Method page

The Evidence Ledger

A lightweight structure we teach for running a compliance evidence tracking financial auditing app without drowning in folders named “final_v7”.

What the ledger holds

Each row is a control instance for a period: owner, artefact list, request status, retention tag, exception flag, and packet link. It is deliberately thinner than a full GRC configuration — which is why teams actually keep it current.

We introduce the ledger in open workshops and deepen it inside Audit Evidence Foundations.

Analytics charts representing tracked evidence status

How teams run it week to week

Freeze the control list for the period

Agree which controls are in scope before requests go out. Scope creep is the usual reason packets arrive incomplete.

Issue requests with artefact definitions

Every request names the exact file or extract expected — not “supporting docs”.

Certify, then assemble

Owners certify completeness; preparers assemble the packet only after certification, so reviewers stop opening half-empty folders.

Close with retention and lessons

Tag retention, log exceptions, and capture one improvement for the next period. That last line is what makes the ledger a living system.