15.3 Audit Evidence Collection & Well-Architected Security Reviews

Key Takeaways

  • AWS Audit Manager continuously and automatically collects compliance evidence from AWS CloudTrail, AWS Config, AWS Security Hub, and AWS API calls, mapping evidence against standard and custom regulatory frameworks.

  • Audit Manager evidence is retained for two years from creation, and assessment reports include a digest that lets auditors validate report integrity; the service is closed to new customers since April 30, 2026.

  • AWS Artifact is the central portal for on-demand access to AWS's own compliance documentation (SOC 1/2/3, ISO, FedRAMP) and legal contracts, including the Business Associate Addendum (BAA) for HIPAA.

  • The AWS Well-Architected Tool provides structured evaluations against the Security Pillar design principles, identifying High Risk Issues (HRIs) and Medium Risk Issues (MRIs) and producing milestone-tracked improvement plans.

  • In the AWS Shared Responsibility Model, AWS Artifact provides verification of security OF the cloud (AWS infrastructure), whereas AWS Audit Manager and AWS Config validate customer compliance IN the cloud (customer configurations).

Last updated: September 2026

15.3 Audit Evidence Collection & Well-Architected Security Reviews

Enterprise security teams operating in regulated industries—including banking, healthcare, government, and payment processing—face continuous audit scrutiny from internal governance bodies and external regulatory examiners. Demonstrating compliance requires proving that security policies, operational procedures, and technical guardrails are continuously operating as intended. Historically, preparing for compliance audits required labor-intensive, point-in-time evidence collection: taking hundreds of console screenshots, exporting log files, parsing spreadsheets, and interviewing engineering leads.

AWS provides three specialized services to eliminate manual audit friction and formalize architectural governance: AWS Audit Manager, AWS Artifact, and the AWS Well-Architected Tool. Understanding the distinct scope, evidence collection mechanics, and shared responsibility boundaries of each service is essential for cloud security architects and a core focus of the Specialty certification.


AWS Audit Manager Architecture & Automated Evidence Collection

Important

AWS Audit Manager is in maintenance mode: since April 30, 2026 it can't be set up in new accounts, while existing customers can keep using it. New programs typically combine AWS Config conformance packs, Security Hub CSPM standards, and CloudTrail for continuous evidence. The exam guide still lists Audit Manager, so know how it works.

AWS Audit Manager automates evidence gathering to assess whether cloud usage adheres to industry standards, legal regulations, and internal corporate controls. Audit Manager continuously monitors AWS accounts and automatically collects, organizes, and cryptographically timestamps audit evidence across distributed environments.

Audit Manager Evidence Pipeline:
┌──────────────────────────────────────────┐
│ Automated Data Sources:                  │
│ 1. AWS CloudTrail (API & User Activity)  │
│ 2. AWS Config (Resource Configurations)  │ ──> [Audit Manager Assessment] ──> [Auditor-Ready Report]
│ 3. AWS Security Hub (Security Findings)  │          │                               (PDF + Cryptographic
│ 4. AWS Checkers (Direct API Evaluations) │          ├── Standard / Custom Frameworks         Manifest)
└──────────────────────────────────────────┘          ├── Control Sets & Controls
                     ▲                                └── Manual Evidence Uploads
                     │
            [Organization Scope]

Core Audit Manager Concepts

  • Frameworks: Pre-packaged collections of control sets mapped to specific regulatory baselines or internal policies. Audit Manager provides pre-built Standard Frameworks (e.g., SOC 2 Type II, PCI DSS v4.0, HIPAA Security Rule, ISO/IEC 27001, FedRAMP Moderate, GDPR) and allows organizations to build Custom Frameworks by combining custom controls with standard controls.
  • Controls: Individual compliance requirements within a framework (e.g., "Enforce multi-factor authentication for administrative users" or "Ensure S3 buckets enforce encryption in transit").
  • Assessments: An active audit project created within Audit Manager. When an assessment is created, the user selects the target framework, defines the scope (specific AWS accounts in an AWS Organization), and specifies designated audit team members.
  • Evidence Folders: Structured containers where Audit Manager continuously deposits collected evidence, organized hierarchically by control set and control.

