"Evidence pack" describes a task, not a feature. You compile it by exporting a few reports and records into one bundle for handover.
The board report is the most comprehensive single document to lead with
Supplement it with on-demand reports for area-specific deep dives
Pull supporting evidence from Records (
/app/records)Reference the audit trail to show continuous management, not a one-off effort
Export everything as PDF and bundle it for handover
Putting a pack together
Generate the latest board report as the cover document (see The Quarterly Board Report).
Generate on-demand reports for anything the regulator has specifically flagged: incidents, the risk register, or a framework-specific compliance posture (see Generating an on-demand report).
Pull the relevant records from Records (
/app/records), filtered by framework. Records is where your documents and policies live; test evidence sits on each control's detail page (Documents · Policies · Tests).Reference the audit trail in your cover note (see Using the audit trail (activity log)) to show a regulator that your management is continuous, not point-in-time.
Export everything to PDF and bundle the files into a single folder for handover.
What regulators are looking for
Inspecting psychosocial compliance, a regulator typically wants to see:
A clear narrative of how you manage psychosocial risk: the board report
Evidence that hazards have been identified and assessed: the risk register and surveys
Evidence that controls are in place: Controls and the evidence in Records
Evidence that incidents are investigated and acted on: Investigations and Hierarchy-of-Controls assessments
Evidence that workers are consulted: Consultations
A demonstrable audit trail across all of the above
ReFresh's structure already maps to these expectations. The evidence pack is simply the formatted handover of what the platform is holding.
Generate your board report close to the inspection date so the regulator's reference point reflects your current posture.
