Evidence & audits

Collect reusable evidence, carry out internal and external audits, and close findings using CAPA — without having to rebuild the file from scratch each time.

Evidence is what makes a claim of compliance defensible. At iComply, evidence does not belong to a framework or an audit — it belongs to the control. That is why it supports all audits that relate to that control, for as long as necessary.

The evidence library

All pieces of evidence are stored in a central library, in Evidências → Biblioteca. Each item has:

  • Type — policy, procedure, record, configuration printout, report, minutes, certificate, contract.
  • Associated controls — one or more.
  • Validity — from when it is valid and when it expires.
  • Person responsible — the person responsible for keeping it up to date.
  • Versions — complete, immutable history.

Reuse: the key issue

When evidence is attached to a control, it automatically satisfies all the requirements mapped to that control. A single penetration test report can satisfy ISO 27001, NIS2, DORA and SOC 2 at the same time.

The panel for each piece of evidence shows the full list of requirements it supports — which is useful when an auditor asks, ‘Where is the evidence for this?’, and the answer is just a click away.

Validity and out-of-date evidence

Evidence with no expiry date is a pitfall. When uploading, set the validity period according to the nature of the document:

  • Key policies — annual review.
  • Access audit logs — quarterly or monthly.
  • Penetration testing — annually, or following a significant change.
  • Training and awareness-raising — annually, per employee.
  • Supplier certificates — subject to the expiry date stated on the certificate itself.

When the validity period is nearing its end, the platform notifies the person responsible and the control’s status changes to ‘Under review’. If it expires, the control is flagged and the dashboard highlights the gap — before the auditor spots it.

Versioning

Replacing a document never deletes the previous version. The new version becomes the current one, and the previous versions remain accessible, showing the date, author and reason for the change. This is essential for retrospective audits: an auditor may wish to see what the policy was eighteen months ago, not just the current one.

Carry out an audit

In Auditoria → Auditorias, an internal or external audit is set up. The process is as follows:

  1. Scope — which domains, frameworks, entities and time period are covered.
  2. Plan — controls to be tested, based on risk and previous results.
  3. Execution — each test is recorded along with its procedure, result and worksheets. The evidence is retrieved from the library; it is not recreated.
  4. Findings — what went wrong, categorised by severity.
  5. Report — generated from the data, exportable to the external auditor or to senior management.

For external auditors, create a user with the ‘Auditor’ profile and a scope limited to the audit. They can access the evidence they need without altering anything.

Findings and classification

  • Major non-compliance — a systemic failure that compromises compliance. Requires a CAPA to be carried out within a short timeframe.
  • Minor non-conformity — an isolated or one-off fault.
  • Note — it works, but there is a risk of deterioration.
  • Opportunity for improvement — no non-compliance, with potential benefits.

Each finding is linked to the relevant check, which means that a check’s history shows every time it has failed — valuable information for deciding where to invest.

The CAPA cycle

A finding leads to a corrective (and, where applicable, preventive) action. The cycle has five stages:

  1. Root cause analysis — why it failed, not just what failed.
  2. Corrective action — the measure that resolves the specific issue, with a designated person responsible and a deadline.
  3. Preventive action — what prevents recurrence, often a change to the control procedure.
  4. Effectiveness check — confirmation, after a defined period, that the action has worked.
  5. Closing — with proof of the result.

A closed CAPA without verification of effectiveness is the most common non-conformity found in follow-up audits. The platform does not allow it to be closed without this step.

Ongoing assurance between audits

Between formal audits, the platform provides continuous assurance: expiring evidence, overdue tasks, controls under review and rising risks are automatically flagged. The practical result is that the next audit finds everything in order, because it has never been out of order.

Preparing for an external audit

  • Check the panel for expired evidence and resolve the issue before announcing the date.
  • Please confirm that all controls within the scope have a designated person responsible and that records are kept up to date.
  • Complete any outstanding CAPAs from the previous audit — this is always the first thing the auditor checks.
  • Generate the status report by framework and go through it with the managers responsible for each area.
  • Create an auditor’s access with a defined scope and duration.

On this page

Do you have an audit scheduled?

We’ll show you how to put together your evidence file in days, not weeks.