Control evidence that survives a Malaysian reporting cycle
Screenshots of a settings page rarely help. The evidence that holds up is tied to a named run, a named user, and a named freeze date.
Internal audit files we inherit are often full of policy excerpts and a screenshot of a “maker-checker enabled” toggle. That material shows intent. It does not show that the control operated on the Thursday the return was released.
For a Malaysian statutory or regulatory cycle, useful evidence usually looks like this: the change ticket that promoted a report definition, the access listing as at the freeze, the job log for the extract, the hash or control total of the file the platform consumed, the approval record for any overlay, and the lock timestamp on the released pack. If any of those artefacts rotate out of the system after thirty days, the engagement letter should say so before fieldwork starts, because we cannot test what the platform has already discarded.
PDPA and vendor retention rules sometimes limit how long logs are kept. That is a practical constraint, not a reason to skip the test. We document the retention gap and test what remains. Pretending a missing log was “not applicable” is how findings reappear in the next external audit.
If you are preparing for us, or for another firm, export the run artefacts while the cycle is still open. Waiting until the auditor arrives is how evidence disappears.