Methodology

How Netallion assesses evidence

Evidence assurance and compliance readiness — not checklist compliance. Most tools collect and organise files. Netallion goes a step further on assessed engagements: it reads the content of submitted evidence against each applicable requirement, weighs whether that evidence is sufficient, and preserves the review history behind the conclusion.

10 supported frameworks523 requirement-level criteriaversioned, change-controlled control libraries

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.

The pipeline

Evidence moves through six stages

The first two are live today. The assessment stages run on assessed engagements — the differentiated, requirement-level work that turns a pile of documents into a defensible readiness conclusion.

Stage 1

Evidence collected

Live today
You collect and organise evidence in the platform: each item has an owner, a type, and an expiry where relevant. Every uploaded file is malware-scanned before processing, fail-closed, and tenant data is isolated at both the application and database layers — proven by continuous-integration isolation tests on every change.
Stage 2

Evidence hygiene (System A)

Live today
System A reports evidence status / hygiene — whether an item is present, current, expired, or missing against the framework you are working toward. It is a metadata view: it tells you what evidence exists and whether it is in date. It does not read the contents of a document or judge whether that content satisfies a requirement. Evidence status / hygiene is never presented as evidence-assessed readiness.

Stages 3–5 run on assessed engagements. The methodology continues into requirement-level evidence assessment, per-requirement determinations, and recorded review provenance. These are delivered as part of an assessed engagement rather than a self-serve feature — talk to us about scoping one. What is live today is everything above: evidence collection, hygiene, and the change-controlled framework libraries.

Stage 6

Readiness conclusion

Boundary — live
The result is a readiness conclusion against a defined scope, labelled with the highest review level it actually reached — never above it. A self-assessed result is never dressed up as reviewed; a reviewed result is never dressed up as independent; and nothing Netallion produces is a certificate. See the provenance ladder.

Traceability

Byte-verified citations, integrity-manifested exports

A readiness result is only as trustworthy as your ability to trace it back to the evidence it rests on.

Evidence-linked findings (assessed engagements)

On assessed engagements, each finding is tied back to the evidence it relied on so a reviewer can trace any determination to its source. This traceability is part of an assessed engagement.

Audit-ready export package

The export package — readiness report, evidence index, Statement of Applicability, and an audit-ready ZIP with a SHA-256 integrity manifest — is a live capability today. (The contents of an assessed report depend on activation; the packaging and integrity manifest are available now.)

Scoring

Fixed-denominator, blocker-precedence

On assessed engagements, readiness is scored against the full applicable requirement set, and mandatory blockers take precedence over any headline number — the scoring model is part of an assessed engagement. Ask us how scoring works for your framework.

The denominator is the whole applicable set

Coverage is not sufficiency. Having evidence against a requirement is not the same as that evidence being judged sufficient — and gaps are counted, not hidden.

Lifecycle-aware currency

A readiness conclusion is only as current as the evidence beneath it. On assessed engagements, requirements are reopened for reassessment when the evidence they depend on lapses or is replaced.

The assurance model

Two axes, plus a derived claim

Netallion keeps three things separate that lesser tools blur together — so a label always means exactly what it says.

AxisWhat it capturesValues
Axis A — review levelWho looked at the finding, and how.R0 system → R1/R2 self-attested → R3 authorised assessor review
Axis B — readiness outcomeWhat the evidence says about the requirement.sufficient / partial / insufficient / invalid / unable-to-verify
Axis C — derived assurance claimThe claim the two axes entitle you to.self-assessed | reviewed | independent

The Axis-C claim is derived, never typed. No one can select “Independent” from a menu; the platform resolves the highest wording the engagement has actually earned. A strong readiness outcome (Axis B) delivered by a system or self-attestation (low Axis A) resolves to self-assessed — it cannot borrow the credibility of a review that did not happen. A failed independence test auto-downgrades the claim to reviewed, and the wording cannot be overridden manually.

Boundaries

What this methodology is not

  • Not certification, accreditation, or an accredited audit opinion.
  • Not a guarantee of compliance or of passing an external audit.
  • Not real-time or continuous compliance monitoring — assessment is of uploaded, periodic evidence.
  • Coverage is not sufficiency: having evidence against a requirement is not the same as that evidence being judged sufficient.

See the methodology against your framework

Walk through how Netallion collects, checks and — on an assessed engagement — assesses your evidence against the requirements that matter.