Evidence
Evidence is what an auditor actually reviews: the artifacts that prove a control is really happening. Keel keeps evidence organized, connected to the controls it supports, and fresh enough to stand up at audit time.
Uploading evidence
Section titled “Uploading evidence”In Evidence, upload a screenshot, configuration export, report, or document. Each artifact lives in your workspace’s evidence library, where you can find it later and reuse it. Because one artifact often proves several things at once, evidence isn’t locked to a single control.
Linking evidence to controls
Section titled “Linking evidence to controls”Attach an artifact to the control (or controls) it supports. Thanks to the framework crosswalk, a control can satisfy requirements in several frameworks, so a single, well-chosen piece of evidence can improve your coverage across multiple standards at the same time. This is the practical payoff of collect once, comply everywhere: gather the proof once, and it counts everywhere the control applies.
The shape of that is easier to see than to read. Take a real case from Keel’s starter control set: the MFA enforcement setting exported from your identity provider, attached to the multi-factor authentication control. These are the frameworks in Keel’s catalog where that one control scores a requirement:
One evidence artifact, attached to one control, counted against the requirements each of those frameworks states for it — collected, labelled, and reviewed a single time.
Only the frameworks you have applied count toward your readiness, so how much of this a given workspace sees depends on your program. One thing to know when you map a clause to a control yourself: the clause picker lists the section and theme headings a framework uses to organize its requirements alongside the requirements themselves. Keel keeps a mapping you make to a heading, but scores nothing for it, because readiness is measured against the requirements underneath a heading rather than the heading itself. Map to the requirement if you want it to move your number. Your workspace is the source of truth for the actual mappings.
Keeping evidence fresh
Section titled “Keeping evidence fresh”Auditors want current proof, not a screenshot from two years ago. Keel tracks a review date on evidence so you can see at a glance what’s current, what’s expiring, and what’s already expired. Refresh aging artifacts before they lapse to keep your program audit-ready between formal reviews rather than scrambling right before one.
Know what to collect
Section titled “Know what to collect”Not sure what an auditor expects for a given framework? Use the framework-scoped “evidence to collect” guidance to see the kinds of artifacts each area calls for, so you’re gathering the right things instead of guessing.
AI: Review evidence for sufficiency
Section titled “AI: Review evidence for sufficiency”When you’ve attached an artifact, Keel’s AI “Review evidence” check reads it against what the control requires and tells you whether it’s likely sufficient, or what’s missing or weak. It’s an optional, credit-metered sanity check that catches gaps before an auditor does. Learn how credits work in AI tools & credits.
Next steps
Section titled “Next steps”- Evidence-readiness meter: see how audit-ready your evidence is at a glance.
- Frameworks & crosswalks: why one artifact can cover several frameworks.
- Trust Center: turn your posture into something prospects can see.