Skip to content

Evidence Fabric

The Evidence Fabric (/evidence) is OrviQ's centralized repository for verified proof supporting internal controls, compliance determinations, and audit inquiries.


Evidence Attributes

Each evidence record maintains:

  • Title & Description: Clear summary of what the evidence artifact represents (e.g., Q2 Firewall Configuration Export or Annual User Access Certification).
  • Source Asset: Uploaded document, screenshot, export file, or structured log.
  • Validity Period / Expiration Date: The date until which the artifact is considered valid.
  • Verification Status: Verified, Pending Review, Expired, or Rejected.
  • Entity Links: Direct associations to Controls, Requirements, Audits, or Risks.

Freshness & Expiration Mechanics

Evidence is time-sensitive. OrviQ monitors evidence freshness:

  • Current / Fresh: The evidence artifact is within its valid coverage window.
  • Expiring Soon: Approaching expiry (typically within 30 days), triggering a reminder task in the Control Owner's workbench.
  • Expired: The validity window has elapsed. The associated control will flag an evidence freshness breach until a new artifact is provided and verified.

::: note Sufficiency Doctrine An evidence artifact must demonstrate substantive operational proof for the relevant period. Simply uploading an empty template or outdated document does not satisfy assurance requirements. :::

OrviQ Enterprise Governance, Risk & Compliance Platform