Evidence is the proof that a control actually operated — not that it exists on paper, but that it ran. In Comply, every piece of evidence lives in the Evidence module and is mapped to the control(s) it supports, so that when an auditor asks “show me that access reviews happened every quarter,” the answer is one click away instead of a week of scrambling.
This guide covers what good evidence looks like, how to add and map it in Comply, and how to keep it fresh so it survives an audit.
What counts as evidence
Auditors accept several kinds of proof. The strongest evidence shows a control operating repeatedly over a period, not a single moment:
- Generated artefacts — export files, logs, configuration snapshots, ticket exports. These are the gold standard because they are hard to fake and show real activity.
- System-of-record links — a live link to the Jira board, the IdP access report, or the MDM console. Better than a screenshot because it stays current.
- Screenshots — acceptable for point-in-time facts (e.g. a setting is enabled), but weak on their own for anything that must operate over time.
- Attestations — a signed statement that a process was followed. Use these to supplement, not replace, system evidence.
Rule of thumb: a screenshot from the day before fieldwork proves nothing about the prior three months. For period-of-time controls (SOC 2 Type II, ISO 27001 surveillance), collect evidence that spans the whole observation window.
Add a piece of evidence
- Go to Evidence → + New (or use Upload evidence from the global + New menu / ⌘K).
- Choose a source:
- File — drag in an export, PDF, or log bundle.
- Link — paste a URL to the live system of record.
- Connector — if you have an integration configured, evidence can be pulled automatically (see Automate collection below).
- Give it a clear title an auditor will understand (“Q2 2026 user access review — Okta”) and a short description of what it proves.
- Set the collected date and, for recurring evidence, a freshness cadence (e.g. every 90 days).
Map evidence to controls
Unmapped evidence is invisible to your readiness score and to auditors. Mapping is what turns a file into proof.
- Open the evidence record and use Map to controls.
- Select every control this artefact supports — one artefact often satisfies several (an access-review export can cover a SOC 2 CC6 logical-access control and an ISO 27001 Annex A access control).
- Save. The mapped controls now show this evidence on their Control detail page, and your framework readiness updates automatically.
Because mappings are many-to-many, resist the urge to re-upload the same file per framework. Upload once, map to all — one source of truth.
Keep evidence fresh
Stale evidence is the most common cause of audit findings. Comply tracks freshness so nothing silently expires:
- Each recurring control has a test cadence; evidence older than the cadence is flagged stale on the control and in the readiness view.
- The Inbox surfaces evidence that is due or overdue so collection becomes routine work, not a fire drill.
- Set realistic cadences: quarterly for access reviews, continuous for automated config checks, annually for policy sign-off.
Automate collection
The most reliable evidence is the evidence you never touch. Under Integrations, connect your identity provider, cloud, ticketing, and MDM. Connectors pull evidence on a schedule and map it to the linked controls automatically, so a large share of your evidence room stays current with zero manual effort. Reserve manual uploads for the things machines cannot see (board minutes, signed contracts, vendor reports).
DPDP note
Under India’s DPDP Act 2023, a Data Fiduciary must be able to demonstrate compliance — reasonable security safeguards, breach handling, and honouring data-principal rights (see §8). Treat DPDP obligations like any other control: attach the evidence that shows the safeguard operated (encryption config, breach drill records, DSAR fulfilment logs) and map it to the relevant DPDP requirements so your privacy posture is provable, not just asserted.
Checklist
- Every recurring control has evidence covering the full observation window.
- Evidence is mapped to all the controls it supports, across frameworks.
- Freshness cadences are set and the Inbox is clear of overdue items.
- Automated connectors cover everything a machine can produce.
- Titles are auditor-legible and dates are accurate.