Assurance and evidence
Evidence, proof levels, exceptions and audit packs.
Northwind Mutual ⌄Console › Assurance › OverviewSearch ⌘KProductionModelPolling
Assurance overview
How far each control is proven. Effective only after a passed test.
Schedule testsBuild audit pack
Controls evidenced35 of 81+6 this month
Rated effective10Needs a passed test
Tests due in 30 days92 overdue
Open exceptions31 high risk
Assurance level by framework
Number of controls at or above each levelDeclaredObservedImplementedEvidencedTestedEffectiveCPS 2304137311996CPS 2342422171053FAR161511621
Evidence collected
Last 12 weeksExceptions
3 open- HighOR-15 test failed, 2 payments approved above threshold without a recorded approver
- MediumOR-07 overdue, Azure OpenAI provider review past due date
- MediumUnowned asset, gpt-4o caller in Finance has no accountable owner
Evidence sources
| Cogna8 decision receipts | Live | 1,204 |
| CI/CD change records | Live | 86 |
| Model evaluation results | Weekly import | 42 |
| Third-party assurance reports | Uploaded | 7 |
Proof levels
Every control carries a proof level. It only rises when the record supports it, and effective is never inferred without a passed test.
How far is this control proven?Move the slider. Each level needs everything below it.
- DeclaredA control exists on paper and has an owner.Policy document, owner assigned
- ObservedCogna8 can see it in configuration or behaviour.Connector reading, configuration export
- ImplementedThe mechanism is in place.Active gate policy, enforced permission
- EvidencedDated records show it operating.Decision receipts, change records
- TestedA test has run and its result is recorded.Test run with date, sample and result
- EffectiveA passed test supports the claim.Passed test within the review period
Evidence sources
| Source | Collected |
|---|---|
| Cogna8 decision receipts | Automatically, for every gate decision |
| Change records from CI/CD | Automatically, through connectors |
| Evaluation and monitoring results | Imported from your existing tools |
| Third-party assurance reports | Uploaded and linked to vendors and models |
Exceptions
A failed test, an overdue review or an unowned system raises an exception with an owner and a due date. Exceptions stay visible until closed.
Audit packs
An audit pack collects the controls in scope, their proof levels, evidence for the period, gaps and exceptions. The copilot can assemble it and draft evidence requests for approval.
Northwind Mutual ⌄Console › Assurance › Audit packs › CPS 230 Q3 2026Search ⌘KCopilotProductionModelPolling
CPS 230 audit pack, Q3 2026
1 July to 30 September 2026. Draft, 82% complete.
Preview packExport
Controls in scope41All CPS 230
Evidenced or better35+6 this quarter
Gaps4Owners not yet asked
Failed tests1OR-15
CopilotAssurance · Audit packs×
Working onBuild the CPS 230 audit pack for Q3
- Collected evidence for 41 controls, July to September
- Linked 1,204 decision receipts to OR-15
- Found 4 gaps and 1 failed test
- Send 3 evidence requests to owners
- Draft the exceptions summary for the committee
Needs your approval
Request evidence from ProcurementOR-07 · no third-party review since June
Email and task to the control owner, due 10 Oct.
SendEditSkip
✓Sent by Alex Morgan · task created, due 10 Oct
Raise exception for OR-152 payments approved above threshold without an approver
Opens an exception owned by the Claims Ops Lead.
RaiseEditSkip
2 more waiting below
Nothing is sent or raised without your approval.
Ask what is missing, or change the period↵
Last reviewed October 2026Suggest a change