Internal Auditor
If the audited party assembles the evidence, what you receive is not evidence. It is a selection.
The audit plan is set, a sample is drawn, evidence is requested from the relevant team. The team gathers it and you wait.
What arrives is screenshots, printed emails and hand prepared spreadsheets. All of it may be accurate. None of it is independent.
The sample is kept small, because gathering evidence for each item costs the team a week. A small sample means narrow assurance.
Evidence is not gathered afterwards. The action produces it. That also lowers the burden on the audited team, so both sides gain.
Every record carries the rule set that was in force that day. Even after the rules change, an old action is read against the rules of its own day.
Every skipped step is recorded with its reason. An exception stops being invisible and becomes reviewable.
The evidence file can be verified independently of the system that keeps it. You perform the verification rather than being told the result.
That sentence means nothing without a mechanism behind it, so here it is. Every package delivered to you is a zip containing the data itself, an identity file listing the SHA-256 digest of every file in the package, the RSA signature over that identity file, the public key that checks the signature, and a verification script.
The verification runs on your machine. Nothing connects to the product, nothing goes over the network, nothing is requested from the organisation. The PowerShell that ships with Windows, or openssl, is enough.
Neither check needs the organisation's audit key, because that key never leaves them. The first shows the records are linked to each other. The second compares a value from an anchor delivered to you earlier against today's records; that is where the evidential weight sits, and it depends on your having received the anchor before audit day.