Evidence is the proof a control is in place, uploaded to the control's Evidence tab. Each evidence item has an effective date, expiration date, and renewal cadence inherited from the control.
Open the control and click into the Evidence tab
Each control has one or more required evidence specifications
Click Add Evidence Item to upload a new document or attach a link
Evidence is saved as Draft first, then submitted for review
Supported file types: PDF, DOCX, TXT, MD up to 500MB per file
Where to upload evidence
From a control's detail page, the Evidence tab shows the evidence items required (with a description of what each item should cover). Each evidence specification has an Upload Evidence button.
Adding an evidence item
Click Add Evidence Item on the control's evidence tab, or use the Add Evidence button on a document detail page. The Add Evidence Item dialog opens with these fields:
Field | What to enter |
Evidence Type (required) | Document Upload, link, or template |
Title (required) | A short title for the evidence |
Description | What the evidence demonstrates |
File (required for Document Upload) | Click to upload or drag and drop. Supported types: PDF, DOCX, TXT, MD up to 500MB |
Effective Date | When the evidence takes effect (defaults to today) |
Expiration Date | When the evidence expires (defaults based on renewal cadence) |
Click Add to Draft to save. Items in draft persist across page refreshes.
Draft and submitted states
Evidence flows through two states before it counts as Complete:
Draft: items are saved but not yet submitted. Add multiple items to a draft, then submit them as a batch.
Submitted for review: a reviewer approves or requests changes (see "Conducting a control effectiveness review", 4.5).
Once approved, evidence appears under Current Evidence on the document detail page and counts against the control's evidence requirement.
Auto-linking from policies and documents
Documents and policies in your library automatically serve as evidence for the controls they cover. When a policy is updated and approved, the controls that reference it pick up the new version and recalculate status.
For more on managing the library, see "Managing the policy and document library" (4.10).
File types and size limits
Supported file types: PDF, DOCX, TXT, MD
Maximum file size: 500 MB per file
Multiple files: upload as separate evidence items if a single requirement covers multiple files
If a file fails to upload, see "Evidence and document upload issues" (9.3).
Related articles
The control library (4.2)
Assigning control owners and managing renewals (4.3)
Conducting a control effectiveness review (4.5)
Managing the policy and document library (4.10)
Evidence and document upload issues (9.3)