Certification bodies typically conduct surveillance audits in the years between initial certification and the recertification audit, and surveillance audits sample parts of the management system rather than reviewing all of it. Companies that treat evidence as a once-every-three-years project find that the annual visits arrive faster than their evidence does.

Across all three, the common requirement is the same: dated, attributable proof that a control operated, retrievable without a hunt.

The Cost of Evidence Gathered After the Fact

Vendor surveys report a wide range of hours spent on manual compliance work, but most of those figures trace back to marketing material rather than independent research, so treat any single number with caution. A simple calculation with your own inputs is more useful.

Take a company with a 10-person leadership and operations group where audit prep pulls in a COO, an IT lead, an HR manager, and a finance lead for several hours a week across a quarter. If those four people spend six hours a week each on evidence for twelve weeks, that is 288 hours. At a blended loaded cost of $90 an hour, the prep costs roughly $26,000 in internal time, before the auditor's fee, and before counting the projects that did not move while those four were in spreadsheets. Substitute your own headcount, hours, and rates. The point of the exercise is to put a number on what "audit season" costs, because most companies have never added it up.

The second cost is risk. Evidence assembled under deadline pressure gets backfilled, approximated, or reconstructed from memory. Auditors are practiced at spotting a ticket opened the week before the audit that claims to document a decision made in the spring.

A Framework for Continuous Evidence Collection

The fix is to move evidence collection from a project to a routine. Here is a five-step approach that works for companies without a dedicated compliance team.

1. Build a control-to-evidence map

List every control your framework requires, and next to each one write down four things: what evidence proves it ran, where that evidence lives, who owns it, and how often it is generated. A 50-person company pursuing SOC 2 will usually end up with a few dozen controls. The map is a working document, not a deliverable. Its job is to turn "we need to prove access reviews happen" into "the IT lead exports the quarterly access review from the identity provider and attaches it to the compliance folder by the 10th of the month."

2. Name one owner per control

Each control gets one named person, and a named backup. Ownership belongs to a role with a person assigned, so that a departure does not orphan the control. This sounds administrative, and it is, but unowned controls are where evidence disappears.

3. Capture evidence at the point of work

The best evidence is a byproduct of doing the work in a system that records it. Change approvals live in the ticketing tool, not in a chat message. Onboarding and offboarding run through a checklist with timestamps. Access reviews are completed in the identity platform and exported, not described in an email. When the work and the record are the same action, nothing has to be reconstructed later.

4. Set a monthly evidence rhythm

Pick a fixed day each month for a short review: are this month's artifacts in the repository, do they show dates and owners, and is anything missing? A thirty-minute check catches a missed quarterly access review in the month it was missed, when it can still be performed, rather than eight months later when it can only be explained.

5. Run a mock request before the real one

About 60 days before the audit, have someone who did not collect the evidence work through the auditor's likely request list and try to find each item. Gaps surface while there is still time to close them. This single exercise does more to shorten the real audit than any tool purchase.

What to Collect, and How Often

Different controls generate evidence on different schedules. This table shows a common pattern for a company in the 25-200 employee range. Adjust frequencies to match your own policies, since an auditor tests against what your policies say you do.

Control areaTypical evidenceFrequency
Access reviewsExported user lists with manager sign-offQuarterly
Onboarding and offboardingDated checklists, ticket recordsPer event
Change managementApproved tickets, deployment recordsPer change
Security trainingCompletion reports with datesAnnual, plus new hires
Backup and recoveryJob logs, restore test resultsDaily logs, annual test
Vendor riskAssessments, signed agreementsAnnual per vendor

The "per event" rows are where manual collection breaks down fastest, because the volume is high and the work is easy to forget in the moment. Those are the best candidates for automation.

Where Automation Helps and Where It Doesn't

Automated evidence collection tools can pull configuration snapshots, user lists, and training records directly from the systems that hold them, and they can flag when a scheduled artifact is missing. That removes the most tedious and error-prone work.

They do not decide what your controls should be, and they cannot create a policy your company does not follow. A tool pointed at a weak control produces well-organized evidence of a weak control. Tooling also adds a recurring cost and an integration to maintain, so the question to settle first is which controls generate enough repeated evidence to justify it. For many 50-person companies, a disciplined folder structure, a ticketing system, and a calendar reminder cover the first year, and tooling is added where the monthly review shows the pain.

This is a technology leadership decision, not a procurement one. Elevaire's Compliance & Security work typically begins with the control map, because the map decides which systems need to record what, and which gaps are worth closing before anything is bought. It fits alongside an existing managed service provider, which continues to run the environment while the evidence process is designed around it.

Signs Your Evidence Process Is Working

You can tell the process has taken hold when a few things become true. The auditor's request list arrives and most items are already in the repository. Nobody has to ask who owns a control. The monthly check finds small gaps instead of large ones. And the audit itself takes days of focused review rather than weeks of leadership time.

Frequently Asked Questions

How long should audit preparation actually take?

For a company with a working evidence routine, preparation is mostly confirming what already exists and answering auditor follow-up questions, which can fit within a few weeks. Three months of prep usually signals that evidence is being created or reconstructed during the audit window rather than collected as the work happens.

How much does it cost to set up a continuous evidence process?

The main cost is time to build the control-to-evidence map and assign ownership, which is typically a matter of weeks of part-time effort rather than a large project. Tooling is optional and varies widely in price, so size it against the hours you calculated for your last audit, using your own headcount and rates.

Do we need compliance automation software to do this?

Not necessarily. A structured shared folder, a ticketing system that records approvals, and a monthly review get many companies through a first audit. Software earns its cost when you have many high-volume, repeating controls, or multiple frameworks sharing the same evidence.

Can we use the same evidence for more than one framework?

Often, yes. Access reviews, change approvals, training records, and backup tests are required in some form by SOC 2, ISO 27001, and HIPAA. Mapping each artifact to every framework that needs it lets you collect once and reuse it, though each framework still has its own scope and wording requirements.

How does this work alongside our existing MSP or IT team?

Your MSP or IT team already runs many of the systems that produce evidence, such as ticketing, backups, and device management. A fractional IT leader designs the process that tells those systems what to record and who reviews it, and the existing team keeps operating the environment day to day. Nobody is replaced.

How do we get started?

Pick the one framework driving your next audit and list its controls. For each, write down where the evidence lives and who owns it. That list shows you which controls are already well documented, which have no records at all, and what to fix first.

About Elevaire Systems

Elevaire Systems provides fractional Chief Information Officer (CIO), Chief Technology Officer (CTO), and Chief Information Security Officer (CISO) leadership, along with infrastructure modernization, intelligent automation, and compliance strategy for growing organizations.

Ready to Put This Into Practice?

Schedule a free consultation and let's talk through what this means for your organization specifically.

Schedule a Free Consultation