Source
Approved record pathScope
Defined system boundaryPeriod
Relevant review windowControl
Linked objectiveOwner
Accountable collectorReviewer
△ Question openEvidence operations
Collect evidence with its context intact.
Route recurring requests, receive records from people or systems, link each item to the right control and period, and preserve the review trail behind every decision.
A file is not evidence until its relevance is understood.
Useful evidence needs source, scope, period, control relationship, and review context. ControlQuill keeps those fields close to the item.

Collected item
Receipt establishes arrival.
A source artifact or reference has entered the approved workflow with basic provenance.
Reviewed record
Review establishes context.
The item has been examined for the relevant scope, period, control relationship, questions, and follow-up.
Preserve the evidence lifecycle.
Request
State the control objective, expected record, owner, period, and due date.
Receive
Accept the item through the approved human or system workflow and retain source context.
Link
Associate the item with the relevant control, requirement, vendor case, training assignment, or audit request.
Review
Record relevance, completeness, exceptions, questions, and reviewer action.
Follow up
Route remediation or clarification to an owner with a traceable status.
Retain or dispose
Apply the organization's documented retention and access rules to the evidence record.
Use automation where the evidence pattern is stable.
A recurring system record may follow a defined intake path. A narrative decision, unusual exception, or changed scope still needs human evaluation.
Defined source
Expected record and metadata
Intake
Receipt and validation
Link
Control and period context
Human review fork
Relevance, exception, or changed scope
Give the assessor a reviewable trail.
Preserve the connection among the request, source record, control, relevant period, questions, changes, and final response. The independent assessor determines what is sufficient for the engagement.
Source
Approved internal record path
Period + control
Defined quarter · access review
Reviewer
One clarification routed to the owner
History
Receipt, review, question, response
Evidence questions
Does collected evidence automatically prove a control is effective?
No. Collection establishes that an item was received. Relevance, sufficiency, and control conclusions require review in the applicable scope and period.
Can evidence come from an API?
Use the API workflow to submit an approved record or reference with the source, control, period, and owner context needed for review. Supported objects, authentication, formats, and file handling require technical evaluation.
Can evidence be reused?
It may support more than one mapped requirement when the scope, period, and purpose align. Every use should remain reviewable.
Trace one repeated request
Start with evidence your team collects again and again.
We will map its source, metadata, owner, review, exception path, and final use.
Prepare an evidence-flow review