Internal Audit & Compliance Guide 13 min read

Audit evidence and documentation — what to record and retain

What actually counts as audit evidence, the difference between a document and a record, the chain that ties a finding to proof, what a certification body reviews, and how long to keep it all.

By Vidya Kathare · July 18, 2026 Updated July 2026
The evidence chain
01
Answered checklist
Conformance, score, clause per question
Recorded
02
Observations & files
The objective evidence, attached
Attached
03
Finding & CAPA trail
Closure history with dates & sign-off
Traced
04
Report archive
Retained, retrievable on demand
Retained

What audit evidence is

Audit evidence is, in ISO 19011's definition, the records, statements of fact or other information that are relevant to the audit criteria and verifiable. Two words in that definition do all the work. Relevant means the evidence bears directly on the requirement being audited — a calibration record is relevant to a calibration clause, not to a training one. Verifiable means someone else could confirm it: the record exists, the measurement can be repeated, the practice was actually observed. Information that fails either test is an impression, and an impression cannot support a finding.

This is why an audit is fundamentally an evidence-gathering exercise, not an opinion-forming one. Every conclusion an auditor reaches — conform or not, major or minor — must trace back to objective evidence that was seen and recorded. An audit programme that captures conclusions but not the evidence behind them is hollow: it cannot defend a finding under challenge, and it cannot prove to a certification body that the finding was justified. Recording the evidence, not just the verdict, is the foundation the whole audit management lifecycle rests on.

A simple way to think about it
Evidence is to an audit what exhibits are to a court. The verdict is not enough — you have to be able to point to the specific fact it rests on, and hand it to someone else to check.
"I got the impression the process was fine" is testimony. "Records QR-14 through QR-19 were complete and signed" is evidence.

The four sources of audit evidence

Auditors gather evidence from a small set of well-defined sources, and a thorough audit draws on more than one so that a claim can be corroborated:

01
Interviews
Asking people how the process actually works
02
Observation
Watching the activity being performed
03
Documents
Procedures, work instructions, control plans
04
Records
Completed forms proving results occurred

The strongest audits triangulate: what the operator says in an interview is checked against what the auditor observes on the line and against the records that should exist if the practice is real. A claim supported by all three is solid; a claim contradicted by the records is a finding. Capturing the specific record numbers, observations and measurements at the point of the checklist question — rather than reconstructing them afterwards — is what preserves the evidence while it is still fresh and exact.

Documents versus records

ISO 9001:2015 folded both into the single term documented information in clause 7.5, but the practical distinction is worth keeping clear because the two are handled differently:

AspectDocumentRecord
PurposeStates intent — how something should be doneProves a result — what actually happened
ExamplesProcedure, work instruction, control plan, checklist templateCompleted checklist, audit report, CAPA history
LifecycleKept current — revised, superseded, version-controlledRetained unchanged — frozen as evidence
ControlControlled so the right version is in useRetained, protected and retrievable for a period

An audit programme produces mostly records — the completed audit, the findings, the corrective-action histories — and its main document is the reusable checklist template, which is controlled and revised so the right questions are always asked. Confusing the two causes real problems: editing a record after the fact destroys its value as evidence, while failing to control a template means different audits ask different questions. A system that treats the template as a controlled document and every completed audit as a frozen record keeps the two roles straight automatically.

If a registrar asked for last year's audit evidence, how long would it take?

See Fast Audit retrieve the whole chain — checklist, evidence files, findings and closure history — for any past audit, in a 30-minute demo.

Get a demo

The audit evidence chain

What a certification body really tests is not any single record but the chain — whether you can follow one thread from the planned audit all the way to its closed findings without a break. A complete chain looks like this:

From plan to retained evidence
1
The planned audit
A dated audit generated from an approved plan, against a controlled checklist template — the anchor the whole chain hangs from.
2
The answered checklist
Each question answered with its conformance verdict, score, clause and observation — the record of what was checked and found.
3
The attached evidence
Photos, certificates, measurements and referenced record numbers — the objective evidence behind each answer, held with the audit.
4
The finding and CAPA history
Each non-conformance with its clause and grade, and its append-only closure trail of actions, dates and sign-offs.
5
The retained report
The audit and NC-summary reports, archived and retrievable for the retention period as the durable record of the whole audit.

The power of the chain is that every link points to the next: a finding references its checklist answer, which references its evidence; a closure references its finding. When those links are real database relationships rather than filenames that happen to match, the chain cannot silently break, and reconstructing "what happened in that audit" is a query, not an archaeology project. The CAPA closure history is the most scrutinised link, because it proves findings were not just raised but resolved.

What a certification body reviews

At a surveillance or recertification audit, a registrar works through a predictable set of evidence, and knowing the list is the fastest way to be ready:

  • The audit programme and plan — evidence that audits were planned at intervals and covered every process and clause.
  • Completed audit reports and checklists — evidence the planned audits were actually conducted, with results.
  • Findings, non-conformances and corrective actions — evidence issues were graded, actioned and verified to closure.
  • Auditor competence records — evidence the audits were conducted by qualified, independent auditors.

