For internal audit, investigators and assurance

A supplier’s report about a supplier’s own log is the weakest evidence there is.

Everybody senior knows it, which is why the useful question is not what a supplier records but where the record lands. Events arrive in a store your organisation controls, on your retention schedule, examinable without asking us — so a reconstruction does not wait on our cooperation or our goodwill.

You will be asked to prove something about a supplier, using the supplier’s own account of it

An investigation into a past event has a familiar and uncomfortable shape. The evidence lives with the party being examined, it is produced on their timeline, in their format, at whatever completeness they choose, and the person receiving it is expected to treat it as fact. Nobody in the chain is comfortable with this and it is nonetheless the normal arrangement.

Retention is where the reconstruction usually dies. Investigations begin months after the event because that is when a complaint or a discrepancy surfaces, and a trail retained for a shorter period than the discovery lag is a trail that answers nothing. The retention decision is made by an engineer weighing storage cost long before anybody imagined this investigation.

Then there is the difference between logging and an audit record, which is enormous and is rarely drawn. Operational logs are written for engineers to debug, they are sampled when volume grows, their format changes when somebody refactors, and they are frequently mutable. An audit record is written to be read years later by somebody hostile, and it has to be complete, stable, attributable and impossible to quietly amend.

Correlation is the other half of the difficulty. A single business event crosses several systems, each with its own identifiers, its own clock and its own idea of what a session is. Reconstructing one customer’s afternoon means joining across all of them, and the join usually fails on a timestamp precision or an identifier that was regenerated halfway through.

And attribution is where an investigation stops being technical. Knowing that a record changed is easy. Knowing which named person changed it, under whose authority, and what it said before, is the part that determines whether an investigation reaches a conclusion or a shrug.

Where the record lands decides whether it is evidence

A trail retained only inside the supplier can be produced late, incompletely, in a chosen format, or not at all — so the property that makes it evidence is not what is recorded but whether a copy lands somewhere the customer controls.

Every audit-relevant event is delivered to a destination you nominate, as it happens, in addition to being retained here. That is the whole structural argument: once a copy is in an append-only store your organisation controls, an investigation is something your team performs rather than something your team requests, and the retention period is your decision rather than an engineering trade somebody else made.

The distinction between operational logging and an audit record is drawn deliberately. Audit records are never sampled, their shape is versioned and additive so a query written this year still runs against last year, and they are written once. Operational logs remain what they are — useful for debugging, unsuitable as evidence — and nothing here pretends the two are one thing.

Each record carries what an investigation actually needs: the named person or the automated step, the grant it acted under, the record affected, what the value was before and after, the time on a synchronised clock, and a correlation identifier that survives across every component the event touched. That correlation identifier is what makes a reconstruction a query rather than a project.

Immutability is bounded honestly. Records here are append-only and a correction is a new record referencing the earlier one rather than an edit — so the history of what was believed at each point survives, which is usually the thing an investigation is actually chasing. What this does not claim is cryptographic proof against an operator of the underlying storage; where your evidential standard requires that, the answer is the copy in your own store under your own controls, and that is a real answer rather than a deflection.

Retention here is on a stated schedule and it is deliberately not the important number, because the copy in your store is retained on yours. A supplier’s retention period should never be the binding constraint on your ability to investigate your own operation, and the arrangement here is designed so it is not.

What an investigator should be able to do without asking us

Whether a reconstruction needs our cooperation — measured by performing one entirely against your own copy, with our involvement removed deliberately.

How far back a reconstruction can reach — measured by your own retention schedule rather than a period we chose.

Whether the actor is identifiable — measured by picking any record and finding the named person or automated step and the grant it acted under.

Whether prior values survive — measured by finding what a field said before a change, not only that it changed.

Whether one event can be followed across components — measured by querying a correlation identifier and receiving the full path rather than fragments.

Whether a query written today runs on last year’s records — measured by running a current query against the oldest records you hold.

no cryptographic proof against an operator of the underlying storage is claimed for records retained here; where that evidential standard is required, the answer is your own copy under your own controls. No claim that operational logs are evidence — they are sampled and unsuitable, and the two are kept distinct on purpose. No independent audit of these arrangements has been performed. An independent SOC 2 Type II attestation is in progress and no report exists yet.

Into your store, on your terms

The destination is yours: your append-only object storage, your log platform, your evidence store. Delivery is continuous rather than a nightly export, because a nightly export has a window in which an event can be produced and never delivered, and that window is exactly what an examiner asks about.

