You are here:
Manage Evidence for IT Compliance
Move evidence through its full lifecycle — create compliance audits, raise evidence requests, fulfill requests with artifacts, and verify evidence so it's ready for external auditors.
Required Editions
| Available in: Lightning Experience |
| Available in: Enterprise, Performance, and Unlimited Editions with Agentforce IT Service. |
- Evidence Management Lifecycle for IT Compliance
Follow how compliance evidence moves from audit planning to external review. See how audit managers, fulfillers, compliance reviewers, and auditors work together to collect, verify, and lock evidence in a traceable workflow. - Create a Compliance Audit for IT Compliance
Create a Compliance Audit record to define the scope, type, and timeline for an audit engagement. The audit captures who requested the audit, what framework or regulation it covers (such as ISO 27001 or internal governance), and the observation and execution windows. It serves as the parent for all evidence requests and tracks the overall audit lifecycle. - Create Evidence Requests for IT Compliance
Create compliance evidence requests to gather artifacts from subject matter experts for an audit. Each request specifies what evidence is needed, who should fulfill it, and when it's due. Requests can be created manually or autogenerated from an audit template. - Create and Link Evidence Artifacts for IT Compliance
Respond to evidence requests by creating a new artifact and uploading files, or by linking an existing artifact that already satisfies the request. If the same evidence artifact applies to multiple requests, link the existing file instead of creating duplicates. - Fulfill Evidence Requests from the IT Service Employee Portal
Employees can fulfill evidence requests directly from the IT Service employee portal without needing access to the Evidence Hub app. Requests appear as assigned tasks, and employees upload evidence artifacts using a simplified, guided interface. - Preview an Evidence Artifact
Open the built-in evidence artifact previewer to review the files attached to a Compliance Evidence Artifact directly inside the artifact record. Reviewing in the previewer means you don't have to download a copy of the file to verify the evidence. - Review and Close Evidence Requests for IT Compliance
Verify submitted evidence artifacts by previewing files, checking completeness, and setting each artifact's status to Accepted or Rejected. Once all artifacts are verified, mark the evidence request as Accepted to close out the request. - Considerations for Evidence Artifacts in IT Compliance
Understand how artifact statuses work, when artifacts lock, which file types are supported, and what classification levels mean, so you can manage compliance evidence accurately and securely.
Did this article solve your issue?
Let us know so we can improve!

