How to record control evidence on Mac
Do it in RiskOS, a risk register for macOS. The proof sits beside the control it belongs to, dated and ready to hand over.
An auditor rarely asks whether a control exists. They ask to see it working, and the difference between a calm hour and a bad fortnight is whether anyone can produce the proof without a search party. Evidence notes are where you write it down, on the control itself, while you still remember what you saw.
Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine.
Where control evidence lives
Choose Controls in the sidebar. The table lists everything you rely on: Ref, the control with its detail beneath, Type, Status, an Effectiveness meter, Owner, a count of the Risks leaning on it, and Review. Click a row and the panel on the right opens that control.
Its fields run in order — name, description, type, status, owner, effectiveness with its written descriptor, the next review date, and last of all evidence notes. That final field belongs to the control rather than to any one risk, so a single note answers for every risk in the Risks count at once.
Record evidence for a control
-
Open the control
Click the row you want in Controls, or find it with the search field above the table. If the control is not recorded yet, press ⌘N to create one; it takes the next reference in sequence, reading CTL-0001 and onwards.
-
Settle the status before the note
Set the status honestly first, because it changes what the evidence has to prove. A planned control needs a decision and a date. An operating one needs something it produced recently. Only implemented or operating controls reduce risk, so a strong plan with no start date buys you nothing.
-
Name the artefact in one line
Open evidence notes and start with the thing itself, in the words someone would use handing it across: quarterly restore rehearsal report, signed off by the infrastructure lead. Do not describe the control again — the description field already carries that. The note answers a narrower question: what would you put in front of somebody.
-
Say who produces it and how often
Add the source and the cadence on the next line. Produced by the platform team after each rehearsal, quarterly. This line saves the most time later: the question that delays an audit is rarely "does it exist" but "who do I ask". Name a team rather than a person, so the note survives somebody changing jobs.
-
Date what you last saw
Write the date of the most recent evidence you have actually laid eyes on, and the period it covered: last seen 14 July 2026, covering the June rehearsal. An undated note ages invisibly. A dated one says at a glance whether this is a live control or a memory of one.
-
Set the next review date to match
Move up to next review and set it to the point at which this evidence goes stale, usually one cadence after the last sighting. The date appears in the Review column, which sorts, so one click brings everything that has gone quiet to the top.
-
Raise an action for anything missing
Where evidence should exist and does not, do not bury the admission in prose. The control's own panel holds its remediation actions: add one with a title, an owner, a priority and a due date. It then appears in Actions with the rest of the register, badged if the date passes.
-
Check it against the risks that rely on it
Open one of the risks in the control's Risks count. The risk's Controls section lists what it leans on, with each control's status and effectiveness in place. Where a risk derives its residual score from this control, your note is the argument behind that score. Changes save as you type.
What belongs in an evidence note
A good note is five short lines and takes two minutes. Write it for a stranger — the colleague who inherits the register, or you in eighteen months — so it never leans on what was said in the meeting.
| Line | The question it answers | Worked example |
|---|---|---|
| The artefact | What would you hand over? | Quarterly restore rehearsal report, signed off by the infrastructure lead. |
| The source | Who produces it? | Produced by the platform team after each rehearsal. |
| The cadence | How often does a fresh one appear? | Quarterly, in the first week after quarter end. |
| The last sighting | When did you last see one? | Last seen 14 July 2026, covering the June rehearsal. |
| The gap | What is missing, and who is closing it? | No rehearsal held in Q2. Action raised with M. Halvorsen. |
Write what you saw, not what you were told
There is a real difference between the team confirmed backups are tested and saw the July rehearsal report; restore completed in 4h 20m against a 6h objective. The first is hearsay with tidy grammar. The second survives someone paid to be sceptical. Where you were only told something, say so and treat it as a gap.
Keep one note per control
Evidence belongs to the control, and that is where RiskOS keeps it, so a control linked to six risks carries one record all six inherit. If you want two different notes, you usually have two controls — split them, and let each carry its own status, owner and effectiveness.
Status is half the evidence
The most common finding is not missing paperwork. It is a control described as though it were running when it is still a plan. RiskOS separates the two and refuses to let a planned control reduce anything.
| Status | What the evidence has to show | Effect on a linked risk |
|---|---|---|
| Planned | The decision, the scope and the date it goes live. | None. However strong it will be, it reduces nothing yet. |
| Implemented | That it is in place and configured as described. | It counts towards the residual score. |
| Operating | That it ran recently and produced something you can point to. | It counts, and the evidence renews itself on a cadence. |
| Retired | When it stopped, why, and what took its place. | Nothing. It stays out of the list until you show retired controls. |
Effectiveness needs the same discipline
Effectiveness claims how much a control reduces exposure, and the note justifies the strength you chose: one tested quarterly with clean results earns more than one nobody has exercised. Editing a control's status or effectiveness re-scores every risk deriving from it immediately, so note and meter should move together.
Watch for a divergence warning
A risk can take its effectiveness from its strongest operating control automatically, or keep a value set by hand. When the two disagree, the risk's panel points it out rather than quietly choosing. Read that as a prompt to check the evidence: either the hand-set value is stale, or the control's record has drifted.
Keeping evidence current
Evidence decays. A note written in January describes a control as it was in January, and the only thing between that and a misleading register is a date you agreed to honour.
Let the Review column do the chasing
Sort the controls table by Review and the rows that have gone quiet rise to the top. Work down them in one sitting rather than in ones and twos, and RiskOS keeps the sort where you left it. Where a date has passed and nothing fresh has appeared, say so in the note and raise an action, rather than quietly pushing the date forward.
