PBC list
Also known as: Request List, Evidence Request List (ERL), Audit Request List
PBC stands for "Provided By Client." It is a formalized request list sent by an auditor to the organization being audited to specify the evidence needed to verify controls. This document serves as the primary checklist for gathering logs, policies, and screenshots required for compliance validation.
Why it matters
Missing or inaccurate submissions lead to audit delays and increased billable hours from the external firm. If a requested item is not provided, auditors may conclude that the control does not exist or is ineffective, resulting in an "exception" or a qualified opinion in reports like SOC 2 or ISO 27001. Such failures can jeopardize customer contracts that require clean compliance certifications. The CISO or CFO typically remains accountable for these gaps and the subsequent impact on business reputation.
In practice
The external auditor creates this list during the planning phase, before fieldwork begins. It is usually delivered via a secure GRC portal or a shared spreadsheet to ensure tracking. Evidence requested often includes user access reviews, change management tickets, and signed employee handbooks. The process produces an evidence repository where each item is mapped to a specific control ID. In a first-year engagement, the list is exhaustive as auditors establish a baseline; in repeat years, it focuses on "delta" changes and current-period samples.
Worked example
FinTechFlow Inc. underwent a SOC 2 Type II audit for the period of January 1 to December 31, 2023. The auditor requested a list of all employees hired in Q3 along with their corresponding background check confirmations via the PBC request. FinTechFlow provided documentation for only five hires when HR records showed twelve new staff members during that window. Because evidence was missing for seven individuals, the auditor flagged a control deficiency regarding personnel screening. This resulted in a qualified report, requiring the company to implement a remediation plan before the next audit cycle.
Common mistakes
- Providing summary spreadsheets instead of raw system screenshots or logs, which prevents auditors from verifying data integrity.
- Uploading outdated policy versions that have not been reviewed or signed within the current audit window.
- Batching all evidence on the final day of fieldwork, leaving no time for the auditor to ask clarifying questions before the report deadline.
- Including unredacted PII (Personally Identifiable Information) in screenshots, which violates data protection laws and creates a security risk within the audit tool.
Frequently asked questions
What does PBC stand for in an audit context?
It stands for "Provided By Client." It refers to any documentation or evidence that the auditor requires the organization to produce from its own internal records.
How is a PBC list different from a Request List?
They are effectively the same thing; "PBC" is the traditional accounting and audit term, while "Request List" is more common in general security assessments. Both serve as the master checklist for evidence collection.
What is the best way to organize responses to these requests?
Use a naming convention that matches the auditor's request ID (e.g., "CTRL-01UserAccessReview2023.pdf"). This allows auditors to map files quickly and reduces time spent on manual reconciliation.
What happens if I cannot provide a document requested in the PBC?
You must notify the auditor immediately and provide a written explanation or alternative evidence that proves the control is working. Failure to do so usually results in a "finding" or a "deficiency" in the final report.
When should the organization expect to receive this list?
Typically, it is sent during the planning phase, two to four weeks before fieldwork begins. This gives the internal team time to gather evidence without disrupting daily operations.
More terms
Materiality · SOC 1 · Statement of Applicability · Walkthrough · Segregation of duties · Inherent risk · Gap assessment · Assertion