Evidence collection
Evidence collection is the first step towards gaining your SOC 2 attestation. It provides proof that your policies, processes, workflows, controls, and checks are not only designed properly but also operating effectively throughout the observation period.
Proper evidence collection requires understanding exactly what evidence is needed for each control, who is responsible for providing it, and how frequently it must be collected.
Common types of evidence include:
- Screenshots of system configurations and settings
- System-generated reports and logs
- Policy and procedure documents
- Meeting minutes and approval records
- Training completion records
When you include an external auditor in your path towards gaining attestation, evidence is one of the first things the auditor will request after scoping and planning.
Proving Compliance: Why SOC 2 Evidence Collection Matters
SOC Frameworks Overview
SOC 2 Basics
SOC 2 Compliance Process
SOC 2 Compliance Process
Sprinto: Your ally for all things compliance, risk, governance