Evidence Is Point-in-Time. Risk Is Continuous

Compliance evidence documents the state of controls at the time evidence was collected. Risk accumulates in the space between evidence collection events.

RCDr. Richard Chingombe · Founder, Verisq·9 min read·Practitioner perspective, not legal advice

The evidence is accurate for its date. The risk that exists today may be materially different from the risk the evidence describes. Governance programs that treat historical evidence as current assurance are filling compliance files with accurate records of a past that has already changed.

Why This Matters Now

Evidence collection is the operational backbone of enterprise compliance programs. Audit logs, access review records, training completion certificates, penetration test reports, policy attestations, and control testing results collectively form the evidence base that demonstrates compliance with regulatory requirements and governance frameworks.

The limitation of evidence-based assurance is temporal. Evidence collected at a specific time describes the control environment at that time. The control environment continues to evolve after the evidence is collected. New vulnerabilities emerge. Access rights accumulate. Configurations drift. The evidence accurately describes the past. It does not validate the present.

The compliance file grows continuously. The risk environment it describes has continued changing from the moment each piece of evidence was collected. The thicker the file, the older the evidence. The older the evidence, the wider the gap between what the file proves and what is actually true today.

The Governance Problem Beneath the Surface

Evidence collection programs are structured around defined collection cycles: annual penetration tests, quarterly access reviews, periodic policy attestations, annual training completions. Each cycle produces evidence that is accurate for the collection period. The collection period ends. The evidence remains in the file. The environment continues to change.

The compliance program treats the evidence as demonstrating ongoing compliance. Regulators and auditors reviewing the evidence see documentation of past compliance. The gap between the state the evidence describes and the current state of the environment is not visible in the evidence file. It is visible only through current assessment.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

What This Actually Means in Enterprise Practice

Access Review Evidence Describes Past Access, Not Current Access

Quarterly access reviews produce evidence that access was reviewed and appropriate at the time of review. Access rights change continuously between reviews: new access is provisioned, old access accumulates, role changes create permission drift. Evidence of a clean access review from three months ago does not demonstrate that current access is appropriate.

Access review evidence has a defined validity window. Organizations that treat quarterly review evidence as current assurance for the duration of the following quarter have a three-month evidence currency gap.

Configuration Evidence Ages Immediately Upon Collection

Configuration assessment evidence documents the configuration state at assessment time. Cloud configurations, security settings, and system parameters change continuously through deployments, updates, and administrative actions. Configuration evidence collected during an annual assessment describes the configuration that existed at that time.

Configuration drift is the accumulation of changes between configuration assessments. Evidence of correct configuration at assessment time does not demonstrate correct configuration at any subsequent time.

Penetration Test Evidence Does Not Address Post-Test Disclosures

Penetration test reports document vulnerabilities found during the testing period using techniques available at the time of testing. Vulnerabilities disclosed after the test completed are not in the report. A clean penetration test report from six months ago does not demonstrate the absence of critical vulnerabilities disclosed in the following six months.

Policy Attestations Document Past Agreement, Not Current Behavior

Annual policy attestations collect employee signatures confirming awareness of and agreement to comply with organizational policies. They document that employees acknowledged the policy at attestation time. They do not document that employees are currently complying with the policy, or that the behavior the policy governs has not changed since attestation.

How Different Teams See This: Where They All Miss

GRC and ComplianceCollecting evidence at defined intervals for each required control. Not typically assessing whether the evidence remains current or whether the control state has changed since collection.
Internal AuditExamining evidence to confirm compliance at the time of evidence collection. Not typically assessing whether the control environment has changed since the evidence was produced.
External AuditorsReviewing submitted evidence against compliance standards. The evidence they receive was produced at collection time. They examine what they receive, not what has changed since.
Security and OperationsOperating the control environment that produces evidence. Not typically connected to the evidence collection program in ways that update evidence currency when controls change.

Evidence currency is not visible in the evidence itself. Evidence accurately records the past. The gap between the past the evidence records and the present the organization operates in is visible only through current assessment that most compliance programs do not conduct between evidence collection cycles.

Framework Control Reference

The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.

NIST CSF 2.0 | DE.CM / GV.OC-03Continuous monitoring is required to detect changes in the control environment. Evidence collection at intervals does not satisfy continuous monitoring requirements.
GDPR | Article 32(1)(d)Regular testing of control effectiveness is explicitly required. Regular testing implies a current assessment cadence that periodic evidence collection does not provide.
ISO 27001 | Clause 9.1Performance evaluation must be ongoing. Historical evidence demonstrates past performance. Ongoing evaluation requires current assessment.
SOC 2 | CC7.2Monitoring of system components for anomalies must be ongoing. Periodic evidence collection does not satisfy an ongoing monitoring requirement.
PCI DSS v4.0 | Requirement 12.3.1Risk assessment must include evaluation of current threats and vulnerabilities. Current threats require current assessment, not historical evidence.
EU AI Act | Article 72Post-market monitoring for high-risk AI must be continuous. Periodic evidence collection does not satisfy a continuous monitoring obligation.

