Evidence management

An audit evidence naming convention that survives three audits

Evidence that cannot be found, dated or traced to a control gets requested again. A five-part file name fixes most of that before any tool is involved.

Short answer

A good audit evidence name tells an auditor, without opening the file, which control it supports, what it shows, which period it covers and when it was captured. A five-part pattern of control reference, artefact, period, capture date and version works across ISO 27001, SOC 2 and most other frameworks.

Key takeaways

  • Put the control reference first so files sort by control.
  • Always record the period covered as well as the capture date.
  • Use one naming pattern for every framework and tag extra references separately.
  • Never overwrite evidence; add a version instead.

Why naming matters

Most repeated evidence requests are not about missing evidence. The file exists, but nobody can show which control it supports or which period it covers, so the auditor asks for it again. A predictable name answers those questions before anyone opens the file.

The five-part pattern

PartExampleWhy
Control referenceA.5.18Files sort by control
Artefactaccess-reviewSays what the file shows
Period covered2026-Q3Lets the auditor sample the right period
Capture date2026-10-02Proves when it was produced
Versionv1Keeps history instead of overwriting

Put together: A.5.18_access-review_2026-Q3_2026-10-02_v1.pdf. Use hyphens inside parts and underscores between them so the name stays readable and splits cleanly in a spreadsheet.

One artefact, several frameworks

Name each file once, using the reference from your primary framework, and record other framework references as tags or in your control library. The quarterly access review above also supports SOC 2 CC6.2 and CC6.3; renaming or copying the file for each framework is how duplicates and version conflicts start.

File name usesAlso tagged to
  1. A.5.18access-review_2026-Q3CC6.2–6.3SOC 2 user access
  2. A.8.32change-log_2026-09CC8.1SOC 2 change management
Full mappingPartial mappingIllustrative tags; confirm against your own control descriptions.

Rules that keep it working

Checklist

Evidence naming rules

0 of 6 done

Frequently asked questions

Should evidence be organised by framework or by control?

By control. Name and store each artefact once against its control, then tag the other frameworks it supports, so the same file serves every audit.

Sources

  1. ISO/IEC 27002:2022 Information security controls, ISO