---
name: IRAP Evidence Trail
description: Reorganises governance documents into ISM-mapped evidence folders for an IRAP assessment, indexed by control and gap-flagged.
lastReviewed: 2026-09-30
---

# IRAP Evidence Trail

> **TL;DR:** This skill takes an ad-hoc set of governance documents and reorganises them into a folder structure organised by Information Security Manual (ISM) family, with each artefact timestamped, indexed by control, and missing families flagged as gaps.

## How does the IRAP Evidence Trail skill structure an ISM evidence pack?

The IRAP Evidence Trail skill reorganises a flat set of governance documents into a folder structure indexed by Information Security Manual (ISM) control reference, so an IRAP assessor can find each artefact. It records each file's modified date and flags families with no evidence as gaps. It only moves or copies files.

The folder names below are this skill's own working convention, not official ISM chapter titles. Align them to the current ISM published by the Australian Cyber Security Centre before sharing a pack with an assessor.

## When should you run this skill?

- "Organise IRAP evidence trail"
- "Build ISM evidence pack"
- "Prepare for an IRAP assessment"
- "Restructure our security documents by ISM family"

## Target folder structure

```text
IRAP-Evidence-<cycle>/
  00-INDEX.md
  01-Governance/
  02-Personnel-Security/
  03-Communications-Security/
  04-Information-Technology-Security/
  05-Network-Security/
  06-Cryptography/
  07-Application-Security/
  08-Cloud-Computing-Security/
  09-Enterprise-Mobility/
  10-Incident-Management/
```

## How this skill works, step by step

1. Confirm the assessment cycle name (for example, your organisation's assessment name and year)
2. Read each existing document and tag it with the most appropriate ISM family
3. Move documents into the target structure (or copy with original linked back)
4. Create `00-INDEX.md` listing every artefact: file path, ISM family, control references where known, last modified date
5. Flag gaps: ISM families with zero artefacts get a "GAP — needs evidence" row in the index
6. Produce a one-page summary for the assessor's pre-read

## Output format

- File system reorganisation (or copies) in the target structure
- `00-INDEX.md` as the master cross-reference
- Summary table at the end of the run

## Scope and safety

This skill does NOT:

- Author missing evidence (gaps are flagged, not filled)
- Make IRAP assessment decisions
- Modify the original documents — moves or copies only

## Licensing and permissions

- This skill works on files you already hold and needs no Microsoft 365 licence, Microsoft Entra role or Microsoft Graph permission of its own. It does not call Microsoft Graph.
- Microsoft documents that Microsoft Purview Compliance Manager offers a premium assessment template for IRAP. Licence requirements for premium templates are not covered on the pages cited here, so check them on Microsoft Learn before relying on that template.

## Related skills

- [IRAP Control Evidence](/purview/irap-control-evidence): run before this to produce control-by-control evidence from the tenant.
- [ISM Control Pack](/purview/ism-control-pack): run before this to map tenant configuration to ISM controls.
- [Compliance Manager Control Mapper](/purview/compliance-manager-control-mapper): run alongside this to map controls to the ISM and Essential Eight.
- [E8 Evidence Packager](/purview/e8-evidence-packager): run after this if you also need an Essential Eight evidence folder.
- [Australian Compliance for Microsoft 365 Copilot and AI](/purview/australian-copilot-compliance): pillar page on Australian compliance evidence, including IRAP.

## Sources

Reviewed 2026-09-30 against the two Microsoft Learn pages below. ISM chapter names were not verified against the ISM itself, so the folder names are a working convention only.

- [Australian Government Information Security Registered Assessor Program (IRAP), Microsoft Learn](https://learn.microsoft.com/compliance/regulatory/offering-irap-australia): IRAP is governed and administered by the Australian Cyber Security Centre (ACSC); endorsed assessors give independent assessment; the Compliance Manager premium template.
- [Australia IRAP, Microsoft Learn](https://learn.microsoft.com/azure/compliance/offerings/offering-australia-irap): IRAP assesses a system's security against the Australian Government Information Security Manual (ISM).
- Pair with the E8 Evidence Packager skill for the data-repository portion of the evidence pack.