Add to a note rather than replacing it
When fresh evidence arrives, add a dated line above the previous one instead of overwriting. Three sightings in a row tell a reader the control is genuinely running, which is stronger than any adjective. If you overwrite something by accident, ⌘Z undoes it.
Turn a gap into an action
A gap recorded only in prose is a gap nobody is working on. Raise it on the control with an owner and a due date, and it joins Actions, grouped into Just Added, Overdue, Due Soon, Later, No Due Date and Closed. Every row shows its parent risk or control.
Evidence behind a framework claim
Controls map to framework requirements from either side, and Frameworks reports coverage in three honest states: covered, where a mapped control is implemented or operating; mapped but not operating; and not mapped. Evidence notes are what make the first of those defensible rather than decorative.
Requirements group by their source group in catalogue order, with a search field and a coverage filter, so you can work down the ones that read as covered and confirm each has a note behind it. RiskOS ships its own Control Baseline 1.0 and the NIST Cybersecurity Framework 2.0 structure at category level, and imports your own catalogue from CSV or JSON.
Coverage is a figure people quote. Seven of twenty-eight requirements covered is worth quoting only if all seven have a dated note underneath.
Putting evidence in front of someone
Reports carries section toggles for controls, open actions and framework coverage, and every output is built from one snapshot, so the three agree. PDF is paginated A4 with a branded cover and repeated table headers; HTML is one self-contained file that opens in any browser. Shortcuts: ⇧⌘P for PDF, ⇧⌘E for HTML, ⌘P to print.
Troubleshooting
I recorded good evidence and the residual score did not move
Evidence carries no number, so it never changes a score by itself. Check the control's status and effectiveness: only implemented or operating controls reduce risk, and the residual score is worked out from the effectiveness you record. Set both to match the evidence, and every risk deriving from that control re-scores at once.
The control I want has disappeared from the list
Two things hide rows in Controls. A type filter may be narrowing the table to one kind, and retired controls stay out of view until you turn on the show-retired toggle. Clear the filter or switch the toggle on and the row returns, evidence notes intact.
Two people have written conflicting notes on the same control
That usually means the control is doing two jobs. Split it in two, each with its own status, owner, effectiveness and evidence, then relink the risks. A control needing a paragraph of caveats is nearly always one that should have been two rows.
A requirement still reads as mapped but not operating
Coverage follows the control's status, not the quality of the note attached to it. A requirement stays in that middle state until a control mapped to it is implemented or operating. Open the mapped control, set the status that matches reality, and it moves to covered.
I cannot tell which controls still need evidence
Sort by Review and work down; anything dated in the past is asking to be looked at. Then sort by the Risks count and check the few controls the most risks depend on. Those two passes find nearly everything worth finding.
A working routine for evidence
- Write the note the day you see the evidence. A week later you will remember that it existed but not what it said, and the detail carries the weight.
- Date every line. Undated prose ages without telling anyone, and no reader can separate a control checked last month from one checked in 2024.
- Start with the controls that carry the most risks. The Risks count is your priority order; a control six risks lean on deserves the better note.
- Set the next review date one cadence out. Let the Review column chase you, and sweep the overdue rows once a month.
- Turn every gap into an action with an owner and a date. That converts an admission into work, and overdue rows announce themselves.
- Re-read three notes a quarter as a stranger. If you cannot follow one without background knowledge, rewrite it while you still have it.
- Back up before an audit and after a sweep. File ▸ Back Up RiskOS… or ⇧⌘B writes the whole register — controls, evidence, actions and history — to one file.
Frequently asked questions
What counts as evidence for a control?
Anything a sceptical reader could examine and accept: a test report, a signed-off review, a rehearsal record, a dated approval. What matters is the line between something you have seen and something you were told. Record the first with its date, and record the second as a gap with an action against it.
Where do I record control evidence in RiskOS?
In the control's own panel. Choose Controls in the sidebar and select the row; the last field in the detail is evidence notes. It sits below name, description, type, status, owner, effectiveness and the next review date, and it belongs to the control, so every risk linked to it shares the record.
How often should control evidence be refreshed?
One cadence behind whatever produces it. A control tested quarterly should carry a note refreshed quarterly. Set the control's next review date to the point where the current evidence goes stale, then sort the controls table by Review and work down the rows whose dates have passed.
Does recording evidence change a risk score?
No. Evidence is a written record, not a number, so it never moves a score on its own. What moves a score is the control's status and effectiveness, both of which the evidence should support. Change either of those and RiskOS re-scores every risk deriving from that control immediately.
What is the difference between a control's status and its evidence?
Status is the claim; evidence is the reason anyone should believe it. Status decides arithmetic: only implemented or operating controls reduce risk, and only those make a mapped framework requirement read as covered. Evidence decides whether the claim survives questioning. Keeping the two in step is most of control assurance.
How do I show which controls cover a framework requirement?
Open Frameworks and use the coverage filter. Each requirement shows one of three states: covered, mapped but not operating, or not mapped. Work down the covered requirements, open each mapped control, and confirm the evidence note underneath is dated and current. That walk is the same one an assessor will make.
What should I do when evidence for a control does not exist yet?
Say so in the note, in plain words, with the date. Then raise an action on the control itself, with an owner and a due date. It joins the register in Actions, grouped by due state and badged when it falls overdue, so the gap is tracked as work rather than filed as a confession.