Platform
Audit & Controls

Evidence Management

Collect, preserve and reuse assurance evidence once

A central, integrity-preserving store for assurance evidence — control tests, audit workpapers, attestations, policy acknowledgements and supporting documents — gathered once, linked to the controls, risks, obligations and engagements it supports, and reusable across every assurance activity that needs it. Evidence is the currency of assurance, yet most organisations collect the same document five times for five different reviews and still scramble to find it at audit. OnyxOne Evidence Management makes evidence a managed asset: captured with a clear source and timestamp, preserved so it cannot be silently altered, and produced on demand instead of reconstructed under deadline.

At a glance

How it works, visually

Controls, policies & risksSchematic
POLICIESAML policyData protectionSanctions policyCode of conductCONTROLSKYC checksScreeningAccess controlTransaction monitoringApprovalsRISKSFinancial crimeRegulatory breachData lossReputational harmPolicies map to controls; controls mitigate risks — traceable both ways for audit.

How policies map to controls and controls mitigate risks — traceable both ways for audit.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

The same evidence is collected again and again

A single approval record or system report is requested separately by control testing, internal audit, an external assessor and a regulator, each time from the same tired control owner. Evidence is re-gathered for every review rather than collected once and reused, and the cost is paid over and over.

Evidence is scattered and hard to find

Workpapers sit in one drive, attestations in an inbox, screenshots on a laptop, and supporting documents wherever they landed. When an auditor asks for the evidence behind a conclusion, finding it is an archaeology exercise, and some of it is simply gone.

Integrity and provenance are unclear

When evidence finally surfaces, it is unclear where it came from, when it was captured, or whether it has been altered since. Evidence whose provenance cannot be shown is weak evidence, and at examination that weakness becomes the finding.

Evidence is disconnected from what it supports

A document exists, but nothing links it to the control it evidences, the risk it informs or the obligation it satisfies. The evidence and the thing it is meant to prove live apart, so demonstrating that a control is supported means manually stitching the two together.

Retention is inconsistent and risky

Some evidence is deleted too soon to meet a retention obligation; some is kept forever, accumulating risk and cost. Without managed retention, the organisation is exposed on both ends — unable to produce evidence it should have kept, holding evidence it should have disposed of.

The approach

How OnyxOne addresses it

One central evidence store

Control tests, workpapers, attestations, acknowledgements and supporting documents live in one managed repository. There is a single place to look, so evidence is found rather than hunted, and nothing critical is stranded on an individual's device.

Captured once, reused everywhere

Evidence is gathered once and linked to everything it supports, so control testing, audit and external reviews all draw on the same item instead of re-requesting it. The control owner provides it once, and every assurance activity that needs it simply references it.

Integrity and provenance preserved

Each item is captured with its source and a timestamp and preserved so it cannot be silently altered, with a full history of access and use. Evidence carries its provenance with it, so it stands up to challenge rather than raising questions about where it came from.

Evidence linked to what it proves

Every item is linked to the controls, risks, obligations and engagements it supports, so demonstrating that a control is evidenced is a matter of following the link. The gap between a document and the thing it proves closes.

Managed retention and disposal

Retention rules are applied by evidence type and obligation, so items are kept for as long as they must be and disposed of when they should be — protecting the organisation from both losing evidence it needs and hoarding evidence it doesn't.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Central evidence repository

One managed store for control tests, workpapers, attestations, acknowledgements and supporting documents.

Evidence-to-object linking

Link each item to the controls, risks, obligations and engagements it supports so evidence and object stay connected.

Integrity preservation

Preserve evidence so it cannot be silently altered, with source and timestamp captured at collection.

Reuse across assurance

Reference the same evidence item from control testing, audit and external reviews instead of re-collecting it.

Evidence requests

Request evidence from owners through a tracked workflow, with outstanding requests chased and recorded.

Version & supersession

Track versions and supersede stale evidence so the current item is always clear without losing the history.

Provenance & chain of custody

Maintain a full record of where evidence came from and every access and use since.