Your own controls then apply to the copy — your write-once policy, your retention lock, your access restrictions, your separation of duties. That is what allows an evidential standard your organisation already operates to cover this supplier without us having to satisfy it independently, which is both faster and stronger.

And your existing correlation conventions can be carried through, so the identifier arriving here is one that already means something across your estate rather than a foreign identifier your investigators would have to map.

The limit of immutability, stated rather than implied

Records here are append-only and a correction is a new record rather than an edit, which preserves the history of what was believed at each point. That is a real property and it is not the same as cryptographic proof against an operator of the underlying storage, and a supplier implying that append-only means tamper-proof has overstated it.

So where your evidential standard genuinely requires proof against the operator, the honest answer is the copy in your own store, under your own write-once policy and your own retention lock. That is a stronger arrangement than anything we could offer about our own systems, and it is stronger precisely because it does not depend on us.

The separation between operational logs and audit records is maintained deliberately. Operational logs are sampled, reshaped by refactoring and unsuitable as evidence; presenting them as an audit trail is a common and misleading practice, and an investigator who receives one has received something that will fail on the day it is examined.

No independent audit of these arrangements exists. A SOC 2 Type II attestation is in progress and no report exists yet; it is an attestation with a defined scope and period rather than a certification.

Run a reconstruction with us deliberately removed

The decisive test is to perform a reconstruction against your own copy without contacting us at all. If it succeeds, this section of your assurance is answered structurally rather than contractually, and it stays answered even if the relationship deteriorates.

Check that prior values are present rather than only the fact of a change. An investigation that can establish a field changed but not what it previously said usually cannot reach a conclusion, and that gap is invisible until somebody needs it.

Set your own retention on your copy according to your discovery lag rather than to our schedule. Investigations start months late by their nature, and a retention period chosen against storage cost is the reason most reconstructions fail.

And confirm the separation between operational logs and audit records explicitly. A supplier offering sampled logs as an audit trail has offered something that will not survive being examined, and it is worth establishing which you are being given.

One reconstruction, performed without us

A trial in which audit records are delivered to your own store for a week, and your investigator reconstructs one multi-step event entirely from that copy without contacting us.

A week of real records and one reconstruction is a better assurance artefact than any document, because it exercises the exact capability that will be needed under pressure and it exercises it while nobody is under pressure.

Remove us from the exercise deliberately. The property being tested is independence, and an exercise in which somebody here helpfully answers a question has tested cooperation instead.

Then set the retention on your copy according to how late your investigations actually begin, which is almost certainly longer than any default.

Questions buyers actually ask

Every supplier says they have an audit trail.

They do, and the question that separates them is not what is recorded but where it lands. A trail retained only inside the supplier can be produced late, incompletely, in a chosen format, or not at all — and the person you eventually have to satisfy knows that. Records here are delivered continuously into a store your organisation controls, so an investigation is something your team performs rather than requests, and it keeps working if the relationship deteriorates. Test it by running a reconstruction with us deliberately removed.

Our investigations start months after the event.

They almost always do, which is why a supplier’s retention period should never be your binding constraint. The copy in your own store is retained on your schedule rather than on ours, so the number that matters is one you choose against your real discovery lag rather than one an engineer chose against storage cost years earlier. That is the single most common reason a reconstruction fails, and it is entirely avoidable by holding your own copy from the first week.

Is the trail actually immutable?

It is append-only, and a correction is a new record referencing the earlier one rather than an edit — so the history of what was believed at each point survives, which is usually what an investigation is chasing. What it is not is cryptographic proof against an operator of the underlying storage, and we will not imply otherwise. Where your evidential standard requires that, the answer is your own copy under your own write-once policy and retention lock, which is stronger than anything we could claim about our own systems precisely because it does not depend on us.

We were given sampled application logs last time and they were useless.

That is a common practice and it produces evidence that fails on the day it is examined — operational logs are sampled once volume grows, reshaped whenever somebody refactors, and frequently mutable. They are kept deliberately distinct from audit records here, and the list of which events produce which is available so you can check rather than assume. If a supplier cannot tell you which of their two kinds of record you are being offered, you are being offered the wrong one.

Can we follow one customer’s afternoon across everything that touched it?

Through a correlation identifier stamped at the request boundary and carried by every component involved, so the reconstruction is a query rather than a project. Your own convention can be carried through rather than replaced, which means the identifier arriving in your store already means something across the rest of your estate. That join is where most reconstructions fail — usually on clock precision or an identifier that was regenerated partway — so test it during the trial on a genuinely multi-step event rather than a single action.