Evidence & Artefact Validation

Every compliance claim needs proof. The assistant finds it, validates it, and flags what's missing.

ICMS AI treats every compliance claim as a testable statement. It maps required evidence to each clause, verifies what you have on file, and tells you exactly which artefacts are missing, expired, or need renewal.

artefact validator
ISO 27001 · Annex A
CLAIM · A.5.15 · ACCESS CONTROL

“Only authorised personnel can access production systems.”

Proof required
PDF
IAM policy v3
Verified
XLSX
Access review Q3
Verified
JSON
MFA enforcement
Verified
LOG
Privileged access
Missing
PDF
DR test evidence
Verified
JSON
Firewall config
Verified
LOG
Backup logs · Q3
Verified
PDF
Vendor DPA
Verified
IMG
ISO cert · Site A
Missing
JSON
Encryption config
Verified
LOG
Change record
Verified
XLSX
Training CSV
Verified
10 verified·2 missingclaimPass with gaps

Traditional ICMS is a workflow. ICMS AI is a conversation.

Traditional workflow

You navigate the app.

  • Evidence hunt starts a week before every audit
  • Documents live in shared drives, email threads and WhatsApp
  • One person tracks expiry dates in a colour-coded Excel
  • No one knows which evidence proves which clause

ICMS AI · agentic

You just ask.

  • Ask: "Validate all evidence for A.5.15 Access Control"
  • The assistant pulls the artefacts, checks freshness, and flags gaps
  • Every clause has a live evidence map that updates as you upload
  • Missing evidence generates a task, routed to the artefact owner

How it works.

  1. 01

    Map required evidence

    For each clause in scope, the assistant lists the artefacts required to prove it (policies, logs, screenshots, configs, records).

  2. 02

    Match against your library

    Uploaded documents, exported logs, and system snapshots are matched to their target clauses automatically.

  3. 03

    Validate freshness

    Every artefact is checked for expiry, missing fields, or stale timestamps. Expired items are surfaced with the renewal owner.

  4. 04

    Fill the gaps

    A request for evidence is opened for each missing artefact, with the owner and clause it proves attached.

What you get.

No more evidence scramble before audits. Every claim traces to a verified artefact, live.

  • Clause-to-evidence mapping across every framework in scope
  • Automatic expiry tