Evaluate evidence against the question it is meant to answer. A questionnaire is management's representation unless corroborated. A certificate confirms conformity only for its named standard, certified scope, entities, sites, and validity period. An independent assurance report is limited by its control criteria, system description, period, testing, exceptions, and any excluded subservice organizations. A penetration test covers the tested targets, methods, and date, not every control in the relationship.
For each item, record provenance, version, period, scope, reviewer competence or independence where relevant, limitations, exceptions, and follow-up. Compare the evidence with the agreement and risk treatment plan. Evidence can support a conclusion without covering the entire relationship; mark uncovered requirements as not verified rather than treating the document title or logo as proof.
Example: if a supplier's ISO/IEC 27001 certificate covers its corporate ISMS but excludes the hosting location or managed service being acquired, the certificate can still support covered governance controls. It does not verify the excluded service. Request scoped evidence, add another control, restrict use, choose another supplier, or send the remaining risk to the authorized owner.