When Evidence Exists but the Security Control Is Still Ineffective
A Practical Auditor’s Guide to Moving Beyond the Checkbox
In information security audits, one of the most common mistakes is to equate the existence of evidence with the effectiveness of a control.
An organization may provide a policy, system screenshot, log extract, report, approval record, or compliance certificate. At first glance, the evidence may appear sufficient.
But an important audit question remains:
Does the evidence actually demonstrate that the control is appropriately designed, implemented, operating consistently, and achieving its intended security objective?
This distinction is particularly important in BFSI, critical applications, regulated environments, ISO/IEC 27001 implementations, and formal Information Security Management Systems (ISMS).
A control can have documentation and supporting evidence and still fail to provide the intended level of protection.
1. Evidence Is Not the Same as Control Effectiveness
Consider a simple control requirement:
“Privileged access to a critical application shall be reviewed periodically by an authorized person.”
During an audit, the organization provides:
- Privileged-access policy
- List of privileged users
- Application screenshot
- Quarterly access-review report
- Approval email
Does this automatically prove that the control is effective?
Not necessarily.
An auditor should consider questions such as:
- Does the user list represent the complete population?
- Are service, technical and emergency accounts included?
- Was the review performed within the required period?
- Was the reviewer appropriately authorized?
- Does the report come directly from the relevant system?
- Were inappropriate accesses identified?
- Were identified exceptions removed or corrected?
- Was remediation completed within the required timeframe?
- Is there evidence that the control operated consistently?
- Can the evidence be independently verified?
The evidence is important, but it is only one part of the assessment.
2. Four Questions an Auditor Should Ask
A practical control assessment can be structured around four questions.
1. Is the control appropriately designed?
The control should address the underlying security risk.
For example, if the risk is unauthorized privileged access, a periodic review alone may not be sufficient.
The control environment may also require:
- Appropriate authorization
- Segregation of duties
- Periodic access review
- Timely access revocation
- Exception management
- Monitoring
- Escalation
The auditor should understand whether the control design is capable of addressing the identified risk.
2. Is the control implemented?
A policy may state that access reviews must be performed quarterly.
That does not prove that the organization actually performs quarterly reviews.
Implementation evidence could include:
- Access-review records
- System-generated reports
- Approval records
- Tickets
- Review logs
- Exception records
The important distinction is:
“The organization says the control exists” is different from “the organization has implemented the control.”
3. Is the control operating?
Even if the control has been implemented, the auditor needs to determine whether it operates as intended.
For example, an organization may provide one quarterly access-review report.
That proves that one review occurred.
It may not prove that the control operated consistently throughout the audit period.
Depending on the control and audit scope, the auditor may need to examine multiple periods or appropriate samples.
4. Is the control achieving its intended objective?
This is often the most important question.
Suppose an access review was performed and approved.
However, the review identified five inappropriate privileged accounts, and there is no evidence that those accounts were subsequently removed.
The review activity occurred.
But did the control achieve its security objective?
That requires further assessment.
3. A Practical Evidence Assessment Model
A useful way to assess a control is:
Control Requirement → Control Objective → Control Design → Implementation → Operating Effectiveness → Evidence Quality → Risk Outcome
Each stage answers a different question.
| Assessment Area | Key Question |
|---|---|
| Control Requirement | What is required? |
| Control Objective | What risk is the control intended to address? |
| Control Design | Is the control capable of addressing the risk? |
| Implementation | Has the control actually been implemented? |
| Operating Effectiveness | Has it operated as required? |
| Evidence Quality | Is the evidence complete, reliable and traceable? |
| Risk Outcome | Did the control achieve its intended objective? |
This approach helps prevent an audit from becoming nothing more than a document collection exercise.
4. Example: Daily Reconciliation Control
Consider a generic banking environment where data is transferred between two critical systems.
The organization states:
“Daily reconciliation is performed between the source and target systems.”
