Governance and assurance
Compliance Evidence overview
Generated compliance-oriented evidence summaries for audit preparation.
- Audience
- Analysts and above
- Required role
- Analyst
- Plan availability
- All plans
- Last reviewed
Compliance Evidence is a generated summary that assembles posture, findings, remediation, and audit signals into one compliance-oriented view. It supports audit and compliance preparation. It is not compliance certification and does not guarantee that your organisation meets any standard or framework.
Open it from Reports → Compliance Evidence (/dashboard/reports/evidence).
Purpose
Use Compliance Evidence when you need a structured snapshot of your workspace's security posture evidence for stakeholders, auditors, or internal assurance conversations. The report draws on live workspace data rather than uploaded files alone.
How it relates to other assurance areas
| Product area | Purpose |
|---|---|
| Governance & Controls | Track governance readiness and control-related workflows in the dashboard |
| Evidence Vault | Store and review tenant-managed evidence records and attachments |
| Compliance Evidence | Generated compliance-oriented summary from posture, findings, remediation, and audit signals |
| Configurable Reports | Build custom stakeholder reports that can link approved evidence |
Compliance Evidence complements the Evidence Vault. Upload policies, screenshots, and supporting documents in the Evidence Vault; use Compliance Evidence for an assembled posture and activity summary.
What the report includes
The generated view typically summarises:
- workspace scope (domains and assets in scope)
- posture score and confidence signals
- finding counts by severity and workflow status
- remediation progress (overdue, in progress, recently resolved)
- verification outcomes where available
- exposure priority items from recent scans
- recent significant audit actions in the workspace
Analysts and above can view the report. Sharing controls follow the same role rules as other report sharing features in your workspace.
Supported workflow
- Ensure domains are verified and scans are current.
- Review and triage findings and remediation in the dashboard.
- Open Compliance Evidence to review the assembled summary.
- Optionally share the report using approved report-sharing controls where your plan supports it.
- Upload supporting material to the Evidence Vault when auditors need original documents.
Limitations
- The report reflects data available in your workspace at generation time.
- It does not replace professional audit advice or formal certification.
- It does not provide penetration testing, malware scanning, or real-time monitoring.
- Coverage is limited to the external posture checks Cyber Health Score runs; it does not detect every possible vulnerability.
Disclaimer
This report provides security posture evidence to support audit and compliance preparation. It is not a certification or guarantee of compliance.
Related documentation
Related documentation
Return to the documentation home to browse all topics.
Back to documentation