Evidence, audit & findings
Evidence principles
Section titled “Evidence principles”Evidence should be:
- Within the approved AIMS scope.
- Relevant to the atomic requirement.
- Current for the evidence period.
- Authentic and controlled.
- Sufficient to support the conclusion.
- Representative of actual operation.
- Traceable to owner, system, site or process.
Generic governance material may establish organisation-wide design but cannot prove that every included process operates effectively.
Common evidence categories
Section titled “Common evidence categories”| Area | Examples |
|---|---|
| Context and scope | Context analysis, interested-party register, scope statement, process map |
| Leadership | Policy approval, objectives, resourcing, role assignments, management communications |
| Planning | Risk criteria, completed assessments, treatment plans, impact assessments, change plans |
| Support | Competence records, communications, document control, resource decisions |
| Operation | Lifecycle records, approvals, supplier controls, operational risk and impact work |
| Performance | Metrics, monitoring, internal audit programme and reports, management review minutes |
| Improvement | Nonconformity records, cause analysis, corrective action and effectiveness verification |
| Annex A | Control designs, operating records, tests and SoA decisions |
Sampling
Section titled “Sampling”Define the population before selecting a sample. Consider:
- Sites and business units.
- AI roles and lifecycle stages.
- Internal and third-party systems.
- Risk and impact levels.
- New, changed and long-running processes.
- Successful and exceptional cases.
- Time periods and seasonal variation.
Record why the sample is sufficient. Convenience samples alone rarely support an organisation-level conclusion.
Audit test record
Section titled “Audit test record”Capture:
- Requirement and objective.
- Population and selection method.
- Documents or systems inspected.
- Procedure performed.
- Expected criteria.
- Observed result.
- Exceptions and contrary evidence.
- Reviewer, date and independence.
- Conclusion and linked finding.
Findings
Section titled “Findings”A finding should distinguish:
- Nonconformity — a requirement is not fulfilled.
- Observation or improvement opportunity — no demonstrated failure, but weakness may undermine future effectiveness.
Where an audit programme distinguishes major and minor nonconformity, apply the programme’s defined criteria consistently. Do not downgrade a systemic failure merely to improve readiness reporting.
Corrective action
Section titled “Corrective action”Correction addresses the immediate problem. Corrective action addresses the cause and prevents recurrence.
A complete record includes:
- Requirement and objective evidence.
- Scope and impact.
- Immediate correction or containment.
- Cause analysis.
- Corrective action.
- Owner and due date.
- Verification method.
- Effectiveness result.
- Related risks and changes.
Closing an action without verifying effectiveness does not demonstrate improvement.
Audit-readiness checklist
Section titled “Audit-readiness checklist”- Evidence index matches the current scope.
- Controlled documents show approval and version.
- Samples include operating and adverse cases.
- Tests state objective criteria.
- Findings are linked to exact atomic checks.
- Nonconformities are reflected in the readiness conclusion.
- Corrective actions address cause.
- Effectiveness has been independently verified where appropriate.
- Sensitive evidence is protected throughout review and export.