The specific documentation depends on the framework, but most audits require a System Security Plan (SSP) describing how each required control is implemented, a Plan of Action and Milestones (POA&M) addressing any known gaps, written security policies and procedures, evidence of employee security training and logs demonstrating that your controls are active and monitored. Documentation gaps are among the most common reasons organizations fail audits, and among the easiest to fix with proper preparation.