Audit evidence
The records that demonstrate a control was actually operating, not merely defined.
Auditors do not accept assertions. They want the access review with dates and approvals, the patch report, the training completion records, the ticket showing the incident was handled.
Collecting evidence continuously is far cheaper than reconstructing a year of it in the fortnight before an audit, and it produces a more credible result.
Where this comes up
Audit evidence sits inside our compliance and frameworks work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.