The organization provides a reconciliation report showing:
“Reconciliation Successful”
Is that enough?
An auditor may need to understand:
Scope
- What data is being reconciled?
- Is the entire population covered?
- Are all relevant transactions included?
Frequency
- Is reconciliation performed daily as required?
- Are there missed days?
Accuracy
- Does the reconciliation compare the relevant fields?
- Are transaction counts compared?
- Are transaction amounts compared?
Exception Management
- What happens when records do not match?
- Is there an exception report?
- Who investigates the exception?
- What is the escalation timeline?
- Is closure documented?
Review and Accountability
- Who performs the reconciliation?
- Who reviews the results?
- Is the reviewer independent where required?
- Is approval retained?
Evidence Integrity
- Is the report system-generated?
- Can the underlying data be traced?
- Can the report be altered manually?
- Is there an audit trail?
A report saying “Reconciliation Successful” does not, by itself, answer all these questions.
5. Why a Screenshot Can Be Misleading
Screenshots are frequently provided as audit evidence.
For example, an organization may provide a screenshot showing:
MFA Enabled: Yes
This demonstrates the configuration visible at the time the screenshot was taken.
However, it may not establish:
- When MFA was enabled
- Whether it was enabled throughout the audit period
- Which users are covered
- Whether privileged accounts are included
- Whether exceptions exist
- Who configured the setting
- Whether the configuration was authorized
- Whether the setting was subsequently changed
Depending on the control, stronger evidence may include:
- Configuration reports
- System-generated records
- Change-management records
- Authentication logs
- Exception reports
- Historical configuration evidence
The lesson is simple:
A screenshot can demonstrate a condition. It does not automatically demonstrate the history or effectiveness of a control.
6. A Policy Does Not Prove Implementation
One of the most common evidence gaps in audits is the use of policy documents as evidence of operational compliance.
Consider:
Policy requirement: Privileged access must be reviewed quarterly.
The policy demonstrates that management has documented the requirement.
But stronger evidence of implementation could include:
Policy → Access Review Process → Review Records → Exceptions → Remediation → Closure
For example:
| Evidence Layer | What It Demonstrates |
|---|---|
| Policy | Requirement exists |
| Procedure | Process is defined |
| Access list | Population being reviewed |
| Review record | Review was performed |
| Exception record | Issues were identified |
| Remediation evidence | Issues were addressed |
| Closure record | Remediation was completed |
The more important the control, the more important it becomes to assess the complete evidence chain.
7. Evidence Should Tell a Complete Story
Good audit evidence should help answer:
What?
What control exists?
Why?
What risk or objective does it address?
Who?
Who owns and performs the control?
How?
How is the control performed?
When?
How frequently does it operate?
What happens when something goes wrong?
How are exceptions handled?
Who reviews it?
Is there appropriate oversight?
Did it operate during the audit period?
Can this be demonstrated?
What was the outcome?
Did the control actually address the intended risk?
This is the difference between collecting documents and assessing controls.
8. Five Common Evidence Weaknesses
1. Incomplete evidence
Only part of the required population or period is covered.
2. Outdated evidence
The evidence reflects an earlier configuration or process and may not represent the audit period.
3. Evidence that cannot be independently verified
For example, a manually prepared spreadsheet without a clear source or audit trail.
4. Exceptions are identified but not addressed
The control operates, but identified issues remain unresolved.
5. Evidence demonstrates activity, not effectiveness
A report proves that an activity occurred but does not demonstrate whether the activity achieved its intended objective.
This fifth issue is particularly important.
Activity ≠ Effectiveness
9. Practical Auditor Checklist
Before concluding that a control is effective, consider the following:
☐ Is the control objective clearly understood?
☐ Does the control address the identified risk?
☐ Is the control appropriately designed?
☐ Has the control been implemented?
☐ Did it operate during the relevant audit period?
☐ Is the evidence complete?
