Short answer
A good audit evidence name tells an auditor, without opening the file, which control it supports, what it shows, which period it covers and when it was captured. A five-part pattern of control reference, artefact, period, capture date and version works across ISO 27001, SOC 2 and most other frameworks.
Key takeaways
- Put the control reference first so files sort by control.
- Always record the period covered as well as the capture date.
- Use one naming pattern for every framework and tag extra references separately.
- Never overwrite evidence; add a version instead.
Why naming matters
Most repeated evidence requests are not about missing evidence. The file exists, but nobody can show which control it supports or which period it covers, so the auditor asks for it again. A predictable name answers those questions before anyone opens the file.
The five-part pattern
| Part | Example | Why |
|---|---|---|
| Control reference | A.5.18 | Files sort by control |
| Artefact | access-review | Says what the file shows |
| Period covered | 2026-Q3 | Lets the auditor sample the right period |
| Capture date | 2026-10-02 | Proves when it was produced |
| Version | v1 | Keeps history instead of overwriting |
Put together: A.5.18_access-review_2026-Q3_2026-10-02_v1.pdf. Use hyphens inside parts and underscores between them so the name stays readable and splits cleanly in a spreadsheet.
One artefact, several frameworks
Name each file once, using the reference from your primary framework, and record other framework references as tags or in your control library. The quarterly access review above also supports SOC 2 CC6.2 and CC6.3; renaming or copying the file for each framework is how duplicates and version conflicts start.
A.5.18access-review_2026-Q3CC6.2–6.3SOC 2 user accessA.8.32change-log_2026-09CC8.1SOC 2 change management
Rules that keep it working
Checklist
Evidence naming rules
0 of 6 done
Frequently asked questions
Should evidence be organised by framework or by control?
By control. Name and store each artefact once against its control, then tag the other frameworks it supports, so the same file serves every audit.