When Evidence Exists but the Security Control Is Still Ineffective

 A Practical Auditor’s Guide to Moving Beyond the Checkbox

In information security audits, one of the most common mistakes is to equate the existence of evidence with the effectiveness of a control.

An organization may provide a policy, system screenshot, log extract, report, approval record, or compliance certificate. At first glance, the evidence may appear sufficient.

But an important audit question remains:

Does the evidence actually demonstrate that the control is appropriately designed, implemented, operating consistently, and achieving its intended security objective?

This distinction is particularly important in BFSI, critical applications, regulated environments, ISO/IEC 27001 implementations, and formal Information Security Management Systems (ISMS).

A control can have documentation and supporting evidence and still fail to provide the intended level of protection.

1. Evidence Is Not the Same as Control Effectiveness

Consider a simple control requirement:

“Privileged access to a critical application shall be reviewed periodically by an authorized person.”

During an audit, the organization provides:

  • Privileged-access policy
  • List of privileged users
  • Application screenshot
  • Quarterly access-review report
  • Approval email

Does this automatically prove that the control is effective?

Not necessarily.

An auditor should consider questions such as:

  • Does the user list represent the complete population?
  • Are service, technical and emergency accounts included?
  • Was the review performed within the required period?
  • Was the reviewer appropriately authorized?
  • Does the report come directly from the relevant system?
  • Were inappropriate accesses identified?
  • Were identified exceptions removed or corrected?
  • Was remediation completed within the required timeframe?
  • Is there evidence that the control operated consistently?
  • Can the evidence be independently verified?

The evidence is important, but it is only one part of the assessment.

2. Four Questions an Auditor Should Ask

A practical control assessment can be structured around four questions.

1. Is the control appropriately designed?

The control should address the underlying security risk.

For example, if the risk is unauthorized privileged access, a periodic review alone may not be sufficient.

The control environment may also require:

  • Appropriate authorization
  • Segregation of duties
  • Periodic access review
  • Timely access revocation
  • Exception management
  • Monitoring
  • Escalation

The auditor should understand whether the control design is capable of addressing the identified risk.

2. Is the control implemented?

A policy may state that access reviews must be performed quarterly.

That does not prove that the organization actually performs quarterly reviews.

Implementation evidence could include:

  • Access-review records
  • System-generated reports
  • Approval records
  • Tickets
  • Review logs
  • Exception records

The important distinction is:

“The organization says the control exists” is different from “the organization has implemented the control.”

3. Is the control operating?

Even if the control has been implemented, the auditor needs to determine whether it operates as intended.

For example, an organization may provide one quarterly access-review report.

That proves that one review occurred.

It may not prove that the control operated consistently throughout the audit period.

Depending on the control and audit scope, the auditor may need to examine multiple periods or appropriate samples.

4. Is the control achieving its intended objective?

This is often the most important question.

Suppose an access review was performed and approved.

However, the review identified five inappropriate privileged accounts, and there is no evidence that those accounts were subsequently removed.

The review activity occurred.

But did the control achieve its security objective?

That requires further assessment.

3. A Practical Evidence Assessment Model

A useful way to assess a control is:

Control Requirement → Control Objective → Control Design → Implementation → Operating Effectiveness → Evidence Quality → Risk Outcome

Each stage answers a different question.

Assessment AreaKey Question
Control Requirement         What is required?
Control Objective         What risk is the control intended to address?
Control Design         Is the control capable of addressing the risk?
Implementation         Has the control actually been implemented?
Operating Effectiveness         Has it operated as required?
Evidence Quality         Is the evidence complete, reliable and traceable?
Risk Outcome         Did the control achieve its intended objective?

This approach helps prevent an audit from becoming nothing more than a document collection exercise.

4. Example: Daily Reconciliation Control

Consider a generic banking environment where data is transferred between two critical systems.

The organization states:

“Daily reconciliation is performed between the source and target systems.”

