# Audit Evidence Index

> **Template — adapt before use.** A single register of the evidence that proves each control, who owns it, and when it was last refreshed. Map one piece of evidence to every framework it satisfies — collect once, credit everywhere.

| | |
|---|---|
| **Program / framework(s)** | [e.g. PCI DSS, SOC 2, ISO 27001] |
| **Maintained by** | [Name / Role] |
| **Last updated** | [YYYY-MM-DD] |

## Evidence register
| # | Control area | Evidence artifact | Source / location | Owner | Frequency | Last collected | Frameworks satisfied |
|---|---|---|---|---|---|---|---|
| 1 | Access review | Signed access-review log | [link] | [owner] | Quarterly | [date] | ISO A.5.18, PCI 7, SOC2 CC6 |
| 2 | Encryption in transit | TLS config export | [link] | [owner] | Annual | [date] | PCI 4, ISO A.8.24, SOC2 CC6.1 |
| 3 | Change management | PR + approval records | [link] | [owner] | Continuous | [date] | PCI 6, ISO A.8.32, SOC2 CC8.1 |
| 4 | Logging | Log samples + alert config | [link] | [owner] | Quarterly | [date] | PCI 10, ISO A.8.15, SOC2 CC7 |
| 5 | Risk assessment | Risk register + report | [link] | [owner] | Annual | [date] | ISO Cl.6, SOC2 CC3, PCI 12.3 |
| 6 | Incident response | IR plan + tabletop notes | [link] | [owner] | Annual | [date] | PCI 12.10, ISO A.5.24, SOC2 CC7.3 |
| 7 | Policies | Approved policy set | [link] | [owner] | Annual | [date] | All |
| 8 | Vendor management | Vendor inventory + reviews | [link] | [owner] | Annual | [date] | ISO A.5.19, PCI 12.8, SOC2 CC9.2 |
| ... | | | | | | | |

## Notes
- Flag any evidence that is stale (past its refresh frequency) for follow-up.
- "Frameworks satisfied" is where cross-framework mapping pays off — reuse one artifact across every framework it covers.
