Audit evidence for publicly funded projects: proving the work was done


For most organisations running a publicly funded project, reporting has been an accounting exercise: paid invoices, bank transfers, eligibility checks, supporting documents uploaded to a portal.

Audit evidence is where it breaks down. Auditors on EU-funded programmes now spend less time asking whether money was spent and more time asking whether the thing was actually built, delivered or taught. The documents meant to answer that, site photos, inspection reports, attendance registers, carry no verifiable time, no verifiable place, and no proof the file has not been altered. The audit trail stops exactly where physical reality starts.

Field evidence survives a check only when date, place and integrity can be verified by a third party. That verifiability has to exist from the moment the evidence is created. It cannot be retrofitted when the request lands.

Evidence of implementation is the documentation showing that a funded activity was carried out in the place, on the date and in the manner declared. It is distinct from proof of expenditure, which shows only what was paid. Site photographs, inspection reports, attendance registers, completion certificates and acceptance records all sit in this category. Article 22 of Regulation (EU) 2021/241, which set up the Recovery and Resilience Facility, requires every payment request to be accompanied by a management declaration confirming that the information submitted is "complete, accurate and reliable", plus a summary of the audits carried out and the weaknesses they found. The wording is worth reading twice: reliability is asserted by the implementing body and tested by somebody else. What separates audit evidence that holds from evidence that does not is rarely the content, which is usually accurate. It is whether a reviewer can check date, place and integrity without taking the author's word for it.

What public funding audits actually check

Two separate questions are being asked. One is whether expenditure was eligible, regular and not funded twice, settled on financial records. The other is whether the declared result corresponds to something that happened, settled on audit evidence from the field. The second question is where reporting teams get into trouble, which is why certified evidence management belongs in the project plan rather than the closing phase.

From spending to results: what changes at the verification stage

The Recovery and Resilience Facility pays for results, not for costs. Under traditional structural funds, reimbursement follows eligible expenditure. Under the Facility, disbursement depends on the satisfactory fulfilment of milestones and targets agreed with the European Commission, and Regulation (EU) 2021/241 makes those the trigger for payment. Milestones are qualitative achievements, such as the entry into force of a legal act or the award of a contract. Targets are quantitative and measurable: buildings retrofitted, kilometres laid, people trained. The consequence for an implementing body is concrete. A paid invoice shows that an amount left an account. It does not show that the windows were replaced in that school building rather than another one owned by the same municipality. Under NextGenerationEU the proof of implementation is physical before it is financial, and it can only be assembled while the work is running.

That shift also moves the exposure. The people holding the decisive records are site engineers, trainers and field technicians, and the audit trail now runs through them.

The levels of control, from the implementing body to the European Court of Auditors

Four sets of eyes look at a funded project, and none of them looks at the same thing:

  1. Implementing body: self-check on administrative regularity, eligibility and programme requirements.
  2. Managing ministry or agency: verification of reports and of milestones and targets, often sampled.
  3. Audit authority: second-level control, independent from the bodies that manage the funds.
  4. Commission services, European Court of Auditors, OLAF and EPPO: external audit and investigation.

Access rights on EU funds do not stop at the beneficiary. Article 22(2)(e) of Regulation (EU) 2021/241 obliges Member States to expressly authorise the Commission, OLAF, the European Court of Auditors and, where applicable, the European Public Prosecutor's Office to exercise the rights set out in Article 129(1) of the Financial Regulation, and to extend the same obligation to all final recipients of the funds. Article 129(1) of Regulation (EU, Euratom) 2024/2509 requires any person or entity receiving Union funds to cooperate fully in protecting the Union's financial interests and to grant the necessary access as a condition for receiving the money. For OLAF those rights expressly include on-the-spot checks and inspections. A subcontractor two steps down faces the same evidentiary standard as the body that signed the agreement.

What happens when evidence does not hold

A claim that cannot be supported is not just a remark in a report. Managing authorities can reduce or withdraw the contribution, and Article 22(1) of the RRF Regulation requires Member States to recover amounts wrongly paid or incorrectly used. A municipality ends up paying back money already spent on works that were genuinely carried out.

