Use this rule: every file in the evidence pack needs an owner, effective date, scope, and approval state. If one is missing, treat the file as a lead until someone validates it.
Copyable evidence checklist
- Information security policy
- Access control and identity policy
- Encryption and key-management standard
- Secure development policy
- Vulnerability and patch process
- Incident response plan
- Business continuity and recovery plan
- Vendor risk process
- Data retention and deletion policy
- Privacy policy and data-processing terms
- Architecture and data-flow diagram
- Subprocessor list
- Current audit reports or certificates
- Penetration-test summary and remediation state
- Control test results
- Current product and environment scope
- Named control owners
- Document effective and review dates
- Known exceptions and compensating controls
- Approved prior answers with source links
Sort the packet by what it proves
| Evidence type | What to check | Common questions it supports |
|---|---|---|
| Policy | Approved, current, and applies to the named product | Governance, access, encryption, response, retention |
| Operating proof | Test date, result, reviewer, and unresolved exceptions | Control effectiveness, reviews, testing cadence |
| Architecture | Environment, boundaries, data stores, and subprocessors | Hosting, data flow, isolation, residency |
| Contract or privacy term | Current language and covered customer or plan | Deletion, breach notice, retention, data use |
| Audit or certification | Entity, system, period, scope, and exclusions | SOC 2, ISO, PCI, or other attestations |
Prepare the packet in four steps
List the question domains
Scan the questionnaire for access, data protection, development, incident response, recovery, privacy, vendor, and compliance topics.
Choose one current source per domain
Prefer approved sources with clear scope. Add operating proof where a policy describes intent but not whether the control works.
Add owner, date, and exception fields
Make the person and review state visible. This turns a document pile into a controlled evidence pack.
Remove duplicate and stale material
Archive superseded versions. When two current sources conflict, flag the conflict before anyone drafts an answer.
Apply one evidence boundary
Mark a claim Supported only when current, in-scope evidence proves it. Use Needs review when evidence is partial, stale, or conflicting. Use Unknown when the approved packet does not answer the question.
A safe synthetic example
Evidence register entry
Source: Access Control Policy v4.2 · Owner: Security lead · Effective: May 1, 2026 · Scope: Production SaaS
Supports: MFA, least privilege, access reviews, offboarding.
Does not prove: That the quarterly review ran on time. Attach the latest review record for that claim.
Common mistakes
- Using a policy as proof that a control operated.
- Missing the system or legal entity covered by a certificate.
- Keeping several versions of the same source in the active pack.
- Uploading contracts or reports without checking whether their disclosure is allowed.
- Assuming the cloud provider's control automatically proves the customer's application control.
How SaneCite handles this
You choose which documents SaneCite may use as evidence. It drafts from those sources, shows the citation behind supported answers, and sends uncovered questions to review instead of filling gaps.
Questions people ask
- Do I need every document on this list?
- No. Gather what applies to the questionnaire and your product. More files can create more conflict when their status and scope are unclear.
- Can a trust center replace the evidence pack?
- It can supply useful public proof, but many questions require internal scope, owner, test, or contract details that a trust center does not contain.
- How often should I review the pack?
- Review it when a source changes and on a regular schedule set by your risk program. High-change controls need shorter review periods.
Primary sources
- NIST SP 800-53 Rev. 5, Security and Privacy Controls (accessed July 26, 2026).
- NIST Cybersecurity Framework 2.0 (accessed July 26, 2026).
- FTC, Protecting Personal Information: A Guide for Business (accessed July 26, 2026).
Published July 26, 2026. No material revisions yet.
Bring your evidence pack.
Use it to draft a cited questionnaire and review the gaps.