Skip to content

Evidence

Evidence library in Keel

Evidence is what an auditor actually reviews: the artifacts that prove a control is really happening. Keel keeps evidence organized, connected to the controls it supports, and fresh enough to stand up at audit time.

In Evidence, upload a screenshot, configuration export, report, or document. Each artifact lives in your workspace’s evidence library, where you can find it later and reuse it. Because one artifact often proves several things at once, evidence isn’t locked to a single control.

Attach an artifact to the control (or controls) it supports. Thanks to the framework crosswalk, a control can satisfy requirements in several frameworks, so a single, well-chosen piece of evidence can improve your coverage across multiple standards at the same time. This is the practical payoff of collect once, comply everywhere: gather the proof once, and it counts everywhere the control applies.

The shape of that is easier to see than to read. Take a real case from Keel’s starter control set: the MFA enforcement setting exported from your identity provider, attached to the multi-factor authentication control. These are the frameworks in Keel’s catalog where that one control scores a requirement:

MFA enforcement settingfrom your identity providerMulti-factor authenticationISO/IEC 27001A.8.5SOC 2CC6.1NIST CybersecurityFrameworkPR.AA-03PCI DSS8.4, 8.5HIPAA164.312(d)NIST SP 800-1713.5.2, 3.5.3, 3.5.4NIST SP 800-53IA-2, IA-2(1), IA-2(2), IA-2(8), IA-11CIS CriticalSecurity Controls6.3, 6.4, 6.5GDPRArt.32(1)COPPA312.8(b)(3)SOX (Sarbanes-Oxley)Section 404P11

One evidence artifact, attached to one control, counted against the requirements each of those frameworks states for it — collected, labelled, and reviewed a single time.

Only the frameworks you have applied count toward your readiness, so how much of this a given workspace sees depends on your program. One thing to know when you map a clause to a control yourself: the clause picker lists the section and theme headings a framework uses to organize its requirements alongside the requirements themselves. Keel keeps a mapping you make to a heading, but scores nothing for it, because readiness is measured against the requirements underneath a heading rather than the heading itself. Map to the requirement if you want it to move your number. Your workspace is the source of truth for the actual mappings.

Auditors want current proof, not a screenshot from two years ago. Keel tracks a review date on evidence so you can see at a glance what’s current, what’s expiring, and what’s already expired. Refresh aging artifacts before they lapse to keep your program audit-ready between formal reviews rather than scrambling right before one.

Not sure what an auditor expects for a given framework? Use the framework-scoped “evidence to collect” guidance to see the kinds of artifacts each area calls for, so you’re gathering the right things instead of guessing.

When you’ve attached an artifact, Keel’s AI “Review evidence” check reads it against what the control requires and tells you whether it’s likely sufficient, or what’s missing or weak. It’s an optional, credit-metered sanity check that catches gaps before an auditor does. Learn how credits work in AI tools & credits.