Skip to content

Evidence Register

Where to find it: Controls & Assurance, then Evidence Register (/evidence).

The Evidence Register holds the artefacts your organisation relies on to demonstrate compliance: reports, exports, screenshots, signed approvals, meeting minutes, test results.


What the register is for

Three things:

  1. Custody. One place where evidence lives, rather than scattered across mailboxes and shared drives.
  2. Linkage. Evidence connected to the controls and requirements it supports, so a reviewer can move from an obligation to its proof in one step.
  3. Input to assurance. Artefacts become the basis for evidence assertions, which indicators evaluate.

What an evidence record carries

FieldPurpose
TitleWhat this artefact is
DescriptionWhat it demonstrates, and about what
FileThe artefact itself
Evidence dateWhen the evidence was produced, which is not necessarily when it was uploaded
Uploaded by and uploaded atCustody record
LinksControls, requirements, activities, assessments and findings it supports
Review stateWhether it has been accepted or rejected

Evidence date matters more than upload date

Freshness is measured from when the evidence was produced. A quarterly access review performed in January and uploaded in April is three months old, not one day old, and recording the evidence date is what makes freshness honest.


Uploading evidence

  1. Open the Evidence Register and select Upload.
  2. Attach the file.
  3. Give it a title that identifies it without opening it — "Q1 2026 Privileged Access Recertification, Payments Platform" rather than "export_final_v3".
  4. Describe what it demonstrates and about which subjects. This is the field that determines whether anyone can use the evidence later.
  5. Set the evidence date.
  6. Link it to the relevant controls and requirements.

Requires evidence.upload.


Linking evidence

Evidence can be linked to controls, requirements, obligation activities, control assessments, findings and action plans.

Linking is what makes evidence findable from the record that needs it. An unlinked artefact is stored, not usable.


Reviewing evidence

Evidence can be accepted or rejected by a reviewer holding evidence.review.

Rejection is not a criticism of the uploader — the most common legitimate reason is that the artefact does not demonstrate what the linked obligation requires. Recording the rejection with a reason prevents the same artefact being resubmitted.


From artefact to assertion

This is the step most often missed, and the reason a register can look full while coverage reads zero.

An artefact in the register is a document. An assertion is a statement about a subject at a time. Assurance evaluates assertions, not documents.

A quarterly access review covering 58 systems produces:

  • One evidence record — the export
  • 58 assertions — one per system reviewed, each with a subject, a state and a freshness window

Recording those assertions is what turns the artefact into coverage.

Requires assertion.create.

An uploaded file changes nothing on its own

Uploading evidence does not move any compliance position. Until assertions are recorded from it and an indicator evaluates them, it contributes nothing to coverage, effectiveness or satisfaction. This is the same principle as mapping not being compliance, applied one stage later.


What makes evidence good

It states its own scope. "Privileged access review, payments platform production, 58 of 63 systems, five deferred pending decommissioning" is usable. "Access review" is not.

It is dated. Undated evidence cannot be assessed for freshness and will be challenged.

It is attributable. Evidence produced by a named system or person, with a timestamp, survives scrutiny. An unattributed screenshot does not.

It is reproducible. Where possible, prefer a system export over a screenshot. If an assessor asks you to reproduce it, you should be able to.

It says what failed. Evidence that shows only successes is treated with suspicion, correctly. A review that found three exceptions and documents them is stronger evidence than one that found none.


Retention and expiry

Evidence does not expire from the register — historical evidence stays available for reconstruction. What expires is its freshness for assurance purposes.

An access review from January remains valid evidence of what happened in January forever. It stops being current evidence of today's state after its freshness window. See Expected Evidence & Freshness.


Permissions

ActionPermission
View evidenceevidence.read
Upload evidenceevidence.upload
Accept or reject evidenceevidence.review
Record assertions from evidenceassertion.create
View assertionsassertion.read
Export evidence dataexport.data

Example

A bank's Evidence Register holds 1,840 artefacts across a year.

A representative record:

FieldValue
TitleQ1 2026 Privileged Access Recertification — Payments Platform Production
DescriptionRecertification of all privileged accounts on 63 in-scope systems. 58 systems completed; 5 deferred pending decommissioning, tracked under FND-2026-0044. Three accounts revoked.
Evidence date31 March 2026
Linked toCTL-2026-0044 Privileged Access Management; requirement A.5.18; activity ACT-2026-0117
Assertions recorded58, one per completed system, freshness window 100 days
Review stateAccepted

The description does the work. It states the population, the completion, the exceptions and where the exceptions are tracked — so a reviewer in nine months does not have to open the file to know what it says.


Troubleshooting

"I uploaded evidence but coverage did not change." No assertions were recorded from it. See "From artefact to assertion" above.

"Evidence shows as stale but we uploaded it last week." Freshness is measured from the evidence date, not the upload date. Check the evidence date on the record.

"I cannot link evidence to a requirement." Check that you hold evidence.upload and that the requirement is visible to you.

"An assessor questioned our evidence." The most common causes are missing dates, unstated scope and screenshots without attribution. See "What makes evidence good".


OrviQ Enterprise Governance, Risk & Compliance Platform