Skip to main content
Version: 1.0.0

Evidence

The Evidence module is the central repository for the proof that supports compliance, audit, risk, and governance work. A single evidence record — a document, screenshot, report, configuration export, or link — can be captured once and reused everywhere it is needed.

1. Background and Business Purpose

Auditors and regulators ask for proof, not assertions. Holding evidence as governed records with ownership, validity dates, and approval means the same artefact can satisfy a control in an assessment, a finding in an audit, and a requirement in a policy review without being uploaded again each time.

Main business outcomes:

  • maintain a single, searchable evidence repository
  • reuse one artefact across many controls and records
  • track validity and approval so stale proof is visible
  • preserve a defensible evidence trail for audits and reviews

2. Core Records and Actors

ItemMeaning
EvidenceA governed proof record with a code, bilingual name and description, type, status, an attached file or external link, validity window, version, tags, and the links to the records it supports.
VersionA superseding update of an evidence record; the prior version is retained for history.
LinkThe association between an evidence record and a GRC object (control, finding, risk, policy, and others).

An evidence record has a type — Document, Screenshot, Report, Configuration, Link, or Other — and a status — Draft, Pending Approval, Approved, Rejected, or Expired.

ActorResponsibility
Evidence owner / uploaderCaptures the artefact, sets validity dates, and links it to the relevant records.
ApproverReviews and approves evidence so it can be relied on.
Assessor / auditorMaps approved evidence to controls and findings during their work.

3. Validity and Expiry

Evidence can carry a valid-from and valid-until date. As proof ages past its valid-until date it moves to Expired, so reviewers can see at a glance which artefacts need to be refreshed before the next assessment or audit cycle. Maintaining validity dates is what keeps an evidence library trustworthy over time.

4. Working with Evidence

The repository is available at Evidence.

ActionWhat it does
Add evidenceCreate a record and attach a file or an external link, with bilingual name, type, validity dates, and tags.
Bulk uploadAdd many files at once from a single dialog.
Link to recordsAttach the evidence to one or more GRC objects so it appears in their context.
View and downloadOpen the evidence detail and download the underlying file.
EditUpdate details, validity dates, or links; create a new version when the proof changes.
DeleteRemove an evidence record that is no longer required.

A single evidence record can be linked to many record types, including assessment controls, audit findings, issues, risks, policies, incidents, vendors and vendor assessments, assets, change requests, vulnerabilities, audits, assessments, and policy exceptions.

  • Compliance and Assessments — evidence is mapped to controls during an assessment, and the Evidence Pack Export bundles an assessment's evidence into a single ZIP.
  • Controls — controls reference the evidence that demonstrates they are operating.
  • Audit Management — findings cite evidence to support their conclusions.