Evidence Collection
Evidence is what backs up a control rating. Uploading a file and linking it to a control are two separate steps — this is deliberate, since one piece of evidence can support several controls independently. Only assessors can upload evidence or create/manage links.
Uploading evidence
From an engagement’s Evidence tab (.../evidence/upload):
| Field | Notes |
|---|---|
| File | Max size 50 MB. Accepted types: PDF, DOCX, XLSX, PNG, JPEG, CSV, plain text. The file’s actual content is verified against its claimed type (not just the file extension), so a renamed file will be rejected. |
| Evidence type | Must be an Active Evidence Type from the Control Library. |
| Description | Optional free text. |
An uploaded file’s own status is simply Active or Withdrawn.
Linking evidence to controls
From the same tab, link an uploaded evidence file to one or more controls. Each link is independent and carries its own review state:
| Review status | Meaning |
|---|---|
Pending |
Newly created, awaiting review. |
Approved |
A reviewer has confirmed this evidence sufficiently supports the linked control. |
Rejected |
A reviewer has determined this evidence does not support the control. |
Superseded |
Explicitly replaced by newer evidence — this never happens automatically; someone marks it superseded. |
Reviewing a link (typically a reviewer’s job) records a decision — approved or rejected — with an optional comment.
Freshness
Evidence freshness is calculated live, not stored, using the linked Evidence Type’s freshness window (default 12 months if none is set):
- Current — well within the freshness window.
- Approaching expiry — within 30 days of going stale.
- Stale — past the freshness window.
Stale or otherwise insufficient evidence links can’t be relied upon for a rating — see Ratings.
Next step
Once evidence is uploaded and linked, move to Ratings to record the control’s current maturity.