{
 "slug": "re-performable-evidence",
 "topic_id": "TOPIC-222",
 "cluster": "Enterprise IGA, Access Certification & Identity Lifecycle",
 "tier": "Tier A",
 "title": "Replacing the screenshot: audit evidence your auditor can re-perform",
 "summary": "An auditor samples twenty access changes and receives twenty screenshots produced by the client's administrator. They are testing a control using evidence generated by the party the control governs.",
 "lede": "Every experienced auditor understands this and accepts it, because no alternative exists. That acceptance is the most quietly consequential compromise in IT general controls testing.",
 "date": "2025-11-08",
 "category": "Compliance",
 "author_id": "constance-ibe-whitmore",
 "tags": [
  "ITGC",
  "audit evidence",
  "SOX",
  "re-performance",
  "access controls",
  "external audit"
 ],
 "image_title": "Re Performable Evidence",
 "schema": "Article",
 "key_takeaways": [
  "Systems produce logs for operations, not evidence for third parties. Extracts are mutable and unsigned, so testing degrades into inspecting a document the client made.",
  "Re-performance is a recognised and stronger form of audit evidence than inspection, and access controls have had no path to it.",
  "An ITGC objective-to-receipt mapping lets a firm pilot this with its auditor on three control objectives rather than across the whole programme."
 ],
 "body": [
  {
   "type": "h2",
   "text": "The hierarchy auditors already use"
  },
  {
   "type": "diagram",
   "kind": "chain",
   "alt": "The evidence hierarchy, and where approvals sit",
   "caption": "Approvals have historically been stuck at inspection because a human decision cannot be re-executed.",
   "nodes": [
    {
     "label": "Inquiry",
     "sub": "asking",
     "note": "weakest",
     "bad": true
    },
    {
     "label": "Observation",
     "sub": "watching",
     "note": "weak",
     "bad": true
    },
    {
     "label": "Inspection",
     "sub": "reading a record",
     "note": "where approvals sit",
     "bad": true
    },
    {
     "label": "Re-performance",
     "sub": "executing the check",
     "note": "strongest",
     "good": true
    }
   ]
  },
  {
   "type": "p",
   "html": "Audit standards distinguish between types of evidence and their relative reliability. Evidence obtained directly by the auditor is more reliable than evidence provided by the entity. Evidence from independent sources outside the entity is more reliable than evidence generated internally. Re-performance — the auditor independently executing a procedure — is stronger than inspection of a document."
  },
  {
   "type": "p",
   "html": "Apply that hierarchy to a typical ITGC access control test and the position is uncomfortable."
  },
  {
   "type": "table",
   "head": [
    "Evidence type",
    "Reliability",
    "Available for access controls today?"
   ],
   "rows": [
    [
     "Auditor re-performance",
     "Highest",
     "<strong style=\"font-weight:600\">No</strong>"
    ],
    [
     "Evidence from an independent external source",
     "High",
     "No"
    ],
    [
     "Entity-generated, auditor-verified",
     "Moderate",
     "Rarely — requires system access"
    ],
    [
     "Entity-generated, inspected",
     "Lower",
     "<strong style=\"font-weight:600\">Yes — this is the norm</strong>"
    ]
   ]
  },
  {
   "type": "p",
   "html": "Access control testing sits almost entirely in the bottom row, and it sits there because nothing better has existed."
  },
  {
   "type": "h2",
   "text": "What a screenshot actually is"
  },
  {
   "type": "p",
   "html": "An image, produced by an administrator of the system being tested, of a screen that administrator can modify, at a time of their choosing, showing what they chose to include."
  },
  {
   "type": "p",
   "html": "Nothing about that is an accusation. The overwhelming majority of screenshots are accurate and produced in good faith. The point is that the evidence type cannot distinguish the good-faith case from the other one, which is the definition of weak evidence."
  },
  {
   "type": "h2",
   "text": "Why direct auditor access is not the answer"
  },
  {
   "type": "p",
   "html": "The obvious alternative — give the auditor read access to production systems — fails for reasons both parties recognise. It creates access that must itself be governed, expands the audit firm's exposure, raises data protection questions, and produces its own provisioning and deprovisioning problem at every engagement."
  },
  {
   "type": "p",
   "html": "It is also not re-performance. An auditor reading the same database the client reads is still relying on the client's system."
