Skip to main content

The Evidence Module

Overview

The Evidence module is your central hub for managing compliance documentation. It gives evidence items their own lifecycle, metadata, and role-based permissions, allowing you to link a single piece of evidence across multiple controls to simplify audits.


How to Access the Evidence module

You can access the Evidence module from the left-hand sidebar menu through Compliance > Evidence.

From here, you will be able to access all your evidence, filter by key fields, or create custom views to organize your data. You can learn how to do this in our article about Custom Views.


How to Create a new Evidence Record

Click Add evidence in the top-right corner to create a new evidence. Creating an evidence record sets up the requirements and instructions for submission; it does not upload the file itself.

You should use this form to fill in the evidence metadata such as a description and submitter instructions. This step configures the evidence details, not the specific fields required during submission.

As a starting point, you will find the following default fields:*

  • Title (Compulsory)

  • Submission instructions (Optional)

  • Validity period (Compulsory)

  • Type (Compulsory)

  • Folders (Optional)

  • Responsible users (Optional)

Inside of the Type field, you will find four options:

  • File: The submitter uploads a document directly to the platform.

  • Link: The submitter provides a URL to an external location (e.g., Google Drive or SharePoint).

  • Text: The submitter types information directly into a text box.

  • Data connections: Links directly to an asset already in the platform (e.g., a policy in the Policies module).

After entering the required information, click Create. The new evidence will appear in your evidence list.

* You can configure additional custom fields in Settings. To learn how, see How to configure Evidence below.


How to Submit an Evidence

After defining your evidence, users can complete an evidence submission to provide proof that the control is operating effectively.

You can learn how to do it in our Evidence submissions article.


How to Configure Evidence

Go to Settings > Compliance > Evidence.

From here, you can create two types of custom fields:

  • Evidence custom fields: Configure the custom fields that appear on evidence records. These fields are separate from submission fields and allow you to capture additional information about the evidence itself. These are the fields that you will see when initially creating an evidence.

  • Submission custom fields: These are the fields that the person uploading or filling in the evidence submission will have to fill in.

You can read more about custom fields in our Custom Fields article.

You will also be able to create Folders to organise your evidences, create Connections to other elements and configure your Data Retention settings for this module.


How to Connect Evidence to Controls

While you would normally use Connections to link elements inside of Formalize (you can see how here), the connection between evidences and controls works slightly differently.

You can connect evidence to their corresponding controls in two ways:

From the control:

  • Go to Frameworks and select the specific control to which you want to connect the evidence.

  • In the Evidence section on the right panel, click Add.

  • Choose whether to link an existing item or create a new one:

    • Connect existing evidence: View your evidence list and toggle on all items that apply to this control, then click Save.

    • Set up new evidence: Set up a new item if it hasn't already been created in the Evidence module.

  • Once saved, the connected items will appear in the control's Evidence section along with their current status and expiration date.

From the evidence

  • Go to Evidence and select the item you want to link.

  • Click Options > Edit.

  • Click the Data connections field and select the applicable controls from the drop-down menu.

  • Click Save.


Common Questions

  1. If a policy is considered a type of Evidence, how should I reflect this inside of Formalize?


    If a policy acts as evidence for a control, you can link it in two ways within Formalize:

    • Option 1: Direct Connection (Quickest)

      Link the policy directly to the control as a connection. This creates a straightforward, direct link between the policy and the control.

    • Option 2: Via an Evidence Item (Best for Tracking)

      Create a new evidence item with the type Data connection, then link this evidence to the policy through a connection. While this adds an extra step, it allows you to assign a Validity period to the evidence (for example, to track the policy's annual review cycle).

  2. Can I link an evidence to multiple controls?

    Yes, a single evidence item can be linked to multiple controls. This is why we recommend managing your evidence in the Evidence module rather than uploading files directly to individual controls. Managing evidence centrally ensures you only need to upload and update proof once across all related controls.

  3. How do I unlink an evidence from a control?

    You can unlink evidence by following the same steps used to connect it—simply deselect the item:

    • From a control: Go to the control's Evidence section, click Add, toggle off the unwanted evidence item, and click Save.

    • From the evidence item: Open the item in the Evidence module, click Edit, and remove the control from the Data connections field.

  4. Can I use Connections to connect controls and evidences like in the rest of modules, instead of the Evidence section?

    Yes. Since Connections are fully customizable, you can create a custom connection between controls and evidence.

    Note: If you link controls and evidence via a custom Connection, this link will not automatically appear in the dedicated Evidence section on the control page.
    ​​


We hope this article was helpful!


If you have any additional questions, please reach out to us via chat in the bottom right corner of the page - our team is always happy to assist you further.

Did this answer your question?