The evidence pack you will actually need
Audits are lost on missing evidence rather than missing controls. Teams often have the control working and cannot produce the artefact that proves it operated on a date.
For a document platform, this is the pack to maintain continuously rather than assemble during fieldwork.
Access evidence. A report, generated from the platform, listing who can access each confidential repository as of a date. Plus a sample of joiner, mover and leaver tests showing access matched the role.
Review evidence. The access reviews themselves, with the reviewer named, the date, and the changes made. A review with no changes ever recorded reads as a review nobody performed.
Change evidence. For every platform upgrade: the approval, the test result, and the date it went to production. A staged upgrade path exists precisely so this is producible.
Restore evidence. The date of the last restore test, what was restored, how long it took, and the result. Backup job completion is not evidence of restorability.
Incident evidence. Detection time, assessment, containment, resolution and the review. For a self-hosted deployment, this includes demonstrating that detection exists at all.
Configuration evidence. Proof that the defaults are what the policy says — external sharing disabled, retention rules active, logging enabled. Configuration drifts, so this needs a cadence rather than a one-off screenshot.
The practical test is uncomfortable but useful: pick one control at random and try to produce its evidence in under an hour. Where you cannot, the gap is an evidence problem you can fix before an auditor finds it.
There is a second-order benefit. A platform that produces these artefacts natively makes the pack cheap to maintain, and that is a more honest reason to prefer it than a badge on a marketing page.