csrdcompliance Put me on the waitlist

Kennisbank

Evidence for an obligation: what an auditor accepts

An obligation that exists on paper is not yet an obligation that has been fulfilled. Between 'we have a policy' and 'we can show we are in control' lies a layer that is often skipped: evidence. And not every document that is stored somewhere counts as evidence.

Policy is not proof of execution

A policy document describes an intention. It states what an organisation wants to do, not what has actually happened. An auditor or supervisory authority does not ask about the policy, but about its outcome: was the risk assessment actually carried out, was the approval recorded, was the deviation reported at the moment it occurred. How that step from policy to practice is made demonstrable depends on the type of obligation and how a process is set up; how you show that policy is also practice addresses that distinction.

What evidence actually is

Evidence is a trail that records an action, a decision or a check at the moment it took place, with a date, a name and an outcome. An email in which a risk was reported. A minutes entry in which a board made a judgment call. A log file that shows a check was actually carried out, not just that it was scheduled. A signed declaration from a supplier. The common feature: it can be reconstructed afterwards who did what and when, without anyone having to retell it.

Whether something counts as evidence depends strongly on the obligation it relates to. A reporting obligation calls for a different kind of trail than a duty of care, and a duty of care calls for something different again than a reporting duty for incidents. There is no fixed list that gives the same answer for every obligation; what counts follows from the nature of the obligation itself and from what a supervisory authority has laid down about it.

Where evidence becomes scattered

In practice, evidence rarely originates in one place. A risk assessment sits in a spreadsheet at the first line. The approval sits in an email exchange with a manager. The final check sits in a system belonging to a third party. When an obligation needs to be demonstrated, someone has to gather these three trails back together — and that does not always succeed. As an organisation grows larger, has more departments or works with more external parties, the likelihood increases that evidence sits in a place no one remembers anymore. where evidence becomes scattered describes the patterns that occur most often here: handovers between departments, system changes, and processes that have been outsourced to an external party.

Findable for someone who did not create it

Evidence that cannot be found by anyone other than its creator does not function as evidence. An auditor, a new compliance officer or a supervisory authority must be able to follow a trail without the original author sitting next to them to explain it. That places requirements on where evidence is stored and how it is labelled: linked to the obligation it relates to, with a date and a responsible person, in a place that does not depend on one individual who happens to still be employed. how you store evidence so an auditor can find it addresses that setup.

Evidence without an owner is evidence without value

Every piece of evidence belongs to an obligation, and every obligation belongs to someone who can explain why the evidence is sufficient. Without that link, an archive of documents emerges of which no one knows any longer which obligation they were meant to demonstrate, or who was responsible for their quality. who owns an obligation describes why that assignment is not a formality, but the link that makes evidence usable at the moment it is asked for.

The link between obligation, owner, evidence and control

The four elements — obligation, owner, evidence, control — belong together in one overview, not scattered across departments and systems. That overview has a name: a control matrix. What exactly that matrix contains and how it is built is described at what a control matrix is. For a group with multiple entities or locations in different countries, this question becomes more complex, because evidence at one level is not automatically valid at another; what counts as evidence for an obligation within a group with multiple entities addresses that situation specifically.

What this delivers, and what it does not

This page describes what evidence is and where it goes wrong, not which evidence specifically suffices for your organisation. That depends on the obligation, the sector and the country in which an entity is established — and on the way national legislators have implemented a European rule. csrdcompliance.net points out that difference, but does not replace legal advice and gives no guarantee about an outcome with a supervisory authority.

The next step

Mapping out and getting evidence in order takes work: gathering trails, linking them to an obligation, labelling them so someone else can find them. Part of that work is repeatable and follows a fixed pattern, which makes it suitable for (partial) automation. The work scan from FTE TO AI calculates per task which part of that work can be taken over by AI, so that it becomes clear where people remain needed for judgment and where the gathering and organising of evidence can be supported. The Compliance Check from csrdcompliance.net is under construction; anyone who wants to be notified about this can sign up for the waiting list.

Alpha 60de assistent van de Compliance Check

Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.