Audit Evidence in IGA is the verifiable record showing that identity controls were designed and operated as intended. Examples include access requests, approvals, policy evaluations, provisioning results, review decisions, revocation confirmations, exceptions and timestamps.
Evidence should be complete, attributable, tamper-resistant, retained for the required period and reproducible without relying on screenshots or individual memory.