Retention & disposal

Apply retention rules by evidence type and obligation, holding and disposing of items on policy.

Search & retrieval

Find evidence quickly by object, type, owner, date or engagement, so production is instant rather than an archaeology exercise.

Immutable evidence trail

Every capture, link, access, version and disposal is written to an append-only record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Evidence inventory

The full evidence store searchable by object, type, owner, date and engagement, so any item is found in moments.

Coverage view

Which controls, risks and obligations are evidenced and which are not, so evidence gaps are visible before an auditor finds them.

Request tracker

Outstanding evidence requests by owner and age, so the burden of collection is visible and chased to completion.

Provenance viewer

The source, capture time and full chain of custody for an individual item, ready to demonstrate integrity on challenge.

Retention monitor

Items by retention status, highlighting what is due for disposal and what must be preserved beyond its default period.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Evidence-request workflow

Requests are issued to the responsible owner, tracked and chased automatically until the evidence is captured and linked.

Reuse suggestion

When an activity needs evidence that already exists in the store, the existing item is offered for reuse instead of a fresh request.

Retention enforcement

Retention rules by type and obligation hold items for their required period and flag them for disposal when it ends.

Staleness alerts

Evidence that has passed its useful period for a live control or obligation is flagged so a refreshed item is requested.

Coverage-gap flagging

Controls or obligations left without supporting evidence are surfaced automatically so the gap is closed before audit.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Evidence-to-object matching

Suggests which controls, risks or obligations a captured item likely supports, which a person reviews and confirms before the link is set.

Duplicate-evidence detection

Flags newly submitted evidence that appears to duplicate an existing item, so the store stays lean and reuse is preferred, with a person deciding.

Metadata extraction

Reads a submitted document to propose type, date and source metadata for the owner to verify, improving searchability and provenance.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01RequestEvidence is requested from the responsible owner through a tracked workflow, withthe object it supports specified up front.02CaptureThe item is captured into the central store with its source and a timestamp, andpreserved so it cannot be silently altered.03LinkThe evidence is linked to the controls, risks, obligations and engagements itsupports, so it is connected to what it proves.04ReuseControl testing, audit and external reviews reference the same item rather thanre-requesting it from the owner.05RetainRetention rules by type and obligation determine how long the item is kept, withversions superseded as evidence refreshes.06Produce or disposeEvidence is retrieved on demand for audit and examination, and disposed of on policywhen its retention period ends.

Every result, decision and override is captured against the record it belongs to.

01

Request

Evidence is requested from the responsible owner through a tracked workflow, with the object it supports specified up front.

02

Capture

The item is captured into the central store with its source and a timestamp, and preserved so it cannot be silently altered.

03

Link

The evidence is linked to the controls, risks, obligations and engagements it supports, so it is connected to what it proves.

04

Reuse

Control testing, audit and external reviews reference the same item rather than re-requesting it from the owner.

05

Retain

Retention rules by type and obligation determine how long the item is kept, with versions superseded as evidence refreshes.

06

Produce or dispose

Evidence is retrieved on demand for audit and examination, and disposed of on policy when its retention period ends.

The value

What your team gains

Once

Collect evidence a single time

Gathering evidence once and reusing it everywhere ends the cycle of re-requesting the same document for every separate review.

Preserved

Evidence that stands up

Integrity preservation with source and timestamp means evidence carries its provenance and withstands challenge instead of raising doubt.

Linked

Connected to what it proves

Linking evidence to the controls, risks and obligations it supports turns demonstrating assurance into following a link, not stitching documents together.

Retrievable

Produced on demand

A central, searchable store means the evidence behind any conclusion is retrieved in moments rather than reconstructed under deadline.

Retention handled by policy

Managed retention and disposal protect the organisation from both losing evidence it must keep and hoarding evidence it should have destroyed.

Less burden on control owners

Providing an item once instead of repeatedly for every review frees the people who operate controls from endless re-requests.

