Evidence quality

What makes evidence sufficient

Coverage answers how much of a framework has evidence. Sufficiency answers whether that evidence actually holds up. A pile of present files is not the same as substantiated requirements — here is how to tell the difference.

Before an assessor or auditor accepts a piece of evidence, they weigh it along a handful of dimensions. Understanding these while you gather evidence — rather than at audit time — is the single biggest thing that turns a folder of documents into a defensible readiness position.

Relevance

The evidence addresses the specific requirement in question — the same control, the same obligation, the same scope — not an adjacent or general one.

What good looks like
A document that speaks directly to the requirement's intent, for the systems and period actually in scope.
Common gap
A generic policy attached to a control it never mentions, or evidence drawn from a system outside the assessment boundary.

Integrity & custody

The evidence is intact and its handling is accountable — you can show it has not been altered since it was produced, and who has held it.

What good looks like
An original export or signed record with a clear chain of custody, stored where changes are detectable.
Common gap
A screenshot with no source, a re-typed summary, or a file whose history nobody can account for.

Provenance

You know where the evidence came from, who produced it, and under what authority — its origin is traceable, not assumed.

What good looks like
A record whose author, source system and generating process are identifiable and appropriate to the claim.
Common gap
An artefact of unknown origin, or one attributed to a person or system without the authority to attest it.

Currency

The evidence is in date for the period being assessed — recent enough to reflect how the control operates now, within any validity window the requirement implies.

What good looks like
Evidence dated inside the assessment window, with a defined review or expiry cadence.
Common gap
A last-year access review, a superseded plan, or a point-in-time export presented as an ongoing state.

Completeness

The evidence covers the whole of what the requirement asks — all in-scope systems, all population, all of the control's parts — not a convenient subset.

What good looks like
Coverage across the full in-scope estate, with any exclusions stated and justified.
Common gap
A change log that shows standard deployments but omits emergency changes; a scan covering part of the asset inventory.

Effectiveness

The evidence shows the control is not just designed but actually operating — that the practice happened, repeatedly, and produced the intended outcome.

What good looks like
Records of the control running over time — tickets, logs, test results, sign-offs — not only the policy that describes it.
Common gap
A well-written procedure with no evidence anyone followed it; a control designed but never exercised.

Assessors weigh further, related dimensions too — approval attribution, applicable scope, and consistency across records. The six above are where most evidence is won or lost.

How Netallion helps

Netallion helps you collect, own, organise and track the currency of evidence against a framework’s control library, so these dimensions are visible while you prepare — not discovered at audit time. Our assessment methodology explains how evidence becomes a readiness conclusion.

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.

Turn evidence into a defensible position

Start with a free readiness kit to structure your evidence, then see how Netallion assesses whether it is sufficient.