> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Producing Evidence for an Audit

> Assemble the record an auditor demands out of versions, reasons and decisions.

We assemble, from the history of a controlled document, the record an audit
demands: which version applies, what changed against the previous one, and that
a rejected attempt stays visible.

## Starting point

The *Access Control Policy* from
[Approving a Document](/docs/en/documents/tutorial-approval) has been in force for a
year. At the annual review the IT Security Officer shortened the review cadence
from quarterly to monthly. A first draft was rejected for a missing transition
rule and revised. The auditor wants to trace how the valid version 2.0 came
about.

## 1. Find the valid version

Tab *History*, *Versions*: 1.0 with status *Superseded*, 2.0 with status
*Valid*. Tab *Overview* shows the same state under *Valid Version*; the history
additionally shows the previous versions.

<Note>
  *Superseded* concerns the version, not the document. Approver and approval date
  of 1.0 stay intact.
</Note>

## 2. Compare the versions

<Steps>
  <Step title="Open version 2.0">
    A click on the row opens the sidebar with *Created On*, *Approved On*,
    *Change Reason* and the properties as of the time of approval.
  </Step>

  <Step title="Choose the comparison">
    The selection at the top of the sidebar puts 2.0 against version 1.0.
  </Step>

  <Step title="Read the properties">
    The table shows *Review interval* in both versions: twelve months against
    one month.
  </Step>

  <Step title="Read the chapters">
    The new chapter *Transition Rule* is marked. The content can be shown side
    by side or one below the other.
  </Step>
</Steps>

The comparison shows what changed. The *Change Reason* of version 2.0 shows why.

## 3. Show the rejected attempt

The version list contains only approved versions. The approval history contains
every request:

| Version | Status | Requested by | Decided by |
| - | - | - | - |
| 2.0 (first request) | *Rejected* | IT Security Officer | IT Manager |
| 2.0 | *Approved* | IT Security Officer | IT Manager |

A click on the rejected row opens the sidebar with the requester's *Comment*
and the IT Manager's *Rejection Reason*: "Transition rule for ongoing review
cycles is missing."

<Note>
  For an auditor, the rejected request is part of the evidence: it shows that the
  approval process was reviewed, not only confirmed.
</Note>

## 4. Output the version as a PDF

*Download* stands next to version 2.0 as soon as the export is finished. The
PDF contains the version as it stood at the time of approval.

<Note>
  The export runs in the background. If *Download* is missing, it has not
  finished yet.
</Note>

## Result

Three sources form the evidence: *Overview* for the current state, *Versions*
for the sequence of versions, the approval history for the requests and
decisions.

## Next steps

The ongoing approval:
[Document Control and Approval](/docs/en/documents/document-control).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.