Scope Statement
Define which systems, date ranges, and record types are included so reviewers understand the audit boundary and what was intentionally excluded.
The audit creates a verifiable record that financial data are protected, can be restored, and were reviewed on a defined schedule. It reduces regulatory risk, supports tax and financial audits, and documents remediation steps after failures.
Typical authors, reviewers, and recipients vary by organization and regulatory exposure.
The document is designed to be exchanged with internal compliance teams, external auditors, banks, or regulators as required by policy or request.
Define which systems, date ranges, and record types are included so reviewers understand the audit boundary and what was intentionally excluded.
Provide a system-by-system list of backup sets, storage locations, vendor names, and retention classifications for each record type.
Document the retention policy applied to each record class and reference the governing policy or legal requirement that determines the retention period.
Describe checksums, automated integrity checks, and restore tests performed, including dates, tools, and pass/fail results for reproducibility.
List failed backups, incomplete restores, mitigation steps taken, and any outstanding remediation tasks with due dates and owners.
A signed declaration by an authorized officer attesting to the accuracy of the audit, the date of review, and contact information for follow-up.
| Field | Configuration |
|---|---|
| Authentication | Email plus SMS code |
| Signature Type | ESIGN-compliant electronic signature |
| Retention Policy | 6 years (configurable) |
| Notifications | CC compliance and legal |
Choose tools that capture a complete audit trail, store files securely, and support required authentication methods.
Verify the platform supports ESIGN/UETA compliance, audit-trail export, and the authentication strength your compliance team requires before use.
Complete and certify yearly backup audit within 90 days of fiscal year end.
Provide requested backup evidence within 10 business days unless extended by regulation.
Run integrity checks and certify within 5 business days after a data incident.
Retention period begins on the record event date as defined in policy.
Follow documented secure deletion procedures once retention expires.
Compile backup locations and types for the audit period.
Run hashes and reconcile results with backup logs.
Perform targeted restores and document results.
Authorized officer reviews and signs the audit packet.
A property management firm consolidated backup evidence across five locations to produce a single certified packet.
A services company experienced a failed nightly snapshot and ran focused restores to validate recovery.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |