Controls And Evidence

Use This Doc For

Purpose

A control describes the preventive, detective, or corrective measure used to address one or more obligations. Evidence is the dated proof that a control or obligation was actually addressed. Keeping the two distinct prevents a stored document from being mistaken for an operating control.

Before You Start

Record Control Coverage

  1. Create or open the control at /compliance/controls.
  2. Describe the control objective and how it operates. Do not mark it implemented merely because it is planned or documented.
  3. Link the control to every obligation it genuinely addresses. One control can support obligations across multiple frameworks.
  4. Assess effectiveness separately from implementation. An implemented control can still be partially effective, ineffective, or not assessed.
  5. Review linked risks and the next review date.

The Controls List, Grid, and Board views all begin with active controls. In Grid or Board, choose All controls beside the view controls to include inactive history. The scope is part of the URL, so a shared or refreshed link keeps the intended dataset.

Record Evidence

  1. Create an evidence record with a clear title and evidence type.
  2. Link it to the relevant obligation, control, or both.
  3. Record who collected it, when it was collected, the file reference, and any retention date.
  4. Open the saved record and confirm that another reviewer can follow the link and understand what the artifact proves.

Evidence records are immutable. If evidence is wrong or stale, use supersede to create a replacement and retire the prior record. The supersession link preserves the audit trail. A retention date is recorded context; it is not proof that an external file has been retained or deleted.

What Runs On Its Own

What it does

Control reviews are watched, not just recorded. The obligation assurance watch works out when each active control is next due for review and raises a finding on the assurance ledger when that date falls inside the next 30 days, or has already passed.

It reads the review date the way you would:

Recurrence words it understands are the ordinary ones: daily, weekly, monthly, quarterly, semi-annual, annual, biennial. Free text it does not recognise is not guessed at — the control is reported as having no computable next date instead.

When it runs

Daily at 05:40 UTC, looking 30 days ahead. It appears on /admin/scheduled-jobs as Obligation assurance watch, where the cadence is editable and a run-now is available.

The compliance specialist reads the findings and reports them to you on its Proactivity setting — weekly at Balanced, daily at Assertive.

How it stays current

Every run re-derives the due date from the current record, so recording a review today moves the next date tomorrow morning and closes the finding. Findings are keyed to the control and its due date, so a re-run updates rather than duplicates, and a control whose review has been completed drops off the list on the next sweep.

What it will not do

What you must do

Decisions And Consequences

What To Watch

Recovery

For a mistaken relationship, unlink only the relationship and attach the record to the correct obligation or control. For mistaken evidence, supersede it with a corrected record and explain the replacement. For an overstated control, change its implementation or effectiveness state and create owned remediation rather than leaving the posture signal artificially high.