In a recent LinkedIn post, Francisco Gaffney shares a strategic approach to managing evidence for assurance and audit processes, aiming to mitigate common pitfalls. Gaffney emphasizes the need for a structured and consistent methodology to ensure clarity and efficiency.
Gaffney begins by outlining a three-pronged solution to avoid evidence-related issues. The first recommendation focuses on establishing a cadence for evidence collection based on risk levels. This includes monthly attestations for patches and multi-factor authentication, quarterly reviews for high-risk suppliers and re-screens, and annual reviews for lower-risk assessments. He stresses the importance of assigning a unique ID and an owner to each risk within this framework.
“First, set a cadence by risk: monthly for patch and multi-factor authentication attestations, quarterly for high-risk suppliers and re-screens, and annually for low-risk reviews. Tie each risk with an ID and owner.”
According to Gaffney, the second critical component is the centralization of logs. He advocates for keeping these logs in a queryable format, aligning with guidance from the National Cyber Security Centre. This centralization ensures that evidence is readily accessible and consistent, which is crucial for effective audits and assurance activities.
The third solution proposed by Gaffney addresses the common issue of providing evidence images without adequate context. He advises including essential details such as the systems involved, the scope of the evidence, the timestamp, and the approver directly within the filenames and metadata. This practice, Gaffney argues, adds the necessary context to make the evidence meaningful and actionable.
The Case for Centralized and Contextualized Evidence
Francisco Gaffney highlights that these measures contribute to a more streamlined and effective process. By implementing a risk-based cadence and ensuring logs are centralized and queryable, organizations can move away from ad-hoc evidence gathering.
“Avoid evidence images without context; include the systems, scope, timestamp, and approver in the filenames and metadata.”
Gaffney further elaborates on the benefits of this structured approach, suggesting that it leads to a more robust assurance process. The integration of these practices aims to provide a clear and consolidated view of compliance and security posture.
Achieving Continuous Gap Analysis
The ultimate goal, as outlined by Gaffney, is to achieve a state where evidence management is no longer a bottleneck. He envisions a system that offers continuous gap analysis, providing a clear overview of what has been completed, what is still outstanding, and who is responsible for addressing any deficiencies.
“All in one place. Continuous gap analysis. Clear view of what’s done, what’s missing, and who owns the fix before assurance or audit.”
This integrated approach, Gaffney suggests, allows teams to perform assurance and audit tasks more efficiently. The emphasis is on doing the process correctly the first time, thereby saving time and resources in the long run. Gaffney concludes by pointing towards a potential solution, inviting interested parties to join a waiting list at pAIpertrail.com, hinting at a tool designed to implement these principles.
📝 About This Content
This article is based on insights shared by Francisco Gaffney on LinkedIn.
📅 Originally posted on November 15, 2025 | View original post on LinkedIn →