← All posts
SharePoint audit evidence5 min read

Managing SharePoint audit evidence the right way

By The Substantively team · Internal audit

If your organization already runs on Microsoft 365, SharePoint is the natural home for audit evidence: it inherits your tenant's permissions, retention labels, DLP policies, and eDiscovery. The question is how to manage that evidence from your audit tool without copying it somewhere less governed.

Link by reference, don't re-host

The right pattern is to keep evidence in SharePoint and link to it by reference — a URL and file identifiers — so opening a workpaper launches it in your own tenant under the signed-in user's permissions. The audit tool stores the link and the metadata, never a second copy of the bytes.

Folders and templates that live in your tenant

  • A folder per engagement, created in your SharePoint on kickoff.
  • Workpaper templates copied into that folder, ready to fill.
  • Uploads that travel browser-to-SharePoint via Graph — never through a vendor server.

Why this matters for your control environment

When evidence stays in SharePoint, your existing governance applies automatically: access reviews, retention, legal hold, and audit logging you already trust. Pulling evidence into a third-party store recreates all of that — badly — and adds a new custodian to your risk assessment.

Substantively is built on exactly this model: file content never touches our servers, and our CI fails any change that tries. Read the data-boundary story or start a trial.