Producing a convincing record — minutes, a log, a screenshot, a report on letterhead — takes minutes, and the cost falls every quarter. Establishing that the record is genuine takes increasingly longer. This asymmetry redefines the profession and raises a single operational question in every audit · how did this evidence reach my desk? The entire edifice of technical trust rests on the assumption that this question examines · that the evidence presented is what it claims to be.


This criterion develops the tacit assumption in Criterion 02. The five elements of verifiable evidence — actor, date, criterion, scope, validity — can all be present and all be synthetic · a generated PDF has them printed on it, a fabricated log lists them in order, minutes produced yesterday bear last year’s date. I call the missing property evidence integrity , and it comprises three conditions of the record · provenance — who and which system produced it —, immutability — no one has modified it since its creation — and custody — who could have handled it on its way to the auditor’s desk. Evidence is audited too. Where record integrity remains unexamined, the five elements have no foundation.

Operational evidence and prepared evidence

Operational evidence usually predates the audit · it is the trail an organisation leaves as it works. Its creation dates follow activity, with pauses and peaks that can be explained. A batch created shortly before the visit does not prove falsity; it requires additional corroboration. The creation date differs from the date the record states, and the gap between the two is investigated before reaching a conclusion.

Three record pathologies

Pathology 01 · the record supplied without corroboration. A screenshot supplied by the auditee or an extract printed by the department without the auditor having access to the source can be useful evidence, but remains clearly dependent on the interested party. Its weight increases when corroborated against an independent source or the originating system.

Pathology 02 · the record generated in bulk. Documentation attributed to different periods turns out to have been created in the same week. Clustered dates, the same author for different processes or versions created as final are signals for review. They may also have a legitimate explanation, such as a migration or consolidation; metadata guides corroboration, not replaces the conclusion.

Pathology 03 · the synthetic record. Minutes with cloned signatures, generated supporting documents, audio or video capable of sustaining a false identity in a video call. The AI Incident Database brings together fraud incidents involving these mechanisms. The database makes it possible to verify that the risk exists; it does not, on its own, provide a universal rate applicable to every organisation.

Evidential value has shifted to provenance

The current ease of generating convincing documents reduces the value of accepting content on appearance alone. Provenance, protection against alteration and custody become part of the analysis. Depending on the risk, the response may include corroboration against another source, metadata review, access to the originating system or cryptographic integrity and timestamping mechanisms. No single mechanism authenticates the documented event on its own.

The standard applies to the auditor too

The doctrine would be incomplete if it stopped at the auditee. The auditor’s working papers face the same question · where each piece of evidence came from, who handled it, and what protection it had. The public version of this discipline is correction · someone who publicly corrects their own information demonstrates that their system of assertions works — continuous auditing applied to their own signature. An auditor who demands provenance from others and neglects their own asks for treatment their doctrine does not authorise.

A statement of limitations, because limitations are part of the argument. This criterion requires reconstructing the provenance of evidence that carries weight in the finding, and honestly stating the degree of corroboration in the report. Case-by-case forensic examination belongs to another profession and is called upon when the risk justifies it.

The criterion test

Take the three pieces of evidence that carry the most weight in your latest audit — internal or external — or in your latest management review. For each, three questions. Who produced it and in which system? Does the creation date match the date the document states? What protection did it have against alteration between its creation and this desk? Expected response · all three questions are answered with a consultable record, without relying on the word of whoever supplied it, and the full reconstruction takes less than one working day. Key evidence supported only by the auditee’s word changes category · it ceases to underpin the finding and remains pending corroboration — and the report says so in those words.