Because an effective control must be defensible at the moment of review, not merely described in a policy. Current evidence shows that the control existed, operated, and matched the governed system state when assessed. Without freshness, the proof is too weak to establish traceable compliance.
Why This Matters for Security Teams
Auditors are not just checking whether a control was documented, they are checking whether it was operating in the environment that existed at the time of review. Fresh evidence helps prove that access boundaries, logging, review cadence, and remediation actions were current rather than stale promises carried forward from an older control cycle. That distinction matters because stale artefacts can hide drift, exceptions, and ownership gaps that no longer match the real system.
Current evidence also reduces dispute during testing. When a team can produce recent screenshots, tickets, exports, or signed attestations that align to the specific asset or process under review, the audit conversation shifts from opinion to verification. That is why frameworks such as ISO/IEC 27001:2022 Information Security Management and SOC 2 Trust Services Criteria (AICPA) place so much weight on evidence that is timely, traceable, and tied to control operation, not merely policy intent. In practice, many control failures are first exposed when an audit asks for current proof and the team can only produce last quarter’s screenshots.
How It Works in Practice
Fresh evidence matters because compliance is assessed against a living control environment. Auditors typically want to see that a control is not only designed correctly, but also executed consistently and at the right interval. The evidence should make the chain easy to follow: what was controlled, when it was checked, who performed or approved the check, and what system state or remediation outcome resulted.
Good evidence usually has four traits:
- Time-bound: it reflects the current review period, not an old control cycle.
- Traceable: it can be linked back to a person, ticket, record, or system event.
- Specific: it matches the exact asset, control, or population being audited.
- Reproducible: another reviewer can confirm the same state from source records.
That is why auditors often prefer current exports from systems of record, recent access reviews, ticket closures, change logs, configuration snapshots, or attestation records over narrative explanations. A policy may show intent, but current evidence shows execution. Where the control is recurring, the most persuasive proof is often the latest completed instance plus the process that would generate the next one. For organizations working to align control operation and evidence collection more systematically, NIST Cybersecurity Framework 2.0 is useful because it reinforces governance, identification, protection, detection, response, and recovery as ongoing functions rather than one-time deliverables.
Freshness also helps surface broken process ownership. If the last evidence pack is easy to find but the current one is missing, that often indicates a control that has become manual, delayed, or informally delegated. These controls tend to break down when evidence is assembled long after the event, because reconstruction is less reliable than contemporaneous recordkeeping.
Common Variations and Edge Cases
Tighter evidence expectations often increase operational overhead, so organisations have to balance audit readiness against collection burden. The right level of freshness depends on the control: a quarterly review may only need quarterly evidence, while access changes, incident response, or privileged actions usually need much more current proof.
Some controls are better demonstrated through system logs and workflow records, while others need human attestation to show review quality. For example, a signed approval may be useful for accountability, but it is weak if it cannot be tied to the underlying state change. Conversely, a clean system export may prove activity, but not necessarily that the reviewer exercised judgment. Current guidance suggests using both where the control has a human decision and a system outcome.
Edge cases often appear in outsourced, cloud, or rapidly changing environments, where the evidence source is split across multiple platforms. In those cases, the key question is whether the evidence still maps cleanly to the governed boundary. When the boundary is unclear, auditors will usually press for more recent and more specific proof, not less. A practical way to reduce friction is to keep evidence generation close to the control execution point, rather than trying to reconstruct it at audit time.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.35 — Independent Review of Information Security | Audit evidence must show controls were operating at review time. |
| A.5.36 — Compliance with Policies, Rules and Standards for Information Security | Fresh evidence proves practice matches approved policy and standards. | |
| Recommendation — Retain current records that demonstrate each control operated during the review period. Validate that evidence reflects the current governed state, not a stale policy snapshot. | ||
Practitioner Guidance
What to prioritise: Build evidence collection around the control event itself. If the proof is being assembled manually after the fact, it is already weaker than the underlying control, even when the control was performed correctly.
What to verify: Confirm that every piece of evidence answers three questions at once: when did it happen, what exact system or population did it cover, and who can attest to it. If any of those are missing, expect follow-up from auditors.
Common mistake: Teams often overfocus on producing a polished evidence pack and underfocus on proving current state. Audit confidence usually comes from freshness plus traceability, not presentation quality.
Practitioner takeaway: The strongest compliance evidence is contemporaneous, specific, and tied to the control boundary, because auditors are testing whether the control is real today, not whether it was once described well.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 16, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org