Evidence you can hand over
A record with a hash, exportable, naming the approver.
A record of who approved which change, and against which version of the content. Each entry carries a hash. The hash shows the record has not been edited since.
Your audit trail writes itself while you work.
Governed changes land in a hash-chained ledger using plain SHA-256 with no secret key, so your auditor can re-verify its integrity from the export with their own tools.
Every governed action is staged as a plan. It is applied only after a person approves it. The approval is the event on the record.
A log anybody can add to is a log an auditor discounts. Entries are hashed by content and chained together. A later edit no longer matches.
Sign in with a managed username and password, plus a required authenticator tool. Or use SAML 2.0 against your own identity provider, one connection per organisation.
A record with a hash, exportable, naming the approver.
Every governed tool writes to the same trail.
Which checks map to which control, and where the mapping stops.
It says which frameworks are covered by real checks, and which are not.