Skip to main content

Uploading evidence to a control

Evidence is the proof a control is in place, uploaded to the control's Evidence tab. Each evidence item has an effective date, expiration date, and renewal cadence inherited from the control.

Written by Harrison Kennedy

Evidence is the proof a control is in place, uploaded to the control's Evidence tab. Each evidence item has an effective date, expiration date, and renewal cadence inherited from the control.

  • Open the control and click into the Evidence tab

  • Each control has one or more required evidence specifications

  • Click Add Evidence Item to upload a new document or attach a link

  • Evidence is saved as Draft first, then submitted for review

  • Supported file types: PDF, DOCX, TXT, MD up to 500MB per file


Where to upload evidence

From a control's detail page, the Evidence tab shows the evidence items required (with a description of what each item should cover). Each evidence specification has an Upload Evidence button.


Adding an evidence item

Click Add Evidence Item on the control's evidence tab, or use the Add Evidence button on a document detail page. The Add Evidence Item dialog opens with these fields:

Field

What to enter

Evidence Type (required)

Document Upload, link, or template

Title (required)

A short title for the evidence

Description

What the evidence demonstrates

File (required for Document Upload)

Click to upload or drag and drop. Supported types: PDF, DOCX, TXT, MD up to 500MB

Effective Date

When the evidence takes effect (defaults to today)

Expiration Date

When the evidence expires (defaults based on renewal cadence)

Click Add to Draft to save. Items in draft persist across page refreshes.


Draft and submitted states

Evidence flows through two states before it counts as Complete:

  1. Draft: items are saved but not yet submitted. Add multiple items to a draft, then submit them as a batch.

  2. Submitted for review: a reviewer approves or requests changes (see "Conducting a control effectiveness review", 4.5).

Once approved, evidence appears under Current Evidence on the document detail page and counts against the control's evidence requirement.


Auto-linking from policies and documents

Documents and policies in your library automatically serve as evidence for the controls they cover. When a policy is updated and approved, the controls that reference it pick up the new version and recalculate status.

For more on managing the library, see "Managing the policy and document library" (4.10).


File types and size limits

  • Supported file types: PDF, DOCX, TXT, MD

  • Maximum file size: 500 MB per file

  • Multiple files: upload as separate evidence items if a single requirement covers multiple files

If a file fails to upload, see "Evidence and document upload issues" (9.3).


Related articles

  • The control library (4.2)

  • Assigning control owners and managing renewals (4.3)

  • Conducting a control effectiveness review (4.5)

  • Managing the policy and document library (4.10)

  • Evidence and document upload issues (9.3)

Did this answer your question?