Appearance
Evidence Register
Where to find it: Controls & Assurance, then Evidence Register (/evidence).
The Evidence Register holds the artefacts your organisation relies on to demonstrate compliance: reports, exports, screenshots, signed approvals, meeting minutes, test results.
What the register is for
Three things:
- Custody. One place where evidence lives, rather than scattered across mailboxes and shared drives.
- Linkage. Evidence connected to the controls and requirements it supports, so a reviewer can move from an obligation to its proof in one step.
- Input to assurance. Artefacts become the basis for evidence assertions, which indicators evaluate.
What an evidence record carries
| Field | Purpose |
|---|---|
| Title | What this artefact is |
| Description | What it demonstrates, and about what |
| File | The artefact itself |
| Evidence date | When the evidence was produced, which is not necessarily when it was uploaded |
| Uploaded by and uploaded at | Custody record |
| Links | Controls, requirements, activities, assessments and findings it supports |
| Review state | Whether it has been accepted or rejected |
Evidence date matters more than upload date
Freshness is measured from when the evidence was produced. A quarterly access review performed in January and uploaded in April is three months old, not one day old, and recording the evidence date is what makes freshness honest.
Uploading evidence
- Open the Evidence Register and select Upload.
- Attach the file.
- Give it a title that identifies it without opening it — "Q1 2026 Privileged Access Recertification, Payments Platform" rather than "export_final_v3".
- Describe what it demonstrates and about which subjects. This is the field that determines whether anyone can use the evidence later.
- Set the evidence date.
- Link it to the relevant controls and requirements.
Requires evidence.upload.
Linking evidence
Evidence can be linked to controls, requirements, obligation activities, control assessments, findings and action plans.
Linking is what makes evidence findable from the record that needs it. An unlinked artefact is stored, not usable.
Reviewing evidence
Evidence can be accepted or rejected by a reviewer holding evidence.review.
Rejection is not a criticism of the uploader — the most common legitimate reason is that the artefact does not demonstrate what the linked obligation requires. Recording the rejection with a reason prevents the same artefact being resubmitted.
From artefact to assertion
This is the step most often missed, and the reason a register can look full while coverage reads zero.
An artefact in the register is a document. An assertion is a statement about a subject at a time. Assurance evaluates assertions, not documents.
A quarterly access review covering 58 systems produces:
- One evidence record — the export
- 58 assertions — one per system reviewed, each with a subject, a state and a freshness window
Recording those assertions is what turns the artefact into coverage.
Requires assertion.create.
An uploaded file changes nothing on its own
Uploading evidence does not move any compliance position. Until assertions are recorded from it and an indicator evaluates them, it contributes nothing to coverage, effectiveness or satisfaction. This is the same principle as mapping not being compliance, applied one stage later.
What makes evidence good
It states its own scope. "Privileged access review, payments platform production, 58 of 63 systems, five deferred pending decommissioning" is usable. "Access review" is not.
It is dated. Undated evidence cannot be assessed for freshness and will be challenged.
It is attributable. Evidence produced by a named system or person, with a timestamp, survives scrutiny. An unattributed screenshot does not.
It is reproducible. Where possible, prefer a system export over a screenshot. If an assessor asks you to reproduce it, you should be able to.
It says what failed. Evidence that shows only successes is treated with suspicion, correctly. A review that found three exceptions and documents them is stronger evidence than one that found none.
Retention and expiry
Evidence does not expire from the register — historical evidence stays available for reconstruction. What expires is its freshness for assurance purposes.
An access review from January remains valid evidence of what happened in January forever. It stops being current evidence of today's state after its freshness window. See Expected Evidence & Freshness.
Permissions
| Action | Permission |
|---|---|
| View evidence | evidence.read |
| Upload evidence | evidence.upload |
| Accept or reject evidence | evidence.review |
| Record assertions from evidence | assertion.create |
| View assertions | assertion.read |
| Export evidence data | export.data |
Example
A bank's Evidence Register holds 1,840 artefacts across a year.
A representative record:
| Field | Value |
|---|---|
| Title | Q1 2026 Privileged Access Recertification — Payments Platform Production |
| Description | Recertification of all privileged accounts on 63 in-scope systems. 58 systems completed; 5 deferred pending decommissioning, tracked under FND-2026-0044. Three accounts revoked. |
| Evidence date | 31 March 2026 |
| Linked to | CTL-2026-0044 Privileged Access Management; requirement A.5.18; activity ACT-2026-0117 |
| Assertions recorded | 58, one per completed system, freshness window 100 days |
| Review state | Accepted |
The description does the work. It states the population, the completion, the exceptions and where the exceptions are tracked — so a reviewer in nine months does not have to open the file to know what it says.
Troubleshooting
"I uploaded evidence but coverage did not change." No assertions were recorded from it. See "From artefact to assertion" above.
"Evidence shows as stale but we uploaded it last week." Freshness is measured from the evidence date, not the upload date. Check the evidence date on the record.
"I cannot link evidence to a requirement." Check that you hold evidence.upload and that the requirement is visible to you.
"An assessor questioned our evidence." The most common causes are missing dates, unstated scope and screenshots without attribution. See "What makes evidence good".