  },
  {
   "type": "h2",
   "text": "The objective-to-receipt mapping"
  },
  {
   "type": "p",
   "html": "Not every ITGC objective can be expressed as a signed receipt. Mapping which can is the practical work, and it is short enough to do in a workshop."
  },
  {
   "type": "table",
   "head": [
    "ITGC objective",
    "Receipt type",
    "Re-performable?"
   ],
   "rows": [
    [
     "Access is granted only with appropriate approval",
     "Access grant receipt: requester, approver, scope",
     "Yes"
    ],
    [
     "Access is removed on termination",
     "Revocation receipt referencing the issuance",
     "Yes"
    ],
    [
     "Periodic review of access occurs",
     "Certification receipt with rendered content",
     "Yes"
    ],
    [
     "Privileged access is restricted and monitored",
     "Elevation approval receipt with scope",
     "Partially"
    ],
    [
     "Changes are authorised before migration",
     "Change approval receipt bound to the artefact",
     "Yes"
    ],
    [
     "Segregation of duties is enforced",
     "Conflict and exception receipts",
     "Partially"
    ]
   ]
  },
  {
   "type": "p",
   "html": "The partial rows are honest. Monitoring and enforcement are ongoing states rather than discrete acts, and a receipt evidences an act. Overclaiming here would undermine the rows that work."
  },
  {
   "type": "h2",
   "text": "What re-performance looks like"
  },
  {
   "type": "p",
   "html": "The auditor receives a set of receipts. They run an open-source verifier, obtain the entity's published verification key from the entity's own published location, and check the signatures themselves."
  },
  {
   "type": "p",
   "html": "They then read the rendered content directly from the receipt — the approver, the scope, the entitlements shown, the timestamps — without asking the client to produce a view of it."
  },
  {
   "type": "p",
   "html": "That is evidence the auditor obtained and verified themselves. Whether a given firm characterises it as re-performance or as verified entity-generated evidence is a professional judgement for them, and it is a step up either way."
  },
  {
   "type": "h2",
   "text": "Running the pilot"
  },
  {
   "type": "ol",
   "items": [
    "Pick three control objectives from the mapping's <em>yes</em> rows.",
    "Instrument them for one quarter alongside your existing evidence process. Do not switch off what you have.",
    "At the next control walkthrough, provide both evidence packages and ask your audit team which they would rather test.",
    "Ask specifically whether the receipts change their sample size or their testing approach. That answer determines whether this saves you money."
   ]
  },
  {
   "type": "p",
   "html": "Step four is the commercial test. If the audit effort does not change, the benefit is confined to internal assurance — real, but a different business case."
  },
  {
   "type": "h2",
   "text": "The professional standards question"
  },
  {
   "type": "p",
   "html": "Audit firms will need to satisfy themselves that this evidence form is appropriate and sufficient under their methodology, and that is their call rather than the client's."
  },
  {
   "type": "p",
   "html": "No article can pre-empt that determination, and a vendor claiming a receipt is automatically acceptable audit evidence is overstating. What can be said is that the evidence is verifiable independently, which is the property the standards value."
  },
  {
   "type": "h2",
   "text": "What the auditor re-performs"
  },
  {
   "type": "p",
   "html": "Not the decision — nobody can re-execute a human judgement. What becomes re-performable is the verification: that this signature is valid, from this credential, over this exact object, with user verification present. That is the part the control's integrity rests on."
  },
  {
   "type": "table",
   "caption": "Screenshot versus receipt, by audit property",
   "head": [
    "Property",
    "Screenshot",
    "Receipt"
   ],
   "rows": [
    [
     "Integrity",
     "None",
     "Verifiable"
    ],
    [
     "Attribution",
     "An account name",
     "A credential"
    ],
    [
     "Binding to the object",
     "A reference",
     "A digest"
    ],
    [
     "Population testing",
     "Sample only",
     "<strong style=\"font-weight:600\">Whole population</strong>"
    ],
    [
     "Independence from the entity",
     "None",
     "<strong style=\"font-weight:600\">Complete</strong>"
    ]
   ]
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Our auditor accepts screenshots.”</strong> Many do, because nothing better has been offered. That is a statement about supply, and it changes the moment a peer supplies something stronger."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Re-performance is an auditor's problem.”</strong> It is your problem at the point where the sample produces a finding you cannot rebut. Evidence designed to be tested is evidence you can stand behind."