Built for

Industries it serves

BankingFinancial ServicesInsuranceInvestment FirmsFintechHealthcareManufacturingPublic SectorRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Control testing
  • Stores and preserves test evidence from the control-testing module so it is captured once and reusable across assurance
Audit
  • Provides workpaper and supporting evidence to audit engagements from one preserved store with full provenance
Internal controls & compliance
  • Links evidence to the controls and obligations it supports so coverage can be demonstrated by following the link
Document & content systems
  • Ingests supporting documents and system reports from your existing content and file stores into the managed evidence repository
Collaboration & notification
  • Routes evidence requests and reminders to owners through your existing email and messaging tools
Assurance

Security, compliance & reporting

Security & data handling

  • Evidence is encrypted in transit and at rest, with access governed by granular, role-based permissions and need-to-know restrictions on sensitive material.
  • Items are preserved so they cannot be silently altered, and their source and capture time are recorded at collection.
  • A full chain of custody records every access and use of each evidence item.
  • Every capture, link, access, version and disposal is written to an append-only audit trail.
  • Retention and disposal are governed by policy, and data residency is configurable to your regulatory and privacy obligations.

Compliance support

  • Supports evidence and record-keeping expectations across assurance, audit and regulatory frameworks
  • Underpins the integrity, provenance and retention of assurance evidence
  • Provides reusable, preserved evidence for internal and external audit and regulatory examination
  • Supports records-retention and disposal obligations by evidence type and jurisdiction
  • Strengthens the evidentiary basis of control testing, audit and compliance attestations
  • OnyxOne is a technology vendor — responsibility for the sufficiency of evidence remains with your assurance functions

Reports & exports

  • Evidence-inventory reports by object, type, owner and engagement
  • Evidence-coverage reports showing which controls and obligations are evidenced
  • Outstanding evidence-request and ageing reports
  • Provenance and chain-of-custody reports for individual items
  • Retention-status and disposal-due reports
  • Evidence management information for audit and compliance functions
Best practice

How to get the most from it

Collect once, link widely

Capture each piece of evidence a single time and link it to everything it supports. Re-collecting the same document for every review is pure waste and burns the goodwill of control owners.

Preserve provenance at capture

Record the source and timestamp when evidence is collected, not later. Evidence whose origin cannot be shown is weak evidence, and provenance is almost impossible to reconstruct after the fact.

Link evidence to what it proves

Always connect an item to the control, risk or obligation it supports. Unlinked evidence is just a file; linked evidence demonstrates assurance.

Let retention rules do the pruning

Apply retention and disposal by policy rather than keeping everything forever or deleting ad hoc. Managed retention protects you from both losing what you need and holding what you shouldn't.

FAQ

Questions, answered

How does evidence get reused across assurance activities?

Each item is captured once into the central store and linked to everything it supports. Control testing, internal audit and external reviews then reference the same item rather than re-requesting it, so a control owner provides a piece of evidence once and every activity that needs it simply points to it.

How is evidence integrity protected?

Items are captured with their source and a timestamp and preserved so they cannot be silently altered, with a full chain of custody recording every access and use. Evidence carries its provenance with it, so it stands up to challenge at audit and examination rather than raising questions about where it came from.

How does retention work?

Retention rules are applied by evidence type and obligation, so each item is kept for as long as it must be and disposed of when it should be. This protects the organisation on both sides — from destroying evidence it is required to keep and from indefinitely hoarding evidence that carries cost and risk.

What kinds of evidence can it hold?

Control-test evidence, audit workpapers, attestations, policy acknowledgements, system reports, screenshots and supporting documents — anything that substantiates an assurance conclusion. Each item is linked to the controls, risks, obligations and engagements it supports so it is always connected to what it proves.

Does OnyxOne judge whether evidence is sufficient?

No. OnyxOne collects, preserves, links and produces evidence, but whether the evidence is sufficient for a given conclusion is a judgement your assurance functions make and own. OnyxOne is a technology vendor; responsibility for the sufficiency of evidence remains with your organisation.

See Evidence Management in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.