๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Evidence Library

Keep every file and record that proves your controls work in one place, reviewed, linked to controls and tracked for expiry.

Where to find it
Compliance (GRC) โ€บ Evidence
Who can use it
Anyone with a GRC role that can view compliance data; adding, changing and linking evidence need a role that can edit; reviewing needs a role that can approve; deleting and exporting need the matching permissions
Plan
Compliance (GRC) platform
For
Everyone

What the page is for

The Evidence library holds the files and records that show your controls are working: policies in action, screenshots, reports, test results and exports. One item can support many controls. Every stored file is encrypted when it arrives and gets a SHA-256 fingerprint, so you can prove later that it has not changed.

Evidence comes from several places: files you upload here, files sent in through evidence requests, assessments, and automated records such as the device inventory. For automated evidence from Microsoft 365, endpoint protection, backups and the agents, use Automatic Checks, which tests live data.

Each item can be reviewed (accepted or rejected with a note), given an owner and an expiry date. Items expiring soon are flagged so a replacement can be collected before the control shows a gap.

What you see

The Evidence Library page, with the header actions, summary tiles, filters and saved views, evidence table and add evidence numbered 1 to 5.
The Evidence Library page. Numbers match the list below.
  1. Header actions: Request evidence from someone, Export XLSX, Record device inventory and Add evidence.
  2. Summary tiles: All evidence, Needs review, Accepted, Expiring in N days, Expired and From requests. Click a tile to filter.
  3. Filters and saved views: Search, Control, Type, Review, Expiry, Source, Owner and Per page, with Clear and Saved views.
  4. Evidence table: Evidence, Controls, Type, Source, Review, Collected, Expires, Owner and Actions, with tick boxes for bulk editing.
  5. Add evidence dialog: File, Title, Type, Controls it supports, Description, Collected on, Expires on and Owner.

How to add evidence

  1. Select Add evidence.
  2. Choose the File. Large files are sent in pieces and resume if the connection drops.
  3. Enter a Title, choose a Type, and pick the Controls it supports. The first control chosen is the primary one.
  4. Add a Description (what it shows and where it came from), Collected on, Expires on (leave blank if it does not expire) and Owner.
  5. Select Save evidence.

How to review evidence

  1. Click the Needs review tile.
  2. Open an item and check the file (use Download).
  3. Select Accept, or Reject with a note (a note is required to reject).
  4. Reviewing evidence you collected yourself needs a reason that auditors can read, and is only possible where your company allows self-approval.

How to edit many items at once

  1. Tick the items in the table (only items on the current page can be selected).
  2. Select Edit the selected evidence.
  3. Change the Owner, Expiry date, Link them all to one more control or Review status.
  4. Select Review the change, check the summary, and confirm with Yes, change them.

How to record the device inventory as evidence

  1. Select Record device inventory.
  2. Choose the Control it supports (for example an asset inventory control).
  3. Select Record it. Lavawall counts the devices its agent reports for your company, by operating system and how many were seen in the last 30 days, and saves the result as dated evidence.

How to save a filtered view or export the index

  1. Set the filters you want, open Saved views and save them with a Name.
  2. Tick Open this view by default when I come to Evidence or Share it with everyone in this company if needed, then select Save the view.
  3. Select Export XLSX to download the evidence index as a spreadsheet.

Tips

  • Changing the expiry date of accepted evidence, or linking it to a new control, sends it back for review.
  • The expiry warning period comes from Evidence expiry warning (days) on Compliance Settings.
  • Search accepts titles, file names, controls, email addresses and SHA-256 fingerprints.
  • If evidence requests are waiting, a banner offers Review them.
  • By default, the control picker lists the controls in the frameworks you have adopted. Tick Show every control when you need one outside them.

Troubleshooting

  • "Files cannot be uploaded until it is." Evidence storage is not ready for your company yet. Contact support.
  • "This company has adopted no frameworks yet, so the whole control library is listed." Adopt a framework to narrow the control picker.
  • Some items were left alone after a bulk change. Evidence you collected yourself is skipped in bulk reviews; review it one at a time with a reason.
  • "Your GRC role does not include viewing evidence." Ask a GRC administrator for a suitable role.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.