IT Audit Factory MSP — Auditor Export and Evidence Guide
Preparing an audit package
- Select the client.
- Select the exact certification/program and scope.
- Review the program requirement workspace and resolve applicability/evidence states.
- Review Reports & Runs and remove/mark invalid output with reasons.
- Confirm command evidence and screenshot proof are present.
- Click Export Current Certification for Auditor.
- Store the generated ZIP using the client/framework/program/date-time file name.
Package contents
The certification export includes the program metadata, requirement state, program-linked assessment run manifest, reports, evidence versions linked to those runs, original run packages (which contain command evidence and screenshots), and the audit trail.
What the auditor should verify
- Client/program/scope match the audit engagement.
- Command evidence is sanitized but specific enough to show the lookup.
- Screenshot proof shows the application and Windows taskbar clock.
- SHA-256 values match exported evidence.
- Manual controls are not falsely presented as automated passes.
Guide basis
R68 package: Auditor-Export-and-Evidence-Guide.html
Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.