☐ Is the evidence accurate and traceable?
☐ Is the evidence obtained from an appropriate source?
☐ Were exceptions identified?
☐ Were exceptions investigated?
☐ Were corrective actions completed?
☐ Is appropriate review or approval available?
☐ Has the control operated consistently?
☐ Does the evidence support the audit conclusion?
If the answer to any important question is “No” or “Cannot be established,” further assessment may be required.
10. What Organizations Can Do Before an Audit
Organizations can significantly improve audit readiness by creating an evidence-to-control mapping before an audit begins.
For example:
| Control | Frequency | Primary Evidence | Supporting Evidence | Owner |
|---|---|---|---|---|
| Privileged Access Review | Quarterly | Access Review Report | Remediation Records | Application/Security Owner |
| Vulnerability Remediation | Monthly / Defined Period | Vulnerability Report | Closure Evidence | IT/Security Team |
| Backup Verification | Defined Frequency | Backup Report | Restore Test Evidence | Infrastructure Team |
| Security Log Monitoring | Continuous / Defined Frequency | Monitoring Records | Incident/Escalation Records | Security Operations |
The exact evidence should depend on the control objective, environment and applicable requirements.
The purpose is not to produce the maximum number of documents.
The purpose is to ensure that appropriate evidence exists to demonstrate that important controls are operating as intended.
11. Example Audit Observation
Consider the following scenario:
An organization performs daily reconciliation between two critical systems. Reconciliation reports are available; however, systematic tracking of reconciliation exceptions, ownership and closure evidence is not consistently available for the audit period.
Observation
The organization has implemented daily reconciliation; however, evidence of systematic tracking, ownership and closure of reconciliation exceptions was not consistently available for the audit period.
Risk
Unresolved discrepancies may remain unidentified or unaddressed, potentially affecting the accuracy, completeness and integrity of critical information.
Recommendation
The organization should strengthen the reconciliation control by implementing:
- Documented exception tracking
- Defined ownership
- Escalation timelines
- Periodic management review
- Appropriate remediation tracking
- Evidence of exception closure
Notice the difference.
The observation does not incorrectly state that reconciliation was not performed.
Instead, it identifies the specific weakness in the control environment.
This produces a more accurate and useful audit conclusion.
12. The Auditor’s Mindset
A traditional approach may be:
“Show me the document.”
A stronger approach is:
“Show me how the control works.”
An even stronger approach is:
“Show me how you know the control worked.”
This shift is important because information security auditing is not simply about verifying whether documentation exists.
It is about obtaining sufficient, appropriate and relevant evidence to support a reasonable conclusion about the control.
Key Takeaways
- Evidence does not automatically equal control effectiveness.
- A policy demonstrates a requirement, not necessarily implementation.
- A screenshot may demonstrate a current configuration but not historical operation.
- A report may demonstrate an activity without proving its effectiveness.
- Exceptions and remediation are important parts of the control lifecycle.
- Auditors should assess the relationship between risk, control, evidence and outcome.
- Organizations can improve audit readiness by defining evidence requirements before the audit.
- The objective is not to collect the largest number of documents; it is to obtain evidence that supports a meaningful conclusion.
The key question remains:
“Does the evidence demonstrate that the control actually works as intended?”
About the Author
Vipin Kumar Tiwari is an Information Security and Cyber GRC professional with 16+ years of IT experience, with a professional focus on Information Security Audit, ISO/IEC 27001, ISO/IEC 27701, privacy, regulatory compliance and IT governance.
Professional Focus
Information Security Audit | Cyber GRC | ISO 27001 | ISO 27701 | Privacy & DPDPA | ITGC | Risk & Compliance
Professional Discussion
I share practical insights and approaches related to Information Security, Cyber GRC, IT Audit, privacy and regulatory compliance.
For professional discussions and knowledge sharing in these areas, feel free to connect.
Comments
Post a Comment