Skip to content

Handing your auditor the evidence

What to give your certification body, three ways to hand it over, and why your auditor never needs an account in your tenant.

Audience: ISMS Admin, before a Stage 1 or Stage 2 audit.

Where: the Certaria app for the documents; SharePoint only if you hand them over by link.

What this is: how to give your certification body what it needs. Your auditor does not need an account in your tenant or a Certaria licence, and nothing in this guide asks you to create one.

What your auditor is looking at, and as of when

Section titled “What your auditor is looking at, and as of when”

Every document an auditor receives raises the same first question: what is this, and what date does it describe? The two documents Certaria produces answer it on their face.

DocumentWhat it isHow it is dated
Statement of ApplicabilityEvery Annex A control, grouped by theme, with your applicability decision and justification against each”Generated” and the date, printed on the document, and in the file name: statement-of-applicability-2026-10-14-0930.pdf
Compliance summaryOne page: certification status, control implementation, last internal audit, last management review, last readiness scanThe production date on the document, and in the file name: compliance-summary-2026-10-14-0931.pdf

The Statement of Applicability also carries a decision trail. The date each control’s applicability was first decided is stamped once and never moves, which answers the auditor’s “when did you decide this?”. See the decision trail.

Tell your auditor the date the documents describe when you hand them over. A document produced the morning of the audit and one produced last quarter are different evidence.

  1. Produce both documents again. Downloading or emailing sends the copy you last produced, not the current state of your ISMS. Produce first, then hand over.
  2. Check that every excluded control has a justification. It is the first thing an auditor challenges.
  3. Keep the file names as they are. The date in the name is part of the record.
  4. Keep a copy of exactly what you handed over in the Audit Pack container on your ISMS site, which only administrators can see, in a folder named by the date. When someone later asks “which version did the auditor see?”, that folder is the answer.

Certification bodies receive documents through their own systems and look at your live systems over a screen share, with you navigating. Accredited bodies conduct remote audit activity under IAF Mandatory Document 4.

Giving an external party an account in your tenant, even a guest account with narrow rights, is access you would then have to justify and review under A.5.15 (access control) and A.5.19 (information security in supplier relationships). The three routes below avoid it.

The simplest route, and the one to use if your certification body has a document portal.

  1. Produce the Statement of Applicability and the compliance summary in Certaria, then download both.
  2. Add anything else the auditor asked for. The compliance summary guide lists what typically belongs in an audit pack.
  3. If they want a single file, zip the folder and name the zip with the date, for example audit-handover-2026-10-14.zip.
  4. Upload it to the certification body’s portal, or send it the way they ask.
Section titled “Route 2: a time-limited link from a separate export site”

For an auditor who asks for a link rather than a file.

Never share from your ISMS site. Keep its external sharing off, as the installation guide sets it. Microsoft’s own advice is to keep confidential content on sites with external sharing turned off, and to create separate sites for sharing. So you create one site for handing files out, turn external sharing on for that site alone, and put copies of the dated files there.

This needs a SharePoint Administrator.

  1. Create a new SharePoint communication site, for example Audit Exports, and give only your ISMS administrators access to it.
  2. In the SharePoint admin centre, open Active sites, select the new site, and on the Settings tab select More sharing settings.
  3. Choose the external sharing level (see the next section). Where the option is offered, set guest access expiry for this site, so that any guest access ends on its own. Select Save.
  4. In the same place, confirm that your ISMS site is still set to Only people in your organization.

A site cannot be more open than your organisation-level sharing setting. If the option you need is not available, that setting (under Policies, then Sharing) is more restrictive, and changing it is your organisation’s decision, not Certaria’s.

Not every sharing link is file transfer, and the difference matters here.

LinkDoes the auditor sign in?Does it add anyone to your directory?Use it when
Anyone link, view only, with an expiry dateNoNoYour sharing policy allows Anyone links. Anyone holding the link can open the files until it expires, and opening them is not recorded against a named person
Specific people linkYes, with a code sent to their email address or with their own work accountIt depends on your tenant. If SharePoint’s integration with Microsoft Entra B2B is turned on, a guest account is always createdYour policy does not allow Anyone links, or you need to know who opened the files

A guest account created this way is standing access of exactly the kind this guide avoids. If one is created, remove it when the audit ends (see After the audit), and let the site’s guest access expiry act as the backstop.

  1. Upload the dated files into a folder on the export site named by the date.
  2. Share the folder as view only, with an expiry date just after the audit window, for example two weeks.
  3. Send the link to your auditor, together with the date the documents describe.

Stage 2 tests whether your controls work in practice. The auditor watches while you navigate.

  • Share one window, not your whole screen, and close anything unrelated first. Agree in advance whether the session is recorded.
  • Start from the Statement of Applicability. The auditor will choose controls from it. Have the exported copy open, so you are both looking at the same dated version.
  • For a control Certaria evidences automatically, open it in Certaria to show the evidence recorded against it and the date that evidence was captured.
  • When the auditor asks to see the configuration itself, open it where it lives: the Microsoft Entra admin centre for Conditional Access, Intune for device compliance, Microsoft Purview for sensitivity labels. Certaria records what it found and when; the admin centre shows the configuration as it stands now.
  • For a control met by a document, show the published document and its acknowledgement record.
  1. Stop sharing. Let the link expire, or remove sharing from the export folder straight away.
  2. Remove any guest account the audit created, in the Microsoft 365 admin centre under Users, then Guest users.
  3. Remove the copies from the export site. The originals stay in Certaria, and your record of what was handed over stays in the Audit Pack.
  4. Record the corrective action for each finding as a task with an owner, so your surveillance audit can see what happened to each one.
SymptomCauseFix
The auditor has an older version than you expectedDownloading and emailing send the copy last producedProduce again, then hand over
The time in the file name is an hour outFile names are stamped in UTCExpected during British Summer Time. Quote the date printed on the document
The Anyone option is missing when you shareYour organisation-level or site-level setting does not allow Anyone linksUse a Specific people link, or ask your SharePoint Administrator
A guest account appeared after you sharedYour tenant uses SharePoint’s integration with Microsoft Entra B2B, so Specific people links create guestsRemove the guest when the audit closes, and set guest access expiry on the export site
Nobody can say which version the auditor reviewedNothing recorded what was handed overKeep a dated handover folder in the Audit Pack every time