Notice that every item is a record, and every one is a link in the chain above. The programmes that sail through surveillance are not the ones with the thickest binders; they are the ones where any of these can be produced in seconds because they all live on one system, tied to the audits they belong to. The dashboards and audit reports are where that retrieval happens, and auditor competence ties back to the competency records.

How long to retain audit records

Retention is a policy decision, but it is bounded below by a hard requirement: records must be kept at least long enough for a registrar to review previous audits, which for a three-year certification cycle means at least three years. Regulated and automotive sectors usually go further, driven by customer-specific requirements and statutory duties — retention tied to the length of production plus a service period, or a fixed number of years beyond it, is common. The disciplined approach is to define a retention period per record type in a documented procedure — audit reports, NC records, competence evidence may each have different periods — and to keep records legible, identifiable, protected and retrievable throughout. Guessing, or keeping everything forever in an unsearchable share drive, both fail an audit in their own way; confirm the exact periods with your certification body and customers.

How Fast Audit captures and retains evidence

Fast Audit Software is built so the evidence chain is a by-product of running the audit, not a separate documentation effort, on the shared Fast Suite platform:

1
Every audit is one linked document. The audit, its answered checklist, findings and closure history are all part of a single audit record on the platform's document engine — so the chain is real relationships, not matching filenames.
2
Evidence captured at the question. Conformance, score, clause and observation are recorded per checklist question during checklist entry, and supporting files attach through the platform's document handlers — the objective evidence held with the answer.
3
Templates controlled, audits frozen. Reusable checklist templates are managed as controlled documents, while each completed audit is retained as a record — the document-versus-record distinction enforced automatically.
4
Competence evidence linked to auditors. Certificates and training records are stored against each auditor, so the competence half of the evidence a registrar asks for is retrievable alongside the audits they conducted.
5
Reports retained and retrievable. The audit and NC-summary reports are generated and archived per audit, and the dashboards and reports make any past audit's full chain available on demand.

Because it runs on the shared platform, audit evidence uses the same document control, party and user masters as the rest of the suite, and the retention it supports is a matter of policy configuration rather than manual filing. The result is that the whole evidence chain — plan, checklist, evidence, finding, closure, report — is one query away when a certification body asks. Confirm retention periods and evidence expectations with your certification body and customers.

Keep going — the internal-audit library
From the findings that generate evidence to the competency records behind them, plus the features that implement each stage.

Frequently asked questions

What is audit evidence?

Audit evidence is the records, statements of fact or other information that are relevant to the audit criteria and are verifiable. It is what an auditor gathers to decide whether a requirement is met — a calibration record, a measurement, an observed practice, a signed document. The two defining tests are relevance, meaning it bears on the criterion being audited, and verifiability, meaning another auditor could confirm it. Anything that fails those tests is an impression, not evidence, and cannot support a finding.

What is objective evidence?

Objective evidence is data supporting the existence or truth of something, obtained through observation, measurement, test or other means. In auditing it is the factual basis of every finding — the specific record seen, the value measured, the activity watched — as opposed to opinion or hearsay. A finding built on objective evidence can be pointed to and re-checked, which is why it stands up to challenge. Recording the exact evidence behind each finding, not just the conclusion, is what makes an audit defensible.

What is the difference between a document and a record?

ISO 9001:2015 uses the term documented information for both, but the distinction still matters. A document states intent and is kept current — a procedure, a work instruction, a control plan, an audit checklist template; it is controlled, revised and superseded. A record is evidence of a result that has occurred and is retained unchanged — a completed checklist, an audit report, a corrective-action history. You control documents to keep them right, and you retain records to prove what happened. An audit programme produces mostly records.

What audit records must be retained?

ISO 9001 clause 9.2.2 requires organisations to retain documented information as evidence of the implementation of the audit programme and of the audit results. In practice that means retaining the audit programme and plans, the completed checklists and audit reports, the findings and non-conformances with their evidence, the corrective actions taken and their results, and the auditor competence records. Together these prove not only that audits happened but that they were conducted by competent people and their findings were closed.

How long should audit records be kept?

Retention is set by the organisation, but it must cover at least the certification cycle so a registrar can review previous audits, which usually means three years. Automotive and other regulated sectors often require longer, driven by customer-specific requirements and statutory duties — sometimes the length of production plus service, or a fixed number of years beyond it. The right approach is to define a retention period per record type in a documented procedure and confirm it against your certification body's and customers' requirements rather than guessing.

How does Fast Audit store audit evidence?

Fast Audit stores every audit as a document on the platform's document engine, so the completed checklist, its answers and observations, the attached evidence files, the corrective-action history and the generated reports are all linked to one audit record. Evidence files and competency certificates are held through the platform's document control, and audit and non-conformance reports are produced and retained as report snapshots. Because everything hangs off the same audit document, the full evidence chain from plan to closure is retrievable on demand rather than scattered across folders and inboxes.

Ready to have your audit evidence one query away?

A 30-minute Fast Audit Software demo shows the whole evidence chain — checklist, attachments, findings, CAPA history and reports — retrievable for any past audit, on your own standards.

Get a demo
No commitment. No slides. Your audit evidence on screen.