The Audit Evidence Layer: Where SOC 2, ISO 27001 and PCI DSS Meet the Physical Record
SOC 2, ISO 27001 and PCI DSS sit differently from the rest of a facility's obligations, and a facility's inspection evidence does not satisfy them. It is one input among many that an assessor may choose to look at.
These are not fire codes or electrical standards. They are assurance frameworks that a customer or a market asks an operator to hold, and they take an interest in the physical environment alongside a great deal else.
What are the three frameworks?
SOC 2 is a reporting framework on the controls a service organisation says it operates.
ISO 27001 is an international standard for an information security management system.
PCI DSS sets out the card industry's data security requirements.
Each has its own owners, documents and assessors, and the detail belongs to the people qualified to apply them.
Why does a physical record matter here?
The environment is part of what an operator is asserting. That includes access to spaces, the condition of the infrastructure those systems depend on, and whether the operator can show what was checked rather than state that it was.
Assurance work rests on evidence produced as a matter of routine rather than assembled for the occasion. Physical inspection evidence is a small part of that picture, one input among many.
Whether any particular evidence is relevant is the assessor's determination, not ours.
What makes routine evidence credible?
It exists before anyone asks for it. A record assembled the week before a review tends to look like one, while a record that has simply been accumulating reads differently. Each item carries when, where and what was observed.
The same points are revisited, so there is a series rather than a snapshot. Findings link to what was done, and the next pass shows whether the condition changed.
It is retrievable a year later by someone who was not there. None of that is unique to these frameworks. It is simply what a record has to be to survive being examined.
Where does FacilityOps fit?
A FacilityOps robot walks the route and captures condition at the same checkpoints on every pass, with thermal, visual and environmental readings from the FacilityOps sensor hub. Each capture is bound to its run and checkpoint, and exceptions are raised to a qualified person who makes the call.
The record builds itself as a by product of the work rather than being compiled ahead of a review. What an assessor concludes from it remains theirs to decide.
One FacilityOps robot route produces the records across all nine compliance surfaces.
If you want to see what routine physical evidence looks like in practice, we can send you a sample inspection record.
Everything in this piece, as a checklist you can take on your rounds
Turn the key points from this article into a practical inspection checklist.