Source

Approved record path

Scope

Defined system boundary

Period

Relevant review window

Control

Linked objective

Owner

Accountable collector

Reviewer

△ Question open

Evidence operations

Collect evidence with its context intact.

Route recurring requests, receive records from people or systems, link each item to the right control and period, and preserve the review trail behind every decision.

A file is not evidence until its relevance is understood.

Useful evidence needs source, scope, period, control relationship, and review context. ControlQuill keeps those fields close to the item.

An evidence intake station registers a source packet, period marker, owner marker, and clarification item.
Source Intake path retainedPeriod Review window attachedQuestion Human review receives the exception

Collected item

Receipt establishes arrival.

A source artifact or reference has entered the approved workflow with basic provenance.

Reviewed record

Review establishes context.

The item has been examined for the relevant scope, period, control relationship, questions, and follow-up.

Preserve the evidence lifecycle.

Request

State the control objective, expected record, owner, period, and due date.

Expectation defined

Receive

Accept the item through the approved human or system workflow and retain source context.

○ Source attached

Link

Associate the item with the relevant control, requirement, vendor case, training assignment, or audit request.

Relationship retained

Review

Record relevance, completeness, exceptions, questions, and reviewer action.

△ Review required

Follow up

Route remediation or clarification to an owner with a traceable status.

Owner assigned

Retain or dispose

Apply the organization's documented retention and access rules to the evidence record.

Policy governs

Use automation where the evidence pattern is stable.

A recurring system record may follow a defined intake path. A narrative decision, unusual exception, or changed scope still needs human evaluation.

Defined source

Expected record and metadata

Intake

Receipt and validation

Link

Control and period context

Human review fork

Relevance, exception, or changed scope

Give the assessor a reviewable trail.

Preserve the connection among the request, source record, control, relevant period, questions, changes, and final response. The independent assessor determines what is sufficient for the engagement.

Evidence questions

Does collected evidence automatically prove a control is effective?

No. Collection establishes that an item was received. Relevance, sufficiency, and control conclusions require review in the applicable scope and period.

Can evidence come from an API?

Use the API workflow to submit an approved record or reference with the source, control, period, and owner context needed for review. Supported objects, authentication, formats, and file handling require technical evaluation.

Can evidence be reused?

It may support more than one mapped requirement when the scope, period, and purpose align. Every use should remain reviewable.

Trace one repeated request

Start with evidence your team collects again and again.

We will map its source, metadata, owner, review, exception path, and final use.

Prepare an evidence-flow review