EvidenceSheet

PI1.4 System outputs are complete, valid, accurate, timely, and distributed

Implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives.

5
artefacts
2
held by a system
1
at each review
moderate
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Evidence outputs are complete and accurate, such as reconciliation of output to input and to processing records · Document repository
  • Records of output errors or failed deliveries and their resolution · Document repository

periodic reviewEvidence produced at each review

  • Evidence of controls over distribution, ensuring outputs reach only authorised recipients and are protected in transit · Document repository

governing documentDocuments that govern the control

  • Policies and procedures governing the creation, availability and delivery of outputs, including who is authorised to receive each output · Policy repository / GRC workspace
  • Evidence of timeliness of delivery against the specification or service commitment · Document repository

First move

Start with the 2 of 5 artefacts that already live in a system (Document repository); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

PI1.3 System processing is complete, valid, accurate, timely, and authorized · PI1.5 Inputs are processed completely, accurately, and timely for stored data