These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.

The Enterprise Reality Gap

The enterprise evidence currency reality gap is the accumulated difference between what compliance evidence files document and what the current control environment actually looks like. The gap grows continuously from the moment each piece of evidence is collected and closes temporarily only when new evidence is collected for the same control.

In mature compliance programs with well-defined evidence collection schedules, the maximum gap at any point in the cycle may be significant: three to twelve months of control environment evolution that is not reflected in any compliance evidence.

The compliance file tells you what the control environment was when the evidence was collected. Current assurance requires knowing what the control environment is now. These are different questions with different evidence requirements.

Enterprise Scenario

The setupA financial services organization maintains a comprehensive compliance file with evidence for all required controls collected at defined intervals. The file passes annual external audit with no material findings.
The regulatory examinationA follow-on regulatory examination focusing on current control effectiveness asks for evidence that specific controls are currently operating correctly. The organization submits its compliance file. The examiner notes that the access review evidence is five months old, the configuration assessment evidence is nine months old, and the penetration test evidence is eleven months old. The examiner requests current evidence for three high-risk controls. The organization cannot produce current evidence because the next collection cycle has not yet occurred.

The compliance file was comprehensive and accurate for its content. The evidence it contained was historical. The examiner's request for current evidence revealed the gap between a well-managed historical compliance file and the current assurance that examination required.

Industry Signal

Regulatory examination methodology is shifting toward requesting current evidence for specific controls at the time of examination rather than reviewing previously collected evidence files. The gap between periodic evidence collection and current control status is becoming an examination finding in itself. Organizations whose compliance programs are built around defined collection cycles are discovering that the examination standard requires evidence that is more current than their collection cadence produces.

The examination is increasingly conducted in the present tense. The compliance file is in the past tense. Build the current assurance capability alongside the historical evidence program.

Enabling Capabilities

  • Continuous compliance monitoring platforms: Tools that track compliance posture in near real-time by monitoring configuration states, access rights, and control status continuously.
  • On-demand evidence generation: Capability to produce current evidence for specific controls at any point in the compliance cycle, not just at defined collection intervals.
  • Change management to evidence integration: Architecture that triggers evidence update when control-relevant changes occur, keeping evidence current rather than aging between collection cycles.
  • Evidence currency dashboards: Reporting that displays the age of evidence for each control alongside the evidence itself, making evidence currency visible in governance reporting.

A Practical Starting Point

For your ten highest-risk controls, calculate the current evidence age: how old is the most recent evidence for each control? Assess whether the gap between the evidence date and today represents a material risk given how quickly that control's environment can change.

Evidence currency assessment reveals the governance gap that compliance file completeness obscures. Conduct the assessment and build monitoring for the highest-risk evidence currency gaps.

Questions Leaders Should Be Asking

  • For our highest-risk controls, how old is the most recent evidence, and does that evidence accurately reflect the current control state given the rate at which our environment changes?
  • If a regulator requested current evidence for a specific control today, outside our normal collection cycle, could we produce it?
  • What is our process for updating evidence when a material change occurs to a control or the environment it governs, between defined collection cycles?
  • Do our compliance dashboards display evidence age alongside evidence status, making evidence currency visible to governance decision-makers?

What to Require From Vendors

Ask directly:

"What continuous compliance monitoring capabilities does your platform provide, specifically the ability to generate current evidence for specific controls at any point in the compliance cycle rather than only at defined collection intervals?"

Expect as evidence:
  • On-demand evidence generation capability with current state reporting
  • Evidence currency tracking with age visualization
  • Change-triggered evidence update for control-relevant changes

A vendor who describes evidence management through collection cycle documentation without addressing on-demand current evidence capability has described a historical record system. Ask specifically for current state monitoring.

Demonstrating Diligence

  • Documentation: Evidence currency tracking for all required controls; evidence age assessment with governance position; current evidence generation capability documentation.
  • Process: Defined evidence currency thresholds for each control category; change-triggered evidence update process; on-demand evidence generation for regulatory examination scenarios.
  • Technical evidence: Continuous monitoring output records; on-demand evidence generation examples; evidence currency dashboard records.

Evidence diligence requires showing that the evidence you hold is current enough to reflect the control state that matters today, not just the state that existed when the evidence was collected.

Closing Perspective

Evidence collection programs provide necessary governance value. They create the documentation base that regulatory compliance requires and that audit programs examine. The evidence collection discipline is mature and important.

The governance frontier is evidence currency: ensuring that compliance programs can produce current evidence of control status at any point, not just at defined collection intervals. This requires continuous monitoring capability that complements rather than replaces periodic evidence collection.

The compliance file proves the past. Current assurance requires governing the present. Build both.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.