The organization provides a reconciliation report showing:

“Reconciliation Successful”

Is that enough?

An auditor may need to understand:

Scope

  • What data is being reconciled?
  • Is the entire population covered?
  • Are all relevant transactions included?

Frequency

  • Is reconciliation performed daily as required?
  • Are there missed days?

Accuracy

  • Does the reconciliation compare the relevant fields?
  • Are transaction counts compared?
  • Are transaction amounts compared?

Exception Management

  • What happens when records do not match?
  • Is there an exception report?
  • Who investigates the exception?
  • What is the escalation timeline?
  • Is closure documented?

Review and Accountability

  • Who performs the reconciliation?
  • Who reviews the results?
  • Is the reviewer independent where required?
  • Is approval retained?

Evidence Integrity

  • Is the report system-generated?
  • Can the underlying data be traced?
  • Can the report be altered manually?
  • Is there an audit trail?

A report saying “Reconciliation Successful” does not, by itself, answer all these questions.

5. Why a Screenshot Can Be Misleading

Screenshots are frequently provided as audit evidence.

For example, an organization may provide a screenshot showing:

MFA Enabled: Yes

This demonstrates the configuration visible at the time the screenshot was taken.

However, it may not establish:

  • When MFA was enabled
  • Whether it was enabled throughout the audit period
  • Which users are covered
  • Whether privileged accounts are included
  • Whether exceptions exist
  • Who configured the setting
  • Whether the configuration was authorized
  • Whether the setting was subsequently changed

Depending on the control, stronger evidence may include:

  • Configuration reports
  • System-generated records
  • Change-management records
  • Authentication logs
  • Exception reports
  • Historical configuration evidence

The lesson is simple:

A screenshot can demonstrate a condition. It does not automatically demonstrate the history or effectiveness of a control.

6. A Policy Does Not Prove Implementation

One of the most common evidence gaps in audits is the use of policy documents as evidence of operational compliance.

Consider:

Policy requirement: Privileged access must be reviewed quarterly.

The policy demonstrates that management has documented the requirement.

But stronger evidence of implementation could include:

Policy → Access Review Process → Review Records → Exceptions → Remediation → Closure

For example:

Evidence LayerWhat It Demonstrates
Policy    Requirement exists
Procedure    Process is defined
Access list    Population being reviewed
Review record    Review was performed
Exception record      Issues were identified
Remediation evidence    Issues were addressed
Closure record    Remediation was completed

The more important the control, the more important it becomes to assess the complete evidence chain.

7. Evidence Should Tell a Complete Story

Good audit evidence should help answer:

What?
What control exists?

Why?
What risk or objective does it address?

Who?
Who owns and performs the control?

How?
How is the control performed?

When?
How frequently does it operate?

What happens when something goes wrong?
How are exceptions handled?

Who reviews it?
Is there appropriate oversight?

Did it operate during the audit period?
Can this be demonstrated?

What was the outcome?
Did the control actually address the intended risk?

This is the difference between collecting documents and assessing controls.

8. Five Common Evidence Weaknesses

1. Incomplete evidence

Only part of the required population or period is covered.

2. Outdated evidence

The evidence reflects an earlier configuration or process and may not represent the audit period.

3. Evidence that cannot be independently verified

For example, a manually prepared spreadsheet without a clear source or audit trail.

4. Exceptions are identified but not addressed

The control operates, but identified issues remain unresolved.

5. Evidence demonstrates activity, not effectiveness

A report proves that an activity occurred but does not demonstrate whether the activity achieved its intended objective.

This fifth issue is particularly important.

Activity ≠ Effectiveness

9. Practical Auditor Checklist

Before concluding that a control is effective, consider the following:

☐ Is the control objective clearly understood?

☐ Does the control address the identified risk?

☐ Is the control appropriately designed?

☐ Has the control been implemented?

☐ Did it operate during the relevant audit period?

☐ Is the evidence complete?

☐ Is the evidence accurate and traceable?

☐ Is the evidence obtained from an appropriate source?

