Skip to content

ISO 27001 and SOC 2 audits: what to mask in the evidence you hand over

Auditors work from samples of tickets, access lists and screenshots. Here is what to mask, what to keep visible, and how to agree it before the audit starts.

By Alexis de ONYRI

Mask what does not prove the control, and keep what does. An auditor needs to see that an access review happened, who approved it and when. They rarely need the salary, the home address or the password that sits next to it. Agree the approach with your auditor before the audit starts.

Take Jane Example, who runs security at a small software company. Her auditor asks for ten leaver tickets, the latest access review and a screenshot of the firewall settings. Each file will leave her company. This guide is general information as of October 2026, not legal advice.

What do auditors sample, and where does your evidence go?

An audit does not read every record. It checks a sample. In Germany, the federal office BSI publishes an audit scheme for ISO 27001 certification based on IT-Grundschutz. It says a certification audit checks requirements on a sample of topic modules. The audit team lead picks them by risk and justifies the choice. ISO 19011, the guideline for auditing management systems, also covers sampling, according to ISO and the IAF.

Four black ring binders stacked on a white desk, each with a coloured index tab, beside an open file full of papers
Auditors flag a sample from the evidence, so any file you hand over may be opened and read.Photo: Jakub Zerdzicki, Pexels

Evidence then moves. Depending on your set-up, it may travel by email, through the audit firm's portal or through your compliance platform. In the BSI scheme, the finished audit report reaches the certification body in encrypted form. How long a firm keeps its working papers is not stated in the sources we checked, so ask in the engagement letter.

Do ISO 27001 and SOC 2 ask you to mask data?

ISO/IEC 27002:2022 lists data masking as control 8.11. ISACA's guide to the 2022 update says it limits the exposure of sensitive data. It quotes the wording: masking should follow your access control policy and business needs, taking applicable legislation into consideration. That wording does not mention audit evidence, but the logic is the same.

SOC 2 reports use the AICPA's Trust Services Criteria. A report covers one or more of five categories: security, availability, processing integrity, confidentiality and privacy. If it includes confidentiality, criterion C1.1 asks the organization to identify and maintain confidential information. If it includes privacy, criterion P4.1 limits the use of personal information to the purposes the organization has identified. Masking your evidence follows the same logic.

Data protection law points the same way. EU: Article 5(1)(c) GDPR requires personal data to be adequate, relevant and limited to what is necessary for the purpose. UK: the ICO states the same test, and its page is under review as of October 2026. Masking reduces exposure. It does not make you compliant by itself.

What should stay visible, and what should you mask?

Use this table as a starting point. Your auditor decides what proves each control.

EvidenceKeep visible (it proves the control)Mask (it does not)
Access review listSystem name, review date, reviewer role, keep or remove decision, user IDPersonal emails, phone numbers, full names if the auditor accepts IDs
Joiner or leaver ticketTicket number, request, approval and access removal dates, approver roleHome address, birth date, reason for leaving, salary
Training recordCourse name, completion date, employee IDPersonal email, test answers, notes about the person
Background check confirmationDate, check completed, result as yes or noReport details, ID numbers, addresses, any criminal record detail
Incident or change ticketNumber, timestamps, severity, approver role, fixCustomer names, emails, phones and IP addresses pasted in the description
Log extract or configuration screenshotThe setting, rule name, date and time, the system shownAPI keys, tokens, passwords, customer data, personal email in the account menu
Supplier contractParties, signature date, term, security and confidentiality clausesPrices if not needed, personal details of signatories, unrelated personal data

How do you handle screenshots, secrets and population lists?

  • Secrets: API keys, tokens, passwords and private keys must never appear in a screenshot or export. If one was visible in a file you already shared, change it.
  • Customer data: tickets, logs and exports often hold customer names, emails and IP addresses. The auditor rarely needs them.
  • Screenshot edges: check the browser tabs, the address bar, the account menu and open notifications. Personal emails hide there.
  • File names: a file named after a person still names that person. Rename it.

Auditors pick samples from a population list, such as all employees or all admin accounts. Send only the columns needed to choose and trace a sample: an ID, a date, a role, a status. In Excel, delete the other columns instead of hiding them. Microsoft's documentation says Document Inspector finds hidden rows, columns and sheets, and document properties such as the author name.

ONYRI Sanitize masks a copy of a PDF, Word (.docx) or image file inside your browser, without uploading it. On every plan it finds emails, names, IPv4 addresses and ID numbers. On Pro it adds API keys, cloud tokens and SSH private keys. On-device OCR reads image files and scanned pages, not screenshots inside a page with text. “Draw an area” covers any region. It cannot judge what your auditor needs, and its export is not searchable text.

How do you agree the approach with your auditor?

  1. Ask, before the audit starts, which evidence will contain personal data and what the auditor must see in each file.
  2. Write the rule on one page and send it. A short email thread can serve as the record.
  3. Mask copies, review the preview and keep the originals untouched, with the same ticket numbers, so the auditor can compare.
  4. Offer to show the original on screen for sensitive samples. The BSI scheme itself says some documents can only be viewed on site for confidentiality reasons.
  5. Note what you handed over, when and how. Ask what the firm does with the files after the audit.

How you send the files matters too. France: the CNIL's security guide says to encrypt sensitive files and use a protocol such as SFTP or HTTPS. It also says to plan the deletion of files left on a transfer platform. It warns against sending unencrypted personal data through consumer messaging.

Start small. Pick one type of evidence, mask a copy and ask your auditor to confirm it works before you do the rest. The first sample that passes becomes your template.

Frequently asked questions

Can I redact evidence for an ISO 27001 or SOC 2 audit?

Yes, if the evidence still proves the control. Agree the approach with your auditor first and keep the originals. The auditor decides what evidence is enough, not you.

Should I mask employee names in an access review?

It depends on what the auditor must match. If a user ID is enough, mask the names. If names must be matched against an HR list, show the original on screen instead of uploading it. Ask first.

How long does the audit firm keep my evidence?

The standards and guidance we checked give no single figure. It depends on the firm's policy, professional rules and national law. Ask in the engagement letter, and ask what happens to your files when the audit ends.

If I mask a key in a screenshot, is it safe?

The copy is safer, but the key is not. If the original showed a key and was shared or stored widely, change the key. Masking protects a file. Only changing the key protects the secret.

Sources & references

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.