The Evidence Lifecycle
evidence lifecycle · compliance evidence flow · evidence architecture · Updated 2026-07-15
Follow one record — an engineer merging a change to production — through its full lifecycle as compliance evidence. This is the Evidence Architecture in motion, and it is the difference between having evidence and being able to prove control.
Stage 1 — Created & Captured
The engineer merges a pull request. The system captures the event at the source: who, what, when, which review approved it, which control it satisfies (change management). No screenshot, no manual log — the record is a byproduct of the work.
Stage 2 — Stored & Connected
The record lands in a tamper-evident store and is mapped to controls once. That single change record now satisfies a control in each framework simultaneously — mapped once, reused everywhere.
Stage 3 — Verified & Consumed
An auditor, reviewing the change-management control, sees the record in context alongside every other change in the period — current, attributed, and verifiable. The audit is verification, not reconstruction.
Why the lifecycle matters
Each stage removes a failure mode of traditional compliance: capture removes backdating, connection removes duplicated effort, consumption removes the export scramble. Together they produce continuous compliance. See how the same records power the audit trail and control mapping.
What this relates to
- Evidence ArchitectureThe three-layer model for how compliance evidence is created, connected, and consumed: Created & Captured → Stored & Connected → Verified & Consumed.
- Evidence-Native SystemsSystems where compliance proof is a property of how they operate — captured at the source — not a document produced under deadline.
- Control Mapping: One Evidence Base, Many FrameworksHow a single evidence base maps to multiple frameworks at once — the mechanism that makes multi-framework readiness economically viable for a startup.
- The Audit Trail: Tamper-Evident Records in PracticeWhat a defensible audit trail looks like — how records are captured, made tamper-evident, and handed to an auditor as scoped live access rather than a static binder.