Skip to content

Evidence & findings

Evidence and findings are where governance stops being a claim and becomes something you can prove. Gamut treats both as first-class objects, captured as work happens rather than gathered in a rush at audit time.

Evidence is any artefact that supports a governance claim, a document, export, log, screenshot or record. In Gamut, evidence is managed as a request-based workflow rather than a folder of files. An evidence request carries:

  • A request title and description, tied to a specific control.
  • The expected evidence type, so the owner knows what will satisfy it.
  • A named owner and due date.
  • A status as it moves from requested to fulfilled.
  • A quality rating and review notes, so weak or missing evidence is visible rather than assumed.

Linking evidence to controls is what creates traceability: a reviewer can move from a control to the evidence behind it without hunting through shared drives. And because requests are tied to controls and owners, the evidence base builds continuously as governance work happens, instead of being chased at the end of a cycle.

A finding records a gap, deficiency or exception identified during assessment, control testing or audit. Each finding is a structured record:

  • A title, description and finding category.
  • A severity: low, medium, high or critical.
  • A root cause and a recommendation.
  • A management response, a named owner and a target date.
  • A status as it moves toward closure, with closure notes, a validated by and a validated date so closure is verified, not just asserted.
  • Links to the control test and evidence request it arose from.

Recording findings honestly is more valuable than an unsupported pass: it gives leadership a true picture and gives reviewers confidence that governance is real.

Remediation is the closure path for a finding. Keeping remediation visible, with an owner, a target date and a validated closure, turns findings from a list of problems into a managed improvement programme, and gives the Improve stage of the lifecycle something concrete to track over time.

Evidence and findings complete the chain that makes Gamut defensible:

control → control test → evidence request → finding → remediation → validated closure

Any conclusion in a report can be followed back through this chain to the underlying records, and every change along it is captured in the audit log.

  1. From a scored control in an assessment, request evidence: set the control reference, what is needed, an owner and a due date. Requests track from open to satisfied.
  2. Attach evidence to the request, or record it directly against the control.
  3. Run a control test where you need to prove a control operates: capture the objective, procedure, sample method and size, the design and operating effectiveness scores, the result, and any exceptions.
  4. Where there is a gap, raise a finding: severity, root cause, recommendation and management response, linked back to the control, test and system.
  5. Convert a finding into a remediation item and track it to closure.

Owners and due dates make evidence and remediation overdue-trackable, and every step is captured in the audit log.