Methodology
How Netallion assesses evidence
Evidence assurance and compliance readiness — not checklist compliance. Most tools collect and organise files. Netallion goes a step further on assessed engagements: it reads the content of submitted evidence against each applicable requirement, weighs whether that evidence is sufficient, and preserves the review history behind the conclusion.
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.
The pipeline
Evidence moves through six stages
The first two are live today. The assessment stages run on assessed engagements — the differentiated, requirement-level work that turns a pile of documents into a defensible readiness conclusion.
Evidence collected
Live todayEvidence hygiene (System A)
Live todayStages 3–5 run on assessed engagements. The methodology continues into requirement-level evidence assessment, per-requirement determinations, and recorded review provenance. These are delivered as part of an assessed engagement rather than a self-serve feature — talk to us about scoping one. What is live today is everything above: evidence collection, hygiene, and the change-controlled framework libraries.
Readiness conclusion
Boundary — liveTraceability
Byte-verified citations, integrity-manifested exports
A readiness result is only as trustworthy as your ability to trace it back to the evidence it rests on.
Evidence-linked findings (assessed engagements)
Audit-ready export package
Scoring
Fixed-denominator, blocker-precedence
On assessed engagements, readiness is scored against the full applicable requirement set, and mandatory blockers take precedence over any headline number — the scoring model is part of an assessed engagement. Ask us how scoring works for your framework.
The denominator is the whole applicable set
Lifecycle-aware currency
The assurance model
Two axes, plus a derived claim
Netallion keeps three things separate that lesser tools blur together — so a label always means exactly what it says.
| Axis | What it captures | Values |
|---|---|---|
| Axis A — review level | Who looked at the finding, and how. | R0 system → R1/R2 self-attested → R3 authorised assessor review |
| Axis B — readiness outcome | What the evidence says about the requirement. | sufficient / partial / insufficient / invalid / unable-to-verify |
| Axis C — derived assurance claim | The claim the two axes entitle you to. | self-assessed | reviewed | independent |
The Axis-C claim is derived, never typed. No one can select “Independent” from a menu; the platform resolves the highest wording the engagement has actually earned. A strong readiness outcome (Axis B) delivered by a system or self-attestation (low Axis A) resolves to self-assessed — it cannot borrow the credibility of a review that did not happen. A failed independence test auto-downgrades the claim to reviewed, and the wording cannot be overridden manually.
Boundaries
What this methodology is not
- Not certification, accreditation, or an accredited audit opinion.
- Not a guarantee of compliance or of passing an external audit.
- Not real-time or continuous compliance monitoring — assessment is of uploaded, periodic evidence.
- Coverage is not sufficiency: having evidence against a requirement is not the same as that evidence being judged sufficient.
See the methodology against your framework
Walk through how Netallion collects, checks and — on an assessed engagement — assesses your evidence against the requirements that matter.