The Evidence Lifecycle

evidence lifecycle · compliance evidence flow · evidence architecture · Updated 2026-07-15

Follow one record — an engineer merging a change to production — through its full lifecycle as compliance evidence. This is the Evidence Architecture in motion, and it is the difference between having evidence and being able to prove control.

Stage 1 — Created & Captured

The engineer merges a pull request. The system captures the event at the source: who, what, when, which review approved it, which control it satisfies (change management). No screenshot, no manual log — the record is a byproduct of the work.

Stage 2 — Stored & Connected

The record lands in a tamper-evident store and is mapped to controls once. That single change record now satisfies a control in each framework simultaneously — mapped once, reused everywhere.

Stage 3 — Verified & Consumed

An auditor, reviewing the change-management control, sees the record in context alongside every other change in the period — current, attributed, and verifiable. The audit is verification, not reconstruction.

Why the lifecycle matters

Each stage removes a failure mode of traditional compliance: capture removes backdating, connection removes duplicated effort, consumption removes the export scramble. Together they produce continuous compliance. See how the same records power the audit trail and control mapping.

What this relates to