Evidence & traceability
Every answer shows its work.
An audit response is a claim. Eviqly attaches the proof to every claim — the report it came from, the policy it cites, and the date the data was pulled — and records who did what along the way.
The three parts of a source
- The report
- The system export, log, or document the fact was taken from — identified by name, version, and period covered.
- The policy
- The internal policy or procedure, down to the section, that the answer relies on.
- The pull date
- When Eviqly read the data. Evidence ages; the date lets a reviewer judge whether it still represents the control.
Transparent limitations
If the evidence does not support an answer, Eviqly does not fill the blank. The response is marked unsupported, the reason is stated — a missing period, a policy without thresholds, a log that cannot be tied to the review window — and the item becomes a gap with an owner.
The immutable trail
Who drafted, who confirmed, what evidence, when.
Drafted
Each draft is stamped with the evidence set it was generated from and the time of generation.
Confirmed
The named client owner who confirmed the answer, and when. Edits to a draft are recorded as new versions.
Closed
For gaps: what was provided, by whom, and the date the item moved to supported.
Signed
The reviewer’s identity, accreditation, and signing time. The record is append-only; nothing is overwritten.
Retention
Six years, on demand.
Signed reports, completion certificates, and their evidence trails are retained for six years and can be produced for examiners, sponsor banks, or partners at any time during that period.
See a full evidence pack.
We’ll walk you through a sample deliverable and the trail behind it.