The Four Automated Evidence Sources

Audit Manager continuously harvests evidence from four distinct automated sources:

  1. AWS CloudTrail: Telemetry evidence capturing user activity, administrative actions, and API events. For example, CloudTrail evidence proves who accessed a resource, modified a security group, or executed a privileged role assumption.
  2. AWS Config: Resource configuration compliance states evaluated by AWS Config rules. Config evidence records whether a resource property matched the desired compliance definition at a given point in time.
  3. AWS Security Hub: Security posture checks and finding evaluations across enabled standards (e.g., AWS Foundational Security Best Practices, CIS Benchmarks). This evidence demonstrates overall control adherence across integrated services.
  4. AWS API Calls (Service Checkers): Direct service state checks executed natively by Audit Manager checkers. Checkers query service APIs directly without requiring Config rules (e.g., querying IAM password policy parameters or checking KMS key rotation status).

Manual Evidence Uploads

Not all audit requirements can be validated through automated cloud telemetry. Regulatory standards frequently require proof of administrative and human processes—such as employee security awareness training records, business continuity plan documents, third-party vendor penetration testing reports, or data retention policy sign-offs. Audit Manager supports Manual Evidence Uploads, allowing security leads to upload PDF, image, or text documents directly into specific controls alongside automated evidence.

Assessment Reports & Cryptographic Integrity

Once an assessment has collected sufficient evidence over an audit window (e.g., a 6-month or 12-month SOC 2 evaluation period), the security team generates an Assessment Report:

  • Audit Manager compiles selected evidence folders into an auditor-ready package consisting of an executive PDF summary and detailed evidence files.
  • The package includes a cryptographic manifest file containing SHA-256 hashes of all evidence items. This cryptographic hash proves to external auditors that evidence files have not been modified, tampered with, or altered since their automated capture.
  • Evidence can't be edited in Audit Manager and is retained for two years from creation; export reports you must keep longer.
Loading diagram...
Cloud Governance, Evidence Collection & Compliance Scope Matrix

AWS Artifact: Compliance Reports & Legal Agreements

While AWS Audit Manager collects evidence regarding the customer's cloud configurations, AWS Artifact is the dedicated self-service portal for accessing compliance documentation and legal agreements concerning AWS's own infrastructure.

Under the AWS Shared Responsibility Model, customers cannot physically audit AWS data centers or inspect physical host hypervisors. Instead, customers rely on independent third-party auditor attestations published by AWS in AWS Artifact.

AWS Artifact Portal:
├── AWS Artifact Reports (Third-Party Attestations OF the Cloud)
│   ├── SOC 1 (SSAE 18 / ISAE 3402) Type II Reports
│   ├── SOC 2 Type II Security, Availability & Confidentiality Reports
│   ├── SOC 3 General Use Public Reports
│   ├── ISO Certifications (ISO 27001, 27017, 27018, 9001, 22301)
│   ├── FedRAMP Package (SSP, SAP, SAR, and Authorization to Operate)
│   └── PCI DSS Attestation of Compliance (AOC) & Responsibility Matrix
│
└── AWS Artifact Agreements (Legal Contracts between Customer & AWS)
    ├── Business Associate Addendum (BAA) for HIPAA / HITECH Compliance
    ├── Non-Disclosure Agreements (NDA)
    └── Federal Financial Institutions Examination Council (FFIEC) Materials

AWS Artifact Reports

  • Service Organization Control (SOC) Reports:
    • SOC 1 Type II: Evaluates controls relevant to internal control over financial reporting.
    • SOC 2 Type II: Comprehensive technical audit evaluating AWS infrastructure security, availability, processing integrity, and confidentiality over a multi-month period.
    • SOC 3: Summary version of the SOC 2 report intended for general public distribution without requiring an NDA.
  • Payment Card Industry Data Security Standard (PCI DSS): Provides the Attestation of Compliance (AOC) and the PCI Responsibility Matrix, which outlines exactly which PCI DSS requirements are handled by AWS and which must be configured by the customer.
  • Confidentiality & Watermarking: Many reports in AWS Artifact are confidential proprietary documents. When an authorized IAM principal downloads a report, AWS automatically embeds a personalized, cryptographic watermark containing the downloader's account details and generates an NDA agreement acceptance record.

AWS Artifact Agreements & HIPAA BAA

Organizations handling regulated workloads must execute legal agreements with AWS before ingesting protected data:

  • Business Associate Addendum (BAA): Mandatory contract under the Health Insurance Portability and Accountability Act (HIPAA) required before storing or processing Protected Health Information (PHI) on AWS.
  • Organization Agreements: When executed by the management account in AWS Organizations, an agreement (such as the BAA) can be accepted on behalf of all current and future accounts within the AWS Organization, eliminating the need to execute separate agreements per account.