Enforcement data shows the pattern. OLAF's 2025 report records 209 concluded investigations and EUR 597 million recommended for recovery, with 18 cases connected to the Facility. The irregularities described on those cases include inadequately defined baselines for performance indicators, insufficient cross-checks against parallel investments, and inflated results through multiple funding of the same project. Not one is a missing bank transfer. All three are failures of audit evidence. EPPO points the same way: at the end of 2025 it was handling 518 active cases linked to NextGenerationEU, 512 of them under the Facility, 66.7% more than the year before.

Why ordinary photos, reports and registers do not hold up

Evidence produced in daily practice usually describes what happened accurately. It just does not prove it to a stranger. Photos, reports and registers are created on personal devices in freely editable formats, and none of the three carries anything a reviewer can verify independently.

Site photos without verifiable time and place

A site photograph becomes audit evidence only when its date, place and integrity can be verified by a third party. Image metadata is declared by the device that produced it, not attested by anyone: EXIF fields can be rewritten with free tools, the device clock can be moved, the location tag can be missing, wrong or edited. Article 36(3)(c) of Regulation (EU, Euratom) 2024/2509 requires effective internal control to include "adequate audit trails and data integrity in data systems, including electronic ones", and Article 149(1) requires computer systems used for expenditure operations to explain in detail how they guarantee a complete audit trail for each operation. A folder of image files on a shared drive satisfies neither. The reviewer has no independent way of establishing that a picture was taken on the stated day at the stated building, and no obligation to assume it.

The break happens in the same place every time. Whoever produces the photograph treats its weight as obvious; whoever examines it does not. That gap is what certified geolocation closes, and its absence is why construction progress documentation keeps coming back for clarification.

Inspection reports in editable PDF

An inspection report saved as an ordinary PDF records what the inspector saw. It does not establish when it was written or that nobody amended it later. The typical challenge is not technical but chronological: if the file could have been created or altered at any moment, it does not prove the inspection took place on the date it carries. Site diaries kept digitally share the weakness, and it breaks the audit trail at exactly the point where it matters. When a report embeds photographs, those need certifying too. An intact container holding unverifiable content moves the problem rather than solving it, which is what well-built photo reports are designed to avoid.

Attendance registers reconstructed after the fact

On training measures the target is a headcount, and the register is the only thing supporting it. It is also the weakest artefact in the file, because it tends to be completed at the end of the course, with signatures gathered in a batch or sheets rewritten to make them legible. A register filled in as the session runs and one reconstructed afterwards look identical on paper. Only the first can show when it came into existence. When a reviewer compares the declared figure with the figure the registers actually sustain, any gap turns into a reduction.

What it means to certify evidence at the moment it is created

TrueScreen, the Data Authenticity Platform, certifies evidence at the moment it is created: a qualified timestamp, certified geolocation and an integrity seal are bound to the file at capture, not applied afterwards. The difference from any later archiving, however orderly, is when the guarantee comes into existence. Certify a file later and what you certify is a file whose history nobody knows: you can show it has not changed since that instant, not that it corresponds to something that happened in a given place on a given day. Build the guarantee into the capture and the audit evidence carries three things inseparable from the content: when, where, what. That is the triad a second-level control has to reconstruct years later, without asking anyone who was there to confirm it.

Qualified timestamp, certified geolocation and integrity seal

The eIDAS Regulation attaches a legal presumption to qualified electronic time stamps. Article 41(2) of Regulation (EU) No 910/2014 provides that a qualified electronic time stamp "shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound". Article 42(1) sets the conditions: it must bind date and time to the data "in such a manner as to reasonably preclude the possibility of undetectable changes", rest on an accurate time source linked to Coordinated Universal Time, and be sealed with an advanced electronic seal of the qualified trust service provider or an equivalent method. Article 35(2) gives qualified electronic seals a parallel presumption of data integrity and correctness of origin. A reviewer who doubts the date can no longer simply say so.

Each element answers a different objection. Qualified electronic timestamps answer when, and they are not issued by TrueScreen: the timestamp and the electronic seal that travels with the capture come from a qualified QTSP integrated into the platform. Certified geolocation answers where, separating a retrofit at one school from one at another building owned by the same authority. The integrity seal, built on a SHA-256 digital fingerprint, answers what: any later change, down to a single bit, becomes detectable.

