An audit is an evidence review. The CTDISR-2025 framework requires specific controls, and a PTA-registered audit firm determines compliance by examining evidence that those controls exist and are functioning. Evidence that cannot be produced, is out of date, or does not directly demonstrate the control it is supposed to support results in a finding regardless of what the underlying reality is.
Evidence management is the practice of systematically collecting, organising, and maintaining the documentation that demonstrates CTDISR compliance throughout the year, rather than assembling it under time pressure in the weeks before an audit.
What Evidence Actually Satisfies a Control
The evidence test for each CTDISR control has three parts: does it show the control exists, does it show the control is current, and does it show someone is accountable for it. A policy document that was written two years ago and never reviewed fails the currency test. An access log showing MFA is enforced but with no policy governing it fails the accountability test. A risk register that has a named owner for each risk but no evidence of quarterly review fails the currency test.
For each of the 104 CTDISR controls, the evidence type varies. Policy and procedure documents demonstrate that requirements have been formalised. Configuration extracts and screenshots demonstrate that technical controls are implemented. Meeting minutes and attendance records demonstrate that governance processes are operating. Training completion records demonstrate staff compliance with training obligations. Scan reports and test results demonstrate that assurance activities are being conducted.
Organising Evidence by Section
Structure your evidence store to mirror the 19 CTDISR sections. An auditor working through the framework expects to receive evidence organised by section: Section 1 governance evidence together, Section 2 access control evidence together, and so on. An evidence package where relevant documents are scattered across email threads, shared drives, and individual laptops requires the auditor to request items repeatedly and creates a poor impression of compliance maturity.
Within each section, maintain the following types of evidence as applicable: the relevant policies and procedures, proof of implementation (configuration records, screenshots, tool reports), records of ongoing operation (meeting minutes, training records, review logs, scan reports), and records of treatment for any findings from previous cycles.
The evidence for Section 2 (access control), for example, should contain: the access control policy, the RBAC role definitions, an access list report showing current user accounts and their roles, MFA enforcement configuration screenshots or reports, evidence of the most recent access review with its findings and any remediation actions, and the PAM policy if applicable.
Evidence Retention Periods
Retain evidence for a minimum of two full audit cycles. If your audit cycle is annual, keep evidence from the current year and the previous year available for immediate retrieval. Evidence from earlier cycles can be archived but should be retrievable if an auditor asks about a finding from a previous cycle and how it was remediated.
For logs specifically, 12 months of hot retention (immediately queryable) is the practical standard, with longer retention in archive depending on the specific log type and regulatory requirements.
Common Evidence Gaps
The most frequently missing evidence items in CTDISR audits are: ISSC meeting minutes (the committee exists but minutes are not recorded consistently), access review records (access reviews are conducted informally but not documented), BCP test results (the plan exists but there is no record of an actual tabletop exercise), training completion records (training happened but individual completion was not tracked), and vulnerability scan reports (scanning is conducted but the reports are not retained or the remediation tracking documentation does not exist alongside the scan).
Each of these is a straightforward evidence item to produce if the underlying activity is happening and someone is responsible for capturing it. The gap is almost always in the capture, not in the activity itself.
Using a Compliance Platform
Managing CTDISR evidence manually, in shared drives and email, works at small scale but becomes error-prone as the evidence base grows across 104 controls and multiple audit cycles. A compliance management platform provides a structured home for each control's evidence, version history, review reminders, and reporting.
ComplianceIQ is built specifically for CTDISR-2025 evidence management: all 104 controls pre-loaded, evidence attachment per control, status tracking, and audit-ready reporting that produces the organised evidence package an auditor expects. For operators who need evidence management supported by a CISO function, CISO-as-a-Service covers the evidence collection and organisation process as part of the governance programme. For operators building their evidence base for an upcoming audit, CTDISR Audit Readiness includes evidence review and gap closure as structured deliverables.