AWS Well-Architected Tool & Security Pillar Reviews

The AWS Well-Architected Framework Tool provides a formal, structured mechanism for measuring cloud architectures against AWS architectural best practices across the six Well-Architected pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability.

The 7 Security Pillar Design Principles

When conducting a Security Pillar review, the Well-Architected Tool evaluates workloads against seven core foundational principles:

  1. Implement a strong identity foundation: Enforce least privilege, centralize identity management, and eliminate reliance on static long-term credentials.
  2. Enable traceability: Log, monitor, and alert on all API activities and metrics in real time; integrate log telemetry into automated response pipelines.
  3. Apply security at all layers: Implement defense-in-depth across edge networks, VPC perimeters, compute instances, operating systems, and application code.
  4. Automate security best practices: Automate software-defined guardrails, IaC security gating, and incident response runbooks to reduce manual operational risk.
  5. Protect data in transit and at rest: Enforce cryptographic protection across all storage tiers, communication channels, and secret management stores.
  6. Keep people away from data: Eliminate direct human access to production databases and storage systems; mandate processing via automated tools, APIs, and CI/CD pipelines.
  7. Prepare for security events: Establish incident response plans, run automated game days, and develop automated containment and forensic investigation playbooks.

Well-Architected Review Mechanics

  • Workload Definition: Users define a workload by specifying its business purpose, environment type (Production vs Non-Production), and operational AWS accounts.
  • Lenses: In addition to the standard Well-Architected Base Lens, organizations can apply specialized lenses (e.g., Serverless Lens, Financial Services Lens, Machine Learning Lens, or Custom Lenses authored by enterprise security teams).
  • Risk Identification:
    • High Risk Issues (HRIs): Critical architectural deficiencies that represent significant security vulnerabilities, single points of failure, or severe operational risks.
    • Medium Risk Issues (MRIs): Deviations from best practices that present moderate risk to workload reliability or governance.
  • Milestones: Formal point-in-time snapshots created to document the state of a workload before and after remediation initiatives.
  • Improvement Plans: The tool automatically generates a prioritized, step-by-step remediation guide listing exact architectural recommendations to eliminate detected HRIs and MRIs.
  • Workload Sharing: Workloads can be shared across AWS accounts or across an entire AWS Organization using AWS Resource Access Manager (RAM) or direct account sharing.

Compliance and Auditing Service Comparison Matrix

Understanding which service to select based on specific auditing and governance requirements is critical for the Specialty exam:

Capability / FeatureAWS Audit ManagerAWS ArtifactAWS Well-Architected ToolAWS Config
Primary ObjectiveContinuous, automated evidence collection for regulatory compliance.Access to AWS compliance attestations and legal contracts.Architectural evaluation against AWS best practices and risk analysis.Real-time resource configuration recording and compliance rule evaluation.
Scope in Shared ResponsibilityCustomer Responsibility (IN the Cloud): Audits customer resources.AWS Responsibility (OF the Cloud): Audits AWS infrastructure.Customer Responsibility (IN the Cloud): Evaluates customer architecture.Customer Responsibility (IN the Cloud): Records customer resource state.
Core OutputAuditor-ready Assessment Reports with cryptographic manifests.Downloadable SOC 1/2/3, ISO, PCI AOC PDFs, and executed BAAs.High/Medium Risk Issues (HRIs/MRIs) and prioritized Improvement Plans.Configuration Items (CIs), compliance status, and SSM remediation actions.
Evidence SourcesCloudTrail, Config, Security Hub, AWS Checkers, and manual uploads.Independent external auditor reports (e.g., EY, PwC, Coalfire).Self-assessment responses against Well-Architected lens questions.Direct API polling and event-driven configuration change streams.
Automated Remediation?No: Evidence gathering and reporting only.No: Legal agreements and static reports only.No: Generates improvement plans; remediation is executed separately.Yes: Native SSM Automation integration for self-healing remediation.

