Free resource
The single artifact that decides most audits: control by control, what evidence proves it, who owns it, its quality and what is missing. The exact structure we use on real work.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | The single artifact most audits turn on: control by control, what evidence proves it, how strong that evidence is, and the gap. The 'Quality' column is the point - presence is not proof. |
| How to grade quality | None = nothing. Weak = it exists but an auditor could pick it apart. Partial = it covers some of the control. Strong = dated, complete, and you would hand it over without hesitation. |
| The #1 mistake | Grading on effort, not on what an outsider would accept. If you would hesitate to hand it over, it is not Strong. |
| A second pair of eyes | If you want someone who has sat on the other side of the audit table to sanity-check your scoring before it counts, that is what we do at kellwick.com. |
Sheet: Evidence Map
One row per control. Grade the evidence you actually hold, then work the gap column before the audit. The 'Most common failure' column is filled in - it is where each control usually falls down.
| Annex A theme | Control | Evidence expected (a pass) | Most common failure (the red flag) | Owner | Where it lives | Quality (None/Weak/Partial/Strong) | Gap / action |
|---|---|---|---|---|---|---|---|
| Organizational | Access control policy and its operation | Approved policy plus proof it is followed (tickets, reviews) | The policy exists; the operation of it has no evidence | - | - | - | - |
| People | Joiner / mover / leaver | Tickets showing access granted and revoked on time | Joiners are evidenced, leavers are not - the risky half is missing | - | - | - | - |
| Technological | User access review | A signed, dated review of who has access to what | A screenshot of the user list, not a review with decisions | - | - | - | - |
| Technological | Logging and monitoring | Log samples plus evidence that alerts are triaged | Logs are collected but nobody reviews them - collection is not monitoring | - | - | - | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources