Skip to main content

How evidence quality and freshness work

Evidence is the currency of the whole platform. A control is only as convincing as the proof behind it; a compliance score is only as trustworthy as the evidence under its controls; an auditor believes a claim only when the artifact holds up. So SolveGRC treats every piece of evidence as a first-class object with two properties that decide how much weight it can carry: quality and freshness.

Quality — is this proof actually strong?

The moment anything becomes evidence — a document you upload, an approved questionnaire answer, a cloud finding, a linked artifact — SolveGRC scores it, automatically, at birth. Nothing sits unscored. Quality is a read on how much a reasonable reviewer should trust the artifact, along a few plain dimensions:

  • Is it complete? A whole policy is stronger than a screenshot of one clause.
  • Is it attributable? Proof tied to a source, an owner, and a date beats an anonymous file.
  • Is it recent? A configuration exported last week says more about today than one from two years ago.
  • Is it the right kind of proof? A tested control result is stronger than an assertion that a control exists.

You see the result as a quality read on the evidence itself — including a dimension-by-dimension breakdown — so a weak artifact is visibly weak before you lean on it, not after an auditor pushes on it.

Freshness — proof decays, and the platform notices

Evidence does not stay true forever. An access review from last quarter, a penetration test from last year, a policy last approved three cycles ago — each was strong once and is weaker now. SolveGRC tracks the age of every artifact and, on a regular sweep, marks aging evidence stale.

Stale is not the same as deleted. A stale artifact still exists and still tells a history; it just stops counting as current proof, and it surfaces as work: this needs refreshing. The point is that proof cannot quietly rot behind a green number. If something your compliance rests on has gone stale, you find out from SolveGRC before you find out from an auditor.

What quality and freshness do downstream

Because evidence feeds controls, and controls roll up into frameworks, these two properties ripple outward:

  • Weak or missing proof shows up as a soft spot in the control it backs, and in the framework position above it.
  • Stale proof surfaces as a refresh task and lowers your confidence in the claims resting on it.
  • Strong, fresh proof is what lets a control — and everything crosswalked to it — stand on its own when someone tests it.

This is why the platform pushes you to link real artifacts rather than assert compliance: an assertion carries no quality and never refreshes; an artifact does both.

Handing evidence over — the evidence package

Strong, fresh evidence is worth little if you cannot hand it to the people who need to see it. When you have to prove something to someone outside your team — an auditor doing fieldwork, a customer doing due diligence — you do not give them a login to your platform. You give them an evidence package: a bundle of specific artifacts, gathered for a specific purpose, at a specific moment.

A package earns its keep in two ways:

  • It is scoped. It holds exactly the evidence relevant to the request and nothing else. The auditor sees the access-review records they asked for — not your entire locker.
  • It is fixed in time. Finalizing a package (you may see this called sealing it) locks its contents. It becomes a snapshot: this is what we handed over, on this date. Later changes to the underlying evidence do not alter what was already delivered.

That second property is what makes a package defensible. An auditor's opinion is about a fixed body of evidence, and locking the package guarantees that body did not shift after the fact. Months or years later you can point to the exact package you delivered and show precisely what was in it.

One safeguard sits in front of every handover: evidence only leaves in a package once it has been cleared for external release, and files that came from outside sources must additionally pass a safety screen first — so nothing unreviewed or unscanned reaches an outside party. And because a package draws from the same quality-scored, freshness-tracked evidence as everything else, it is only as strong as what you put in it. That is one more reason to keep your evidence strong and current before an audit, not during one.

What this means for you

  • Link proof, don't just claim it. A linked artifact is measurable and refreshable; a checkbox is neither.
  • Watch the stale queue. Refreshing aging evidence is the cheapest way to keep a score honest and defensible.
  • Reuse strong evidence. One good artifact can back many controls across many frameworks — see crosswalks.
What we don't expose

You see each artifact's quality, its dimensions, and its freshness. The exact weighting that combines those dimensions into a single quality read stays internal — so the signal is honest and consistent across every tenant, and no one can game it by reverse-engineering the formula.