Evidence maps for SaaS controls
Most weak cloud workpapers fail for the same reason: the narrative asserts a control outcome before the file lists the artifacts that could support it. An evidence map reverses that order.
What belongs in the grid
We teach a four-column map in the Audit Documentation Studio: control claim, artifact type, retrieval path, and retention note. Artifact type is concrete — “IAM role export dated 3 March,” not “system access evidence.”
Retrieval path tells the next reader how to regenerate or locate the file if the shared drive link breaks. Retention note flags vendor log windows that expire before your archival period.
When to draw the map
Draw it during scoping, not after testing. Teams that wait until exception drafting discover gaps when time is shortest. The map also surfaces controls that rely on screenshots alone — a signal to request a more durable export.
What the map is not
It is not a substitute for evaluating design or operating effectiveness. It is a documentation habit that keeps financial auditing guidance for cloud application audit documentation grounded in named sources.