Appearance
Evidence Fabric
The Evidence Fabric (/evidence) is OrviQ's centralized repository for verified proof supporting internal controls, compliance determinations, and audit inquiries.
Evidence Attributes
Each evidence record maintains:
- Title & Description: Clear summary of what the evidence artifact represents (e.g., Q2 Firewall Configuration Export or Annual User Access Certification).
- Source Asset: Uploaded document, screenshot, export file, or structured log.
- Validity Period / Expiration Date: The date until which the artifact is considered valid.
- Verification Status: Verified, Pending Review, Expired, or Rejected.
- Entity Links: Direct associations to Controls, Requirements, Audits, or Risks.
Freshness & Expiration Mechanics
Evidence is time-sensitive. OrviQ monitors evidence freshness:
- Current / Fresh: The evidence artifact is within its valid coverage window.
- Expiring Soon: Approaching expiry (typically within 30 days), triggering a reminder task in the Control Owner's workbench.
- Expired: The validity window has elapsed. The associated control will flag an evidence freshness breach until a new artifact is provided and verified.
::: note Sufficiency Doctrine An evidence artifact must demonstrate substantive operational proof for the relevant period. Simply uploading an empty template or outdated document does not satisfy assurance requirements. :::