The evidence is accurate for its date. The risk that exists today may be materially different from the risk the evidence describes. Governance programs that treat historical evidence as current assurance are filling compliance files with accurate records of a past that has already changed.
Why This Matters Now
Evidence collection is the operational backbone of enterprise compliance programs. Audit logs, access review records, training completion certificates, penetration test reports, policy attestations, and control testing results collectively form the evidence base that demonstrates compliance with regulatory requirements and governance frameworks.
The limitation of evidence-based assurance is temporal. Evidence collected at a specific time describes the control environment at that time. The control environment continues to evolve after the evidence is collected. New vulnerabilities emerge. Access rights accumulate. Configurations drift. The evidence accurately describes the past. It does not validate the present.
The compliance file grows continuously. The risk environment it describes has continued changing from the moment each piece of evidence was collected. The thicker the file, the older the evidence. The older the evidence, the wider the gap between what the file proves and what is actually true today.
The Governance Problem Beneath the Surface
Evidence collection programs are structured around defined collection cycles: annual penetration tests, quarterly access reviews, periodic policy attestations, annual training completions. Each cycle produces evidence that is accurate for the collection period. The collection period ends. The evidence remains in the file. The environment continues to change.
The compliance program treats the evidence as demonstrating ongoing compliance. Regulators and auditors reviewing the evidence see documentation of past compliance. The gap between the state the evidence describes and the current state of the environment is not visible in the evidence file. It is visible only through current assessment.
What This Actually Means in Enterprise Practice
Access Review Evidence Describes Past Access, Not Current Access
Quarterly access reviews produce evidence that access was reviewed and appropriate at the time of review. Access rights change continuously between reviews: new access is provisioned, old access accumulates, role changes create permission drift. Evidence of a clean access review from three months ago does not demonstrate that current access is appropriate.
Access review evidence has a defined validity window. Organizations that treat quarterly review evidence as current assurance for the duration of the following quarter have a three-month evidence currency gap.
Configuration Evidence Ages Immediately Upon Collection
Configuration assessment evidence documents the configuration state at assessment time. Cloud configurations, security settings, and system parameters change continuously through deployments, updates, and administrative actions. Configuration evidence collected during an annual assessment describes the configuration that existed at that time.
Configuration drift is the accumulation of changes between configuration assessments. Evidence of correct configuration at assessment time does not demonstrate correct configuration at any subsequent time.
Penetration Test Evidence Does Not Address Post-Test Disclosures
Penetration test reports document vulnerabilities found during the testing period using techniques available at the time of testing. Vulnerabilities disclosed after the test completed are not in the report. A clean penetration test report from six months ago does not demonstrate the absence of critical vulnerabilities disclosed in the following six months.
Policy Attestations Document Past Agreement, Not Current Behavior
Annual policy attestations collect employee signatures confirming awareness of and agreement to comply with organizational policies. They document that employees acknowledged the policy at attestation time. They do not document that employees are currently complying with the policy, or that the behavior the policy governs has not changed since attestation.
How Different Teams See This: Where They All Miss
Evidence currency is not visible in the evidence itself. Evidence accurately records the past. The gap between the past the evidence records and the present the organization operates in is visible only through current assessment that most compliance programs do not conduct between evidence collection cycles.
Framework Control Reference
The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.
These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.
The Enterprise Reality Gap
The enterprise evidence currency reality gap is the accumulated difference between what compliance evidence files document and what the current control environment actually looks like. The gap grows continuously from the moment each piece of evidence is collected and closes temporarily only when new evidence is collected for the same control.
In mature compliance programs with well-defined evidence collection schedules, the maximum gap at any point in the cycle may be significant: three to twelve months of control environment evolution that is not reflected in any compliance evidence.
The compliance file tells you what the control environment was when the evidence was collected. Current assurance requires knowing what the control environment is now. These are different questions with different evidence requirements.
Enterprise Scenario
The compliance file was comprehensive and accurate for its content. The evidence it contained was historical. The examiner's request for current evidence revealed the gap between a well-managed historical compliance file and the current assurance that examination required.
Industry Signal
Regulatory examination methodology is shifting toward requesting current evidence for specific controls at the time of examination rather than reviewing previously collected evidence files. The gap between periodic evidence collection and current control status is becoming an examination finding in itself. Organizations whose compliance programs are built around defined collection cycles are discovering that the examination standard requires evidence that is more current than their collection cadence produces.
The examination is increasingly conducted in the present tense. The compliance file is in the past tense. Build the current assurance capability alongside the historical evidence program.
Enabling Capabilities
- Continuous compliance monitoring platforms: Tools that track compliance posture in near real-time by monitoring configuration states, access rights, and control status continuously.
- On-demand evidence generation: Capability to produce current evidence for specific controls at any point in the compliance cycle, not just at defined collection intervals.
- Change management to evidence integration: Architecture that triggers evidence update when control-relevant changes occur, keeping evidence current rather than aging between collection cycles.
- Evidence currency dashboards: Reporting that displays the age of evidence for each control alongside the evidence itself, making evidence currency visible in governance reporting.
A Practical Starting Point
For your ten highest-risk controls, calculate the current evidence age: how old is the most recent evidence for each control? Assess whether the gap between the evidence date and today represents a material risk given how quickly that control's environment can change.
Evidence currency assessment reveals the governance gap that compliance file completeness obscures. Conduct the assessment and build monitoring for the highest-risk evidence currency gaps.
Questions Leaders Should Be Asking
- For our highest-risk controls, how old is the most recent evidence, and does that evidence accurately reflect the current control state given the rate at which our environment changes?
- If a regulator requested current evidence for a specific control today, outside our normal collection cycle, could we produce it?
- What is our process for updating evidence when a material change occurs to a control or the environment it governs, between defined collection cycles?
- Do our compliance dashboards display evidence age alongside evidence status, making evidence currency visible to governance decision-makers?
What to Require From Vendors
Ask directly:
"What continuous compliance monitoring capabilities does your platform provide, specifically the ability to generate current evidence for specific controls at any point in the compliance cycle rather than only at defined collection intervals?"
Expect as evidence:
- On-demand evidence generation capability with current state reporting
- Evidence currency tracking with age visualization
- Change-triggered evidence update for control-relevant changes
A vendor who describes evidence management through collection cycle documentation without addressing on-demand current evidence capability has described a historical record system. Ask specifically for current state monitoring.
Demonstrating Diligence
- Documentation: Evidence currency tracking for all required controls; evidence age assessment with governance position; current evidence generation capability documentation.
- Process: Defined evidence currency thresholds for each control category; change-triggered evidence update process; on-demand evidence generation for regulatory examination scenarios.
- Technical evidence: Continuous monitoring output records; on-demand evidence generation examples; evidence currency dashboard records.
Evidence diligence requires showing that the evidence you hold is current enough to reflect the control state that matters today, not just the state that existed when the evidence was collected.
Closing Perspective
Evidence collection programs provide necessary governance value. They create the documentation base that regulatory compliance requires and that audit programs examine. The evidence collection discipline is mature and important.
The governance frontier is evidence currency: ensuring that compliance programs can produce current evidence of control status at any point, not just at defined collection intervals. This requires continuous monitoring capability that complements rather than replaces periodic evidence collection.
The compliance file proves the past. Current assurance requires governing the present. Build both.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