☐ Were exceptions identified?

☐ Were exceptions investigated?

☐ Were corrective actions completed?

☐ Is appropriate review or approval available?

☐ Has the control operated consistently?

☐ Does the evidence support the audit conclusion?

If the answer to any important question is “No” or “Cannot be established,” further assessment may be required.

10. What Organizations Can Do Before an Audit

Organizations can significantly improve audit readiness by creating an evidence-to-control mapping before an audit begins.

For example:

ControlFrequencyPrimary EvidenceSupporting EvidenceOwner
Privileged Access ReviewQuarterlyAccess Review ReportRemediation RecordsApplication/Security Owner
Vulnerability RemediationMonthly / Defined PeriodVulnerability ReportClosure EvidenceIT/Security Team
Backup VerificationDefined FrequencyBackup ReportRestore Test EvidenceInfrastructure Team
Security Log MonitoringContinuous / Defined FrequencyMonitoring RecordsIncident/Escalation RecordsSecurity Operations

The exact evidence should depend on the control objective, environment and applicable requirements.

The purpose is not to produce the maximum number of documents.

The purpose is to ensure that appropriate evidence exists to demonstrate that important controls are operating as intended.

11. Example Audit Observation

Consider the following scenario:

An organization performs daily reconciliation between two critical systems. Reconciliation reports are available; however, systematic tracking of reconciliation exceptions, ownership and closure evidence is not consistently available for the audit period.

Observation

The organization has implemented daily reconciliation; however, evidence of systematic tracking, ownership and closure of reconciliation exceptions was not consistently available for the audit period.

Risk

Unresolved discrepancies may remain unidentified or unaddressed, potentially affecting the accuracy, completeness and integrity of critical information.

Recommendation

The organization should strengthen the reconciliation control by implementing:

  • Documented exception tracking
  • Defined ownership
  • Escalation timelines
  • Periodic management review
  • Appropriate remediation tracking
  • Evidence of exception closure

Notice the difference.

The observation does not incorrectly state that reconciliation was not performed.

Instead, it identifies the specific weakness in the control environment.

This produces a more accurate and useful audit conclusion.

12. The Auditor’s Mindset

A traditional approach may be:

“Show me the document.”

A stronger approach is:

“Show me how the control works.”

An even stronger approach is:

“Show me how you know the control worked.”

This shift is important because information security auditing is not simply about verifying whether documentation exists.

It is about obtaining sufficient, appropriate and relevant evidence to support a reasonable conclusion about the control.

Key Takeaways

  • Evidence does not automatically equal control effectiveness.
  • A policy demonstrates a requirement, not necessarily implementation.
  • A screenshot may demonstrate a current configuration but not historical operation.
  • A report may demonstrate an activity without proving its effectiveness.
  • Exceptions and remediation are important parts of the control lifecycle.
  • Auditors should assess the relationship between risk, control, evidence and outcome.
  • Organizations can improve audit readiness by defining evidence requirements before the audit.
  • The objective is not to collect the largest number of documents; it is to obtain evidence that supports a meaningful conclusion.

The key question remains:

“Does the evidence demonstrate that the control actually works as intended?”

About the Author

Vipin Kumar Tiwari is an Information Security and Cyber GRC professional with 16+ years of IT experience, with a professional focus on Information Security Audit, ISO/IEC 27001, ISO/IEC 27701, privacy, regulatory compliance and IT governance.

Professional Focus

Information Security Audit | Cyber GRC | ISO 27001 | ISO 27701 | Privacy & DPDPA | ITGC | Risk & Compliance

Professional Discussion

I share practical insights and approaches related to Information Security, Cyber GRC, IT Audit, privacy and regulatory compliance.

For professional discussions and knowledge sharing in these areas, feel free to connect. 

Comments

Popular posts from this blog

OWASP Top 10

Information Security: Principles, CIA Triad, and Risk Management Guide

Cyber Security Basics for Beginners in 2025