Choose evidence that can answer the defined monitoring question. Measures and service reports show performance against agreed criteria. Risk assessments and audit reports test compliance or changed exposure. Incident and change histories show whether procedures operated. Corrective-action records show whether findings were addressed. Access reviews, test results, configuration or change records, and transition reports can support specific control conclusions.
A policy, questionnaire, certificate, or assurance report is useful only within its stated scope. Check the covered legal entity, product or service, systems, locations, period, control criteria, exclusions, qualifications, subcontractors or subservice organizations, testing method, exceptions, and management response. Record any gap between that scope and this relationship.
Example review: an access-control obligation calls for a periodic supplier access report. The reviewer checks that the report covers the agreed system, supplier personnel, access period, approvals, removals, and exceptions. A report for the wrong service or period is a coverage gap even if every row in that report passed.