  }
 ],
 "faq": [
  {
   "q": "Will our auditor accept this?",
   "a": "That is their professional judgement under their methodology. The evidence is independently verifiable, which is the property the standards value, but acceptance is theirs to determine."
  },
  {
   "q": "Does this replace our existing evidence process?",
   "a": "Not initially. Run both for a quarter, then let the comparison drive the decision."
  },
  {
   "q": "What about controls that cannot be expressed as receipts?",
   "a": "Keep the existing evidence for those. The mapping is explicit about which objectives are partial, and overclaiming would undermine the rest."
  },
  {
   "q": "Does the auditor need access to our systems?",
   "a": "No. That is the point. Verification uses published keys and open-source tooling."
  },
  {
   "q": "Can an auditor re-perform a human decision?",
   "a": "No. What becomes re-performable is the verification — that this signature is valid, from this credential, over this object."
  },
  {
   "q": "Why does this eliminate sampling?",
   "a": "Because mechanical verification scales. Testing 500 approvals takes seconds, so the auditor tests the population and examines exceptions."
  },
  {
   "q": "Why hand over a tool rather than a dashboard?",
   "a": "A dashboard reports your computation. A tool lets the auditor compute it themselves, which is what independence means."
  }
 ],
 "sources": [
  {
   "t": "PCAOB AS 2201 — An Audit of Internal Control Over Financial Reporting",
   "u": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS2201"
  },
  {
   "t": "PCAOB AS 1105 — Audit Evidence",
   "u": "https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105"
  },
  {
   "t": "ISACA — COBIT framework",
   "u": "https://www.isaca.org/resources/cobit"
  },
  {
   "t": "Published guidance on electronic audit evidence and its evaluation."
  },
  {
   "t": "AICPA — standards and statements",
   "u": "https://www.aicpa-cima.com/resources/landing/standards-and-statements"
  },
  {
   "t": "NIST SP 800-53 Rev. 5 — access enforcement",
   "u": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final"
  }
 ],
 "related": [
  {
   "slug": "certification-evidence-standard",
   "title": "The rubber stamp is the product",
   "category": "Developer"
  },
  {
   "slug": "sod-exception-evidence",
   "title": "Segregation of duties exceptions",
   "category": "Developer"
  },
  {
   "slug": "collection-attestation-receipt",
   "title": "Chain of custody for electronic evidence",
   "category": "Compliance"
  }
 ],
 "image": "https://cdn.twc.sh/images/igcache/Re%20Performable%20Evidence/1200_630/blog.jpg",
 "wordcount": 1003,
 "url": "/blog/re-performable-evidence.html",
 "reading_time": "4 min read",
 "seo_title": "Audit evidence your auditor can re-perform",
 "meta_description": "An auditor samples twenty access changes and receives twenty screenshots produced by the client's administrator.",
 "hub": {
  "slug": "topics/access-governance",
  "title": "Access governance and certification"
 },
 "answer": "That the auditor can execute the check themselves and get the same result. A screenshot cannot be re-performed; it can only be read. Re-performance is the strongest evidence class in audit methodology, and for human approvals it has historically been unavailable.",
 "answer_q": "What makes audit evidence re-performable?",
 "glossary": [
  {
   "term": "Re-performance",
   "def": "The auditor independently executing a control or its verification — the strongest evidence class."
  },
  {
   "term": "Inspection",
   "def": "Examining records, which is where approval evidence has historically sat."
  },
  {
   "term": "Population testing",
   "def": "Testing every instance rather than a sample, practical once verification is mechanical."
  }
 ],
 "checklist": {
  "title": "Producing re-performable evidence",
  "id": "evidence",
  "desc": "Four steps.",
  "steps": [
   {
    "name": "Generate evidence as part of the control.",
    "text": "Not as a reporting step afterwards."
   },
   {
    "name": "Bind it to the object.",
    "text": "Commit, payload, record — not a ticket reference."
   },
   {
    "name": "Publish the verification key and procedure.",
    "text": "So the auditor does not need your systems."
   },
   {
    "name": "Hand over the tool, not a dashboard.",
    "text": "A dashboard reports your computation; a tool lets them do their own."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav turns an access or elevation decision into an artefact: what the approver was shown, who they were, what authority they held, signed and verifiable without your systems.",
  "href": "../docs.html",
  "label": "See approval receipts"
 }
}