Skip to main content

Evidence Bundles

Package compliance evidence for audits and reviews

bundlesauditpackagesevidence collection

Evidence Bundles

Bundle your compliance evidence into organized packages for auditors, reviewers, and stakeholders.

What Are Bundles?

Evidence bundles are curated collections of evidence artifacts organized for a specific purpose:

  • Audit packages - Comprehensive evidence for external audits
  • Framework bundles - All evidence for a specific framework
  • Control bundles - Evidence for specific controls
  • Review packages - Selected evidence for internal reviews

Creating Bundles

Start a New Bundle

  1. Go to Evidence > Bundles
  2. Click Create Bundle
  3. Configure bundle settings
  4. Add evidence
  5. Save bundle

Bundle Settings

SettingDescription
NameBundle identifier
DescriptionPurpose and scope
TypeAudit, review, framework, custom
Framework(s)Associated frameworks
ControlsSpecific controls to include

Adding Evidence

By Control

Include all evidence for selected controls:

  1. In bundle editor, click Add by Control
  2. Select framework
  3. Check controls to include
  4. All linked evidence is added

By Artifact

Select specific artifacts:

  1. Click Add Artifacts
  2. Browse or search artifacts
  3. Select items to include
  4. Add to bundle

By Type

Add evidence by type:

  1. Click Add by Type
  2. Select type (documents, screenshots, etc.)
  3. Filter by framework/control
  4. Add matching artifacts

Bundle Organization

Sections

Organize bundles into sections:

Audit Bundle - Q4 2024
├── 1. Executive Summary
├── 2. Framework Overview
├── 3. Identity & Access Controls
│   ├── MFA Configuration
│   ├── Conditional Access Policies
│   └── Role Assignments
├── 4. Data Protection Controls
└── 5. Appendices

Creating Sections

  1. Click Add Section
  2. Enter section name
  3. Drag artifacts into section
  4. Reorder as needed

Section Notes

Add context to sections:

  1. Click section header
  2. Add introductory notes
  3. Explain what evidence demonstrates

Bundle Templates

Using Templates

Start from pre-built templates:

  1. Click Create from Template
  2. Select template:
    • SOC 2 Audit Package
    • ISO 27001 Review Bundle
    • CIS Assessment Bundle
  3. Template creates sections and control links
  4. Customize as needed

Creating Templates

Save your bundle as a template:

  1. Complete bundle configuration
  2. Click Save as Template
  3. Name and describe template
  4. Template available for future bundles

Bundle Review

Review Workflow

Before finalizing, review bundles:

  1. Completeness Check - Verify all controls have evidence
  2. Quality Review - Ensure evidence is appropriate
  3. Currency Check - Verify evidence is current
  4. Gap Identification - Find missing items

Completeness Report

Generate a completeness report:

  1. Open bundle
  2. Click Review > Completeness
  3. See coverage by control
  4. Identify gaps

Evidence Gaps

If controls lack evidence:

  • Highlighted in review
  • Link to gap resolution
  • Can upload directly
  • Or mark as acknowledged gap

Exporting Bundles

Export Options

FormatDescription
ZIP ArchiveAll evidence files organized
PDF DocumentFormatted bundle document
Index + FilesSpreadsheet index with file references

ZIP Export

Creates a ZIP file with:

bundle-export/
├── index.xlsx          # Evidence index
├── 01-executive-summary/
│   └── summary.pdf
├── 02-framework/
│   ├── control-1.json
│   └── control-2.pdf
└── 03-appendices/
    └── supporting-docs/

PDF Export

Creates a single PDF with:

  • Table of contents
  • Section organization
  • Embedded evidence (images, text)
  • Links to external files

Index Export

Creates a spreadsheet with:

  • Control mapping
  • Evidence descriptions
  • File locations
  • Status indicators

Sharing Bundles

Share bundles with external parties:

  1. Open bundle
  2. Click Share
  3. Configure:
    • Expiration date
    • Password protection
    • Download permissions
  4. Copy share link

Share Options

OptionDescription
ExpirationLink validity period
PasswordRequire password to access
View OnlyPrevent downloads
Track AccessLog who views

Email Bundle

Send bundle directly:

  1. Click Share > Email
  2. Enter recipient addresses
  3. Add message
  4. Choose attachment or link
  5. Send

Bundle Management

Bundle Status

StatusMeaning
DraftWork in progress
Under ReviewBeing reviewed
ApprovedReady for use
SharedDistributed externally
ArchivedNo longer active

Version History

Track bundle changes:

  • View modification history
  • See who made changes
  • Restore previous versions

Archiving Bundles

Archive completed bundles:

  1. Open bundle
  2. Click Archive
  3. Bundle moves to archive
  4. Still accessible, not in active list

Best Practices

Before an Audit

  1. Create bundle well in advance
  2. Run completeness check
  3. Address all gaps
  4. Have internal review
  5. Generate final export

Organization

  • Use consistent naming
  • Organize by control/theme
  • Include context notes
  • Maintain section order

Quality

  • Include only relevant evidence
  • Ensure evidence is current
  • Add explanatory notes
  • Remove duplicates

Troubleshooting

Large Bundle Export

If export fails for large bundles:

  • Export sections separately
  • Use ZIP format (smaller)
  • Contact support for large files

Missing Evidence

If evidence doesn't appear in bundle:

  • Verify artifact is linked to control
  • Check artifact status (active)
  • Refresh bundle

If recipients can't access:

  • Verify link hasn't expired
  • Confirm password is correct
  • Check for firewall blocks

What's Next?

Global Search

Search for pages, settings, and documentation