Assurance and evidence

Evidence, proof levels, exceptions and audit packs.

Northwind Mutual ⌄Console › Assurance › OverviewSearch ⌘KProductionModelPolling

Assurance overview

How far each control is proven. Effective only after a passed test.

Schedule testsBuild audit pack
Controls evidenced35 of 81+6 this month
Rated effective10Needs a passed test
Tests due in 30 days92 overdue
Open exceptions31 high risk

Assurance level by framework

Number of controls at or above each level
DeclaredObservedImplementedEvidencedTestedEffectiveCPS 2304137311996CPS 2342422171053FAR161511621

Evidence collected

Last 12 weeks
W29W31W33W35W37W39

Exceptions

3 open
  • HighOR-15 test failed, 2 payments approved above threshold without a recorded approver
  • MediumOR-07 overdue, Azure OpenAI provider review past due date
  • MediumUnowned asset, gpt-4o caller in Finance has no accountable owner

Evidence sources

Cogna8 decision receiptsLive1,204
CI/CD change recordsLive86
Model evaluation results42
Third-party assurance reports7
Assurance overview: proof level by framework, evidence over time, exceptions and evidence sources.

Proof levels

Every control carries a proof level. It only rises when the record supports it, and effective is never inferred without a passed test.

How far is this control proven?Move the slider. Each level needs everything below it.
  1. DeclaredA control exists on paper and has an owner.Policy document, owner assigned
  2. ObservedCogna8 can see it in configuration or behaviour.Connector reading, configuration export
  3. ImplementedThe mechanism is in place.Active gate policy, enforced permission
  4. EvidencedDated records show it operating.Decision receipts, change records
  5. TestedA test has run and its result is recorded.Test run with date, sample and result
  6. EffectiveA passed test supports the claim.Passed test within the review period

Evidence sources

SourceCollected
Cogna8 decision receiptsAutomatically, for every gate decision
Change records from CI/CDAutomatically, through connectors
Evaluation and monitoring resultsImported from your existing tools
Third-party assurance reportsUploaded and linked to vendors and models

Exceptions

A failed test, an overdue review or an unowned system raises an exception with an owner and a due date. Exceptions stay visible until closed.

Audit packs

An audit pack collects the controls in scope, their proof levels, evidence for the period, gaps and exceptions. The copilot can assemble it and draft evidence requests for approval.

Northwind Mutual ⌄Console › Assurance › Audit packs › CPS 230 Q3 2026Search ⌘KCopilotProductionModelPolling

CPS 230 audit pack, Q3 2026

1 July to 30 September 2026. Draft, 82% complete.

Preview packExport
Controls in scope41All CPS 230
Evidenced or better35+6 this quarter
Gaps4Owners not yet asked
Failed tests1OR-15
IDControlProof levelEvidence
OR-01Critical operations mapped Evidenced3
OR-07Third-party AI due diligence Request drafted0
OR-12Change control for models Tested2
OR-15Human approval above threshold Request draftedTest failed1,204
OR-21AI incident escalation Evidenced4
OR-28Continuity for AI services Request drafted1
CopilotAssurance · Audit packs×
Working onBuild the CPS 230 audit pack for Q3
  1. Collected evidence for 41 controls, July to September
  2. Linked 1,204 decision receipts to OR-15
  3. Found 4 gaps and 1 failed test
  4. Send 3 evidence requests to owners
  5. Draft the exceptions summary for the committee
Needs your approval
Request evidence from ProcurementOR-07 · no third-party review since June

Email and task to the control owner, due 10 Oct.

SendEditSkip
✓Sent by Alex Morgan · task created, due 10 Oct
Raise exception for OR-152 payments approved above threshold without an approver

Opens an exception owned by the Claims Ops Lead.

RaiseEditSkip
2 more waiting below
Nothing is sent or raised without your approval.
Ask what is missing, or change the period↵
Last reviewed October 2026Suggest a change