Evidence & Audit Trail

Evidence must be a governed record with identity, source, version, reviewer, acceptance criteria, expiry, linked controls, linked obligations, and audit reference.

EV-HR-001
Accepted Evidence

DPIA Approval - HR Screening Assistant

Accepted privacy impact assessment for HR-AI-001. Linked to personal-data obligation, DPIA control, pilot approval gate, and audit pack.

Evidence IDEV-HR-001
Linked use caseHR-AI-001 Screening Assistant
Source systemSharePoint Evidence Store
Versionv1.3
ReviewerDPO Office
StatusAccepted
Linked obligationOBL-PRIV-02
Linked controlCTRL-DPIA-01
Expiry180 days

Acceptance criteria

CriterionRequiredStatus
DPIA signed by DPOYesMet
Mitigation plan attachedYesMet
Residual privacy risk acceptedYesMet
Review renewal date setYesDue in 180 days

Evidence quality rules

Evidence should not count toward readiness unless it has a source, reviewer, acceptance criteria, linked obligation/control, version, timestamp, and expiry/renewal treatment.

StatusMeaningCounts toward readiness?
AcceptedReviewed and accepted against criteria.Yes
ConditionalAccepted with explicit conditions or time-bound remediation.Partial
RejectedFailed criteria or missing proof.No
ExpiredPast renewal date or superseded by policy change.No