Evidence Expectations
Define what type of proof a requirement or control needs.
AIRRP treats evidence as governed proof. It links evidence to requirements and controls, evaluates whether the retained content supports the claim, and preserves provenance for assessment and assurance reuse.
Uploading a policy or screenshot is not the same as proving a control. AIRRP’s evidence model is designed to retain the exact relevant material, evaluate whether it establishes the required outcome and fail closed when proof is insufficient.
Define what type of proof a requirement or control needs.
Process text, structured content and supported visual material.
Evaluate against retained spans or visual proof—not mere references or mentions.
Reuse governed evidence where scope and validity permit.
Track age, scope, ownership and supersession.
Preserve source, processing, evaluation and downstream usage.
Architecture diagrams, tables, data-flow diagrams, screenshots and other visual material can be material to a control decision. AIRRP’s document processing path can invoke visual interpretation where needed rather than pretending every document is plain text.
A document that references a DPIA, escalation path or backup process does not automatically prove that the required activity was performed or governed. AIRRP should confirm the claim against the retained proof before marking a requirement Met.
Approved evidence can support assessments, framework requirements, external questionnaires and governance reviews when scope, freshness and authorization align.
Collect less evidence, understand it better, and know exactly what it proves.