Document

Ask review

Create evidence packages, audit trails, and compliance documentation

Hats
2
Review
Ask
Unit Types
Evidence, Documentation, Audit Trail
Inputs
Remediate

Dependencies

Remediateremediation-log

Hat Sequence

1

Documentation Writer

Focus: Create the narrative compliance documentation that ties evidence to controls and tells the compliance story end-to-end. Produce audit trails, control descriptions, and summary documents that make the auditor's job straightforward.

Produces: Compliance documentation package including control narratives, audit trail document, and summary report organized per framework requirements.

Reads: Evidence package from evidence collector, remediation log, and scope documents via the unit's ## References section.

Anti-patterns:

  • Writing documentation that cannot be traced back to specific evidence
  • Creating a narrative disconnected from the actual control implementations
  • Not organizing documentation to match the auditor's expected structure
  • Omitting cross-references between related controls and evidence
  • Producing documentation so dense that auditors cannot find what they need
2

Evidence Collector

Focus: Gather, organize, and catalog evidence artifacts that demonstrate control implementation. Ensure every piece of evidence has clear provenance — source, date, collector, and the control it supports. Build a complete evidence package that an auditor can navigate efficiently.

Produces: Evidence package with artifacts mapped to controls, provenance metadata for each artifact, and an evidence index for auditor navigation.

Reads: Remediation log from remediate stage via the unit's ## References section.

Anti-patterns:

  • Collecting evidence without recording when and where it was obtained
  • Storing evidence without mapping it to specific controls
  • Accepting screenshots without timestamps or context
  • Not verifying that evidence is current and reflects the actual state
  • Leaving gaps in evidence coverage without documenting why

Document

Criteria Guidance

Good criteria examples:

  • "Evidence package includes at least one artifact per control demonstrating implementation with timestamps and provenance"
  • "Audit trail links every control to its scope definition, assessment finding, remediation action, and verification evidence"
  • "Documentation follows the framework's required format and is organized for efficient auditor navigation"

Bad criteria examples:

  • "Evidence is collected"
  • "Documentation is complete"
  • "Audit trail exists"

Completion Signal

Evidence package exists with artifacts mapped to every in-scope control. Each piece of evidence has clear provenance (source, date, collector). Audit trail connects scope through assessment, remediation, and verification in a continuous chain. Documentation is organized for external auditor consumption with a clear index and cross-references.