csrdcompliance Put me on the waitlist

Kennisbank

Where evidence gets scattered

Evidence doesn't arise in one place

An obligation is rarely fulfilled by a single department. Policy is written by legal affairs, executed by the business, checked by finance, and sometimes reassessed by an external party. Each of these steps leaves a trail: a document, an email, an approval, a log. That trail is the evidence. The problem doesn't arise because there is no evidence, but because no one knows exactly where it is.

Systems that don't talk to each other

Most organizations work with a combination of systems that weren't built for this purpose: an intranet for policy, an HR system for training, a procurement system for supplier declarations, a mailbox for correspondence with a regulator. Each system stores its own part of the story. None of these systems show the whole picture. Anyone who needs to demonstrate that an obligation has been fulfilled must first figure out which system holds the relevant evidence, and then whether that evidence is still current.

Dispersion increases with the size of the organization

For a single entity, this is already a challenge. For a group with multiple entities, locations, or countries, the problem grows accordingly. An obligation assigned at group level often needs to be demonstrated locally, and vice versa. What this means in concrete terms for what counts as evidence for an obligation within a group with multiple entities depends on how the group is structured and which entity files which report. The same question about dispersion itself comes back in where evidence gets scattered in a group with multiple entities, where the structure of the group itself becomes a factor.

Who needs to be able to find the evidence

Evidence that exists but cannot be found functions, in an audit, as evidence that does not exist. An auditor, regulator, or the board itself must be able to determine who was responsible for what and where the substantiation is located. That requires a fixed location per obligation, not a search through departments the moment the question is asked. How this findability is arranged in practice is described in how you store evidence so an auditor can find it.

Ownership doesn't automatically prevent dispersion

Appointing an owner per obligation doesn't automatically solve the problem of scattered evidence, but it does make it visible. An owner who knows they are responsible will go looking for the evidence that belongs to their task, and often discovers that it is spread across multiple systems or colleagues. That is the moment when dispersion becomes a problem that can be solved instead of a problem that goes unnoticed. What ownership actually entails, and why it is separate from who carries out the task, is discussed in who is the owner of an obligation.

Policy is not proof of practice

Another point at which evidence falls apart: the existence of policy says nothing about its execution. A document describing how a process should proceed is not evidence that the process actually proceeds that way. That requires a different kind of evidence, namely demonstrable execution: logs, spot checks, deviation reports. The difference between these two layers of evidence, and how you place them side by side, is explained on how you demonstrate that policy is also practice.

Structure as a counterbalance

To make scattered evidence manageable, a fixed overview is needed: per obligation, the owner, the evidence, and the control that demonstrates the process works. Without that structure, evidence remains scattered until someone needs it, and by then it is often too late to collect it in full. How such an overview is built, and what a control adds to it, is described on what a control matrix is.

What this means for the boardroom

The question of whether an organization is in control is not answered with a statement but with evidence that can be found at the right moment. As long as that evidence is scattered across departments and systems that each retain their own part, that question cannot be answered with certainty. Bringing together owner, evidence, and control per obligation is the step that makes this possible.

Collecting and keeping that evidence up to date is itself also work, spread across many small tasks: requesting documents, checking versions, updating overviews. The work scan from FTE TO AI calculates per task which part of it can be taken over by AI, so it becomes clear which part of this work can be automated and which part still requires human review.

Alpha 60de assistent van de Compliance Check

Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.