Evidence Packs for Safeguarding Audits: What Regulators and Auditors Expect

Evidence Packs: The New Standard of Proof

An evidence pack is a self-contained collection of compliance records that demonstrates, to a regulator or auditor, that a firm met its safeguarding obligations during a specific period. It is the difference between claiming compliance and proving it.

Under CASS, evidence packs support the auditor's reasonable assurance opinion on client money and asset compliance. Under PS25, they form the basis of the FCA's supervisory assessment. Under MiCA, they provide the documentary evidence that NCAs require when reviewing CASP authorisation and ongoing compliance.

The shift toward evidence-based compliance, where regulators demand proof rather than accepting assertions, means that the quality of your evidence packs directly impacts your regulatory standing. Incomplete, inconsistent, or manually assembled evidence undermines confidence in the firm's compliance programme, regardless of whether the underlying compliance was adequate.

What Goes Into a Compliant Evidence Pack

A compliant evidence pack typically contains: reconciliation results for each cycle during the period, including matched items, unmatched items, and variance analysis; breach event records, including detection timestamps, notification evidence, investigation notes, and resolution records; coverage ratio history showing the relationship between safeguarded assets and client liabilities over time; governance records including review sign-offs, exception approvals, and escalation decisions; and policy attestations confirming that the firm's safeguarding procedures were followed.

Each element must be internally consistent, the reconciliation results must align with the breach records, which must align with the governance sign-offs. Inconsistencies between these elements are the most common finding in audit engagements and regulatory reviews.

The evidence must also be verifiable: timestamps must be credible, user attributions must be authentic, and the records must be demonstrably unaltered since creation. This is where cryptographic integrity, such as SHA-256 hashing, provides an additional layer of assurance.

Cryptographic Integrity: Why SHA-256 Matters

SHA-256 signing provides a mathematical guarantee that a document has not been altered since its creation. Each evidence record is hashed using the SHA-256 algorithm, producing a unique fingerprint. Any modification to the record, even a single character, would produce a completely different hash, making tampering immediately detectable.

For regulators and auditors, cryptographic integrity eliminates a category of doubt: they do not need to rely on trust alone when assessing whether evidence records are authentic. The hash provides independent verification.

This is particularly important for evidence packs that may be reviewed months or years after creation. Without cryptographic integrity, there is always a question of whether records were modified between creation and review. With SHA-256 signing, that question is answered definitively.

Common Failures in Evidence Pack Production

The most common failure is assembly delay: evidence is compiled after the fact, under time pressure, from disparate sources. This reactive assembly introduces errors, gaps, and inconsistencies that undermine the evidence's credibility.

Other common failures include: missing user attribution (the reconciliation was done, but there is no record of who reviewed or approved it); incomplete breach records (the breach was detected, but the investigation and resolution timeline is fragmentary); inconsistent data (the reconciliation results do not match the figures reported in the regulatory return); and expired retention (records from early in the review period have been deleted or lost).

Each of these failures is avoidable with the right infrastructure. When evidence is generated continuously as a by-product of compliance operations, rather than assembled retrospectively, these failure modes are eliminated structurally.

How Safeheld Generates Evidence Packs Continuously

Safeheld generates evidence packs continuously as a by-product of every reconciliation cycle, breach event, and governance action. Each evidence record is SHA-256 signed at creation, with full user attribution and chronological integrity.

Evidence packs can be assembled for any period, a single day, a quarter, a full year, drawing from the same continuous evidence base. The compliance team does not need to assemble evidence manually; they select the period and the applicable framework, and the platform generates a complete, internally consistent pack ready for auditor or regulatory review.

This transforms evidence production from a reactive project into an automatic process, eliminating the assembly delays, gaps, and inconsistencies that undermine most firms' evidence quality.