Specialty Exam Pitfalls & Architectural Traps

  1. The Artifact vs. Audit Manager Scope Confusion: Confusing where to obtain proof of data center physical security versus proof of customer bucket encryption. External auditors requesting proof of AWS physical data center controls or hypervisor isolation must be directed to AWS Artifact for the AWS SOC 2 Type II report. If auditors request proof that the customer's production S3 buckets are encrypted, the team must use AWS Audit Manager or AWS Config.
  2. Assuming the Well-Architected Tool Automatically Scans Resources: Believing that the Well-Architected Tool automatically runs automated vulnerability scans on EC2 instances or S3 buckets. The Well-Architected Tool is primarily an architectural questionnaire and evaluation framework (though integrations exist to import findings via Trusted Advisor and Control Tower). It does not autonomously execute automated remediation or intrusive network scans.
  3. Failing to Execute the HIPAA BAA Before Storing PHI: Assuming that because an AWS service is eligible under HIPAA (e.g., Amazon S3, Amazon RDS), an organization is legally compliant to store PHI immediately. Under the shared responsibility model, an organization must formally review and accept the Business Associate Addendum (BAA) in AWS Artifact prior to processing, storing, or transmitting PHI on AWS.
  4. Overlooking Cryptographic Manifest Integrity in Audit Manager: Disregarding the importance of the manifest file when presenting assessment reports to external auditors. The manifest file containing SHA-256 hashes is what legally validates that the automated evidence was collected directly from AWS telemetry without post-capture tampering.
Test Your Knowledge

A healthcare startup is preparing to deploy an application that processes and stores Protected Health Information (PHI) in an AWS Organizations environment spanning 40 AWS accounts. To comply with HIPAA regulations, the company must execute a Business Associate Addendum (BAA) with AWS. How should the enterprise security team execute this agreement with the least administrative effort?

A

Open a high-priority AWS Support ticket requesting legal execution of a BAA for each individual member account.

B

Log into the AWS Management Console of the AWS Organizations management account, navigate to AWS Artifact Agreements, and accept the BAA on behalf of all accounts in the organization.

C

Deploy an AWS Audit Manager assessment using the HIPAA standard framework and upload a signed corporate compliance statement.

D

Configure an AWS Systems Manager Automation document that executes the AssumeRole API across all 40 member accounts to register HIPAA compliance metadata.

Test Your Knowledge

A financial technology company is undergoing an external SOC 2 Type II audit. The external auditor requires continuous evidence over a 12-month period proving that all user administrative API actions are tracked, all S3 buckets remain encrypted, and security posture checks are continuously evaluated. The security team wants to automate evidence harvesting and eliminate manual screenshot collection. Which service should the team deploy to fulfill this requirement?

A

AWS CloudTrail Lake configured to run scheduled SQL queries against management events.

B

Amazon Inspector configured with continuous EC2 and container image vulnerability scans.

C

AWS Audit Manager configured with an assessment based on the SOC 2 standard framework to automatically collect evidence from CloudTrail, AWS Config, and AWS Security Hub.

D

AWS Artifact configured to download the monthly SOC 2 compliance reports published by third-party auditors.

Test Your Knowledge

A lead cloud architect conducts a review of a core payment processing workload using the AWS Well-Architected Framework Tool. The review of the Security Pillar identifies three High Risk Issues (HRIs) involving unrotated long-term IAM credentials and absent automated incident response capabilities. What is the prescribed next step within the Well-Architected Tool to manage and track these risks?

A

Review the automatically generated Improvement Plan for prioritized architectural remediation recommendations and create a milestone to track risk reduction progress over time.

B

Configure the tool to automatically execute Lambda remediation scripts that delete the non-compliant IAM credentials.

C

Export the HRIs to AWS Artifact and request an immediate compliance waiver from AWS Technical Support.

D

Place an explicit Deny Service Control Policy (SCP) on the workload's AWS accounts to halt traffic until the review passes.

Test Your Knowledge

During an annual compliance audit, an external auditor requests two distinct items: (1) formal independent verification that AWS data centers have adequate physical access controls and environmental protections, and (2) technical evidence that all customer Amazon EBS volumes deployed in the production AWS account are encrypted at rest with Customer Managed Keys. Which combination of services provides the required deliverables?

A

Download the AWS SOC 2 Type II report from AWS Audit Manager for data center physical controls, and run an AWS Artifact assessment to prove EBS volume encryption.

B

Use the AWS Well-Architected Tool to download data center physical security certificates, and use AWS CloudTrail to verify EBS volume encryption status.

C

Download the AWS Config compliance summary for data center controls, and use AWS Systems Manager Inventory to prove EBS volume encryption.

D

Download the AWS SOC 2 Type II report from AWS Artifact for data center physical security controls, and use AWS Audit Manager or AWS Config to generate the customer EBS volume encryption evidence.

Sections you finish are checked off in the contents.

Congratulations!

You've completed this section

Continue exploring other exams