Collect objective evidence that the control exists and operates

Exactly. This is the Evidence Collection stage. In real GRC work, you are trying to prove two things:

  1. The control exists — it has been formally defined.
  2. The control operates — people actually perform it.

Collect Objective Evidence — Real-Life GRC Process

OrderTabWhat you do in real lifeLondonBuild example
1Select ControlIdentify the control you need evidence for.AC-002: Quarterly user-access review
2Define Evidence NeededDecide what evidence would prove the control exists and operates.Access-review procedure + completed access-review reports
3Send Evidence RequestSend a formal request to the control owner.Request evidence from IT Manager
4Receive EvidenceControl owner provides the documents/data.Access review report for Q2 2026
5Check Evidence ExistsConfirm the control is formally documented.Access Control Policy exists and is approved
6Check Evidence Is CurrentConfirm the evidence relates to the assessment period.Q2 2026 report, not an old 2023 report
7Check Evidence Is CompleteConfirm all required information is present.All systems/users included in the review
8Check Evidence Is RelevantConfirm it actually proves the specific control.Report demonstrates access was reviewed
9Check Evidence Is AuthenticConfirm it comes from a reliable company source.Export from Microsoft Entra ID / approved GRC system
10Check Evidence Shows OperationDetermine whether the control was actually performed.Review was completed and approved quarterly
11Store / Link EvidenceStore the evidence in the GRC system or link to its approved repository.Evidence ID: EVD-002
12Record Evidence ResultRecord whether the evidence is sufficient.Sufficient / Insufficient / Missing
13Prepare for TestingUse the evidence to perform your control test.Sample users and verify access approvals

Example: What you actually request

Control:

AC-002 — User access is reviewed quarterly by the IT Manager.

You might send:

Evidence Request: Please provide the Q2 2026 user-access review report, evidence of IT Manager approval, and the list of users reviewed.

The IT Manager gives you:

  • Q2_Access_Review.xlsx
  • Manager approval record
  • User access report

You then examine the evidence.

Evidence TestQuestionResult
ExistenceDoes the access-review process exist?✅ Yes
CurrentIs it from the assessment period?✅ Yes
CompleteWere all relevant users reviewed?✅ Yes
RelevantDoes it demonstrate the control?✅ Yes
ApprovedWas the review approved?✅ Yes
OperatingWas the review actually performed?✅ Yes
SufficientCan this evidence support our conclusion?✅ Yes

The key distinction

Control exists:

LondonBuild has a documented quarterly access-review procedure.

Control operates:

LondonBuild actually performed the quarterly review and can provide evidence showing it happened.

So don’t accept:

❌ “We do quarterly access reviews.”

That’s management’s statement, not objective evidence.

You want:

Documented procedure + actual completed review + supporting records

Your GRC workflow is now

Framework

Requirement

Control Objective

Control Mapping

Crosswalk

Risk Event

Risk Register

Collect Objective Evidence

Test Control

Pass / Partial / Fail

Gap

Risk

Remediation

Reporting

This is the point where your GRC work becomes evidence-based rather than just documentation-based.