Not all evidence is equally believable
Two organizations can hand over evidence for the same requirement and get noticeably different receptions. That is not inconsistency on the assessor's part. Evidence differs in how much weight it can bear, and audit practice has ranked it that way for a very long time.
The ranking is worth understanding before an assessment, because an organization has more control over what kind of evidence it produces than it usually realizes.
Roughly strongest to weakest
What the assessor obtains directly. A configuration the assessor reads from the system, a test they run, a process they watch being performed. Nothing sits between the fact and the person forming the conclusion.
What a system produced while doing its job. Logs, automatically generated reports, ticket histories with system timestamps. These were created for the organization's own operational purposes, not for the assessment, and they are usually inconvenient to alter selectively.
What the organization compiled and handed over. Exports, screenshots, spreadsheets assembled to answer the question that was asked. These might be entirely accurate, and they were produced by someone who knew what answer would be convenient.
That knowledge is the difficulty, and acting on it requires falsifying nothing. Someone who knows what the answer is supposed to be makes a series of small choices while gathering the data—which systems to pull from, which date range to cover, how to word the query, which of several exports to attach—and each of those choices has a defensible rationale and a direction. The result can be truthful in every particular and still not represent the population it appears to describe. It is also the kind of bias that does not feel like bias to the person doing it, which is why an assessor would rather specify the sample than receive one.
What someone says. An explanation of how the process works. Useful for understanding, necessary for context, and the weakest thing on which to rest a conclusion.
The principle underneath
Two things move evidence up or down that list.
The first is distance from the party with an interest in the result. This is not an accusation of dishonesty, and it is worth being clear about that, since organizations sometimes hear it as one. The ranking exists because incentives exist. A method that only works when nobody is tempted is not much of a method, so audit practice assumes the incentive and prefers evidence that does not depend on the auditee's disinterest.
The second is whether the record was created for its own purposes or for the assessment. A report the operations team has produced monthly for three years, and acted on, says something a report generated the week before the assessor arrives does not—even when both contain the same numbers.
Two related factors adjust the weight further. Contemporaneous records beat reconstructed ones: something written when the work happened is stronger than something assembled afterward from memory. And corroboration matters, because two independent sources agreeing is stronger than either alone, particularly when one of them is a system record and the other is a person's account.
The idea is not unique to security
ISACA's CISA material is where many security practitioners first meet this ranking, but it neither originated there nor is peculiar to information systems audit. Financial and internal audit reached the same conclusions, in some cases decades earlier, and phrase them in strikingly similar terms.
The AICPA's audit evidence standard, AU-C 500, long set out generalizations that will look familiar: evidence obtained directly by the auditor is more reliable than evidence obtained indirectly; evidence from independent sources outside the entity is more reliable than evidence from within it; and original documents are more reliable than photocopies or converted electronic copies, whose reliability depends on the controls over the conversion.
Statement on Auditing Standards No. 142 rewrote that section, effective for periods ending on or after December 15, 2022, and replaced the ranking with attributes of the information itself: accuracy, completeness, authenticity, and susceptibility to bias. That is less a reversal than a generalization of the same reasoning. Directness and independence were always proxies for those attributes, and naming the attributes directly travels better to forms of evidence the older wording never anticipated. The PCAOB's AS 1105 makes the same point for public company audits, tying reliability to the nature and source of the evidence and to whether that source is knowledgeable and independent of the company. ISA 500 covers the same ground internationally.
Internal audit frames it as properties rather than a ranking. Under the IIA's 2017 framework, standard 2310 required auditors to identify information that is sufficient, reliable, relevant, and useful, and defined sufficient as factual and convincing enough that a prudent, informed person would reach the same conclusion. The 2024 Global Internal Audit Standards, mandatory since January 2025, carry that requirement into Standard 14.1 on gathering information for analyses and evaluation, framed as relevance, reliability, and sufficiency. The numbering changed; the reasoning did not.
The convergence is the interesting part. Bodies with different mandates, overseeing different work, arrived at the same handful of principles: prefer what the auditor obtained directly, prefer what came from a source with no stake in the answer, prefer the original to the copy, and have enough of it to carry the conclusion. An organization assembling evidence for a CMMC assessment is being measured against reasoning that predates CMMC by a long way, which is also why the reasoning is unlikely to shift under it.
What this means for the organization
The useful consequence is that evidence strength is largely a design decision, made when procedures are written rather than when an assessor asks.
- Prefer output a system generates on a schedule over something a person assembles on request. The first is stronger and, after setup, less work.
- Keep what makes a record self-describing: the timestamp, the system it came from, the account that produced it, and the period it covers. An undated screenshot with no hostname is a picture of a screen.
- Retain records where they cannot be quietly edited, and where the retention period outlasts the assessment window.
- Where an assessor can be given read-only access to a live system rather than an export, offer it. It is stronger evidence, and it means the assessor is not carrying a copy of the organization's data.
- Keep the record of the work, not only the result. That a review was completed is weaker than the dated record naming what was examined and what changed.
None of these is expensive when chosen at the outset. Retrofitting them under assessment pressure is expensive, and it produces exactly the reconstructed, compiled-on-request evidence that carries the least weight.
Weak evidence is not useless
An organization that can only offer a spreadsheet and an explanation has not failed. But it should understand what it has just set in motion.
The mechanism is simple, and worth stating as plainly as possible. When an assessor receives strong evidence that a requirement is met, the item is settled and they move to the next one. When the evidence is weak, or has to be produced during the assessment because it did not already exist, they do not move on. They ask another question, request another sample, look at a second system, and start wondering what else is in the same condition.
Nothing about that is punitive. An assessor's job is to reach a defensible conclusion, and weak evidence has not given them one yet, so they keep going until something does.
The cost lands in two places. The obvious one is time, and assessment time is expensive. The less obvious one matters more: a longer examination covers more ground than a short one, and findings are discovered in the ground that gets covered. Weak evidence rarely produces a finding by itself. It produces the extended look during which the actual findings turn up.
The organization that finishes quickly is usually not the one with fewer problems. It is the one that could answer each question the first time it was asked.
Kenneth Ingham Consulting reviews what an organization's procedures actually produce and what that evidence will be worth when someone independent examines it.