A chain of custody that survives years

Retention is not only about keeping the file alive. Article 22(2)(f) of the RRF Regulation requires records to be kept in accordance with the Financial Regulation, and Article 133(1) of Regulation (EU, Euratom) 2024/2509 sets the period at five years following the payment of the balance, or three years where the funding is EUR 60 000 or less. Article 133(3) is the clause that decides the outcome: electronic versions replace originals only where they "meet the applicable legal requirements in order to be considered as equivalent to originals and to be relied on for audit purposes".

Five years is a long time on a building site. The reporting manager may have moved on, the contractor may have wound up, the phone that took a photograph may no longer exist. A documented chain of custody, of the kind ISO/IEC 27037 describes for the identification, collection, acquisition and preservation of digital evidence, keeps the audit trail readable without depending on memory. Teams reporting on publicly funded projects use TrueScreen to document site inspections, progress stages and training sessions with time and place a third party can verify years later.

Which evidence each type of intervention requires

Measures are not proved the same way. What varies is not the type of document, often identical, but the fact to be established, and therefore the element that makes the audit evidence hold.

Intervention What must be proven Minimum evidence What makes it hold up
Works and infrastructure Physical execution at the declared site Photo sequence before, during, after Certain date and coordinates of capture
Energy efficiency retrofit Components installed or replaced Photos of components, datasheets Integrity seal on image and attachment
Classroom training Actual attendance of participants Attendance register, course materials Capture in real time, not at course end
Online training Delivery and duration of the session Session recording and register Qualified timestamp on the session
Supplies and installations Delivery and commissioning at the recipient Acceptance report, photo of the asset Certified geolocation of the place
Field services Delivery within the declared period Activity reports, field evidence Chain of custody from capture to file

Works and public infrastructure

Take the energy efficiency retrofit of a school building. Before the site opens, the technician records the state of the premises with framing that includes an identifiable feature of the building. During execution three moments are fixed: insulation installed, windows replaced, plant commissioned. At the end, the finished state and the completion certificate. Eighteen months later the audit asks for proof that the work concerned that building and not another one in the district. With a certified progress inspection at each stage, the audit trail answers. For construction companies without one, the answer depends on who still remembers.

Training delivered in person and online

A course delivered partly in a classroom and partly remotely raises two problems. In the room, the risk is the register completed at the end of the day, which says nothing about when attendance was taken. Remotely, the risk is that nothing verifiable survives the session, or that a recording survives with no reliable time reference. One principle settles both: capture the evidence while the activity is happening. Where the target is a headcount, and it usually is, the reviewer compares the declared number with the number the registers can carry.

Setting up evidence collection before work starts

Evidence collection is a planning decision, taken alongside the schedule. The same logic applies to public procurement contracts and to digital public procurement generally: execution has to be proven rather than declared, so the audit trail is designed before anyone breaks ground.

Who collects what, and how often

Three questions, written down before the site opens. Who collects: the works supervisor for progress stages, the project manager for formal milestones, the trainer for each session, the technician for installations. What: the photo sequences, reports, registers and acceptance records set out above. How often: at every progress stage, session and delivery. Collection can be set up before work starts by assigning each role on site what to document and how often, and with TrueScreen every capture enters the file already certified, with no separate validation step.

The audit file that builds itself

A defensible audit file is not assembled at the end, it accumulates while the work is being done, and the difference shows up the day a request arrives. Article 36(2)(d) of Regulation (EU, Euratom) 2024/2509 requires internal control to give reasonable assurance on the prevention, detection, correction and follow-up of irregularities including fraud, corruption, conflicts of interest and double funding, supported by a single integrated and interoperable information and monitoring system with a data-mining and risk-scoring tool. Selection is therefore risk-driven and partly automated, and Article 129(1) gives OLAF the right to carry out on-the-spot checks and inspections. Notice is short by design. Extracting audit evidence that already exists in verifiable form takes days. Reconstructing the history of a two-year project after the fact, chasing contractors that have restructured and staff who have moved on, does not fit the same window.

Even the screenshots that reporting procedures routinely ask for are fragile in the same way: an image of a screen, produced on the day it is requested, carries nothing showing when it was made. Where the file is fed with material certified at source, the digital provenance of each item already travels inside the item.

The moment to act is not when the audit request lands. It is when the handover of the site is signed. At that point, deciding who documents what and with what guarantee costs almost nothing. Later it costs whatever share of the contribution cannot be defended.

The window also stays open longer than most plans assume. The five-year clock in the Financial Regulation starts at the payment of the balance, so projects that feel closed today can still be examined well into the next decade. An orderly archive of photos and reports that nobody can verify is, from an auditor's chair, material to be examined case by case. A file of audit evidence certified at source is material that gets read and closed.

FAQ: audit evidence for publicly funded projects

What is evidence of implementation in publicly funded projects?
Evidence of implementation is the documentation showing that a funded activity was carried out in the place, on the date and in the manner declared. It differs from proof of expenditure, which shows only what was paid. Site photographs, inspection reports, attendance registers, completion certificates and acceptance records all belong to this category. Article 22 of Regulation (EU) 2021/241 requires each payment request to be accompanied by a management declaration confirming that the information submitted is complete, accurate and reliable. Evidence holds up in an audit when date, place and file integrity can be verified by a third party rather than asserted by whoever produced it.
Does a site photograph have evidential value in an audit?
It depends on how it was produced. An ordinary photograph carries metadata declared by the device, not attested by anyone: EXIF fields can be rewritten, the clock can be moved, the location tag can be missing or edited. An auditor has no independent way to confirm that the image was captured on the stated day at the stated site. A photograph certified at the moment of capture removes both objections. TrueScreen produces a forensic report for every item of evidence, with the file's digital fingerprint, a qualified time reference and the coordinates of the capture point.
What is a second-level control on EU funds?
A second-level control is a check carried out by a body independent of the ones that manage and report on the intervention, normally the audit authority designated under the management and control system. It does not repeat the verification already done by the managing ministry. It tests whether that system works and whether the evidence supporting reported expenditure and reported results genuinely exists. Article 22(2)(c) of Regulation (EU) 2021/241 requires each payment request to carry a summary of the audits performed, including weaknesses found and corrective action taken. Field documentation tends to fail here, because the auditor has no direct knowledge of the site.
How long must evidence from an EU-funded project be kept?
Article 22(2)(f) of Regulation (EU) 2021/241 requires records to be kept in accordance with the Financial Regulation. Article 133(1) of Regulation (EU, Euratom) 2024/2509 sets the period at five years following the payment of the balance, dropping to three years where the funding is EUR 60 000 or less. Article 133(2) extends retention until closure where audits, appeals, litigation or OLAF investigations are open. Article 133(3) accepts electronic versions in place of originals only where they meet the applicable legal requirements to be treated as equivalent and relied on for audit purposes. Storage alone is not enough.
What happens if you cannot document a funded intervention?
The outcome depends on the seriousness of the gap and when it surfaces. Managing authorities can reduce or withdraw the contribution, and Article 22(1) of Regulation (EU) 2021/241 requires Member States to recover amounts wrongly paid or incorrectly used. For a public body that means returning money already spent on works that were genuinely carried out, with an immediate effect on the budget. Where the facts suggest fraud against the Union budget, OLAF and the European Public Prosecutor's Office can open their own proceedings, and OLAF's rights of access include on-the-spot checks and inspections under Article 129(1) of the Financial Regulation.
Is an inspection report in PDF enough for reporting purposes?
An ordinary PDF documents the content of the inspection but does not establish when it was drawn up or that it was not amended afterwards. The usual challenge in an audit is not the technical merit of the report, it is its position in time: if the file could have been created or altered at any moment, it does not prove the inspection happened on the date it carries. A report with an integrity seal and a qualified timestamp makes alteration detectable and fixes the moment of drafting. If the report embeds photographs, those need certifying as well, since an intact container holding unverifiable content solves nothing.
Who audits EU funds, and at which levels?
Control runs across levels that examine different things. The implementing body performs its own check on administrative and accounting regularity. The managing ministry or agency verifies reports and the achievement of milestones and targets, often on a sample basis. The audit authority carries out second-level control, independent from the management of the funds. Externally, the European Commission, the European Court of Auditors, OLAF and the European Public Prosecutor's Office operate under Article 22(2)(e) of Regulation (EU) 2021/241, which extends their access rights to all final recipients of the funds, including subcontractors.

Certify evidence while the work is happening

Every photo, inspection report and register captured with TrueScreen carries a verifiable time, place and integrity seal, so the audit file builds itself during delivery instead of after the request arrives.

mockup app