> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/company-operating-manual/security-compliance-and-data/audit-and-evidence.md).

# Audit and Evidence

### Purpose

Audit evidence allows the company to demonstrate that delivery was controlled, secure, and compliant.

### Evidence Types

Evidence may include:

* contracts
* Statements of Work
* approvals
* meeting records
* decision logs
* change records
* risk logs
* test evidence
* security records
* acceptance records
* access records
* release records

### Evidence Standards

Evidence should be:

* dated
* attributable
* complete
* stored in an approved location
* linked to the relevant deliverable or control
* retained according to the applicable requirement
