Skip to main content

Adding evidence to a control (Records)

Evidence is the proof that a control is in place. In ReFresh, each piece of evidence is a Record (a document, a policy, or a test) attached to the control it supports.

Written by Taylor Laing
  • Open a control and work through its evidence requirements.

  • Each control has one or more required evidence specifications describing what to provide.

  • Use Add Upload on a document requirement to upload a file or fill the provided template.

  • Evidence is saved as a draft first, then submitted for review.

  • Approved evidence counts toward the control's requirement and updates its status.

Records is the unified evidence model: Documents and Policies are unified into Records. A Record you attach here is the same object you can manage from the central Records hub at /app/records. See Records - documents, policies, and tests.

Where to add evidence

On a control's detail page, each evidence requirement describes what the document must cover. Use Add Upload on a requirement to open its document record, where you attach the file.

Adding an upload

Selecting Add Upload opens the document record (its Uploads tab). From there you either upload a file that satisfies the requirement or fill the provided template. Uploaded files appear in the Current Uploads list, each noting who submitted it and when.

The document record carries the evidence's status, renewal cadence, review state, and the frameworks it supports, so the effective and expiration dates track the control's renewal cadence. Save to draft first; draft items persist across page refreshes, so you can gather several before submitting.

Draft, review, approved

Evidence moves through a short workflow before it counts:

  1. Draft: saved but not yet submitted. Add several items to a draft and submit them together.

  2. Submitted for review: a reviewer approves the evidence or requests changes. See the Reviews article in the Consultation and reviews section.

  3. Approved: the Record now counts against the control's requirement, and the control's status recalculates.

Auto-linking from your Records

Records in your library automatically serve as evidence for the controls they cover. When a policy or document is updated and approved, the controls that reference it pick up the new version and recalculate their status; you don't have to re-attach it to each control by hand.

This is why the Records hub and the control library work as one system: manage a policy once, and every control it evidences stays current. See Records - documents, policies, and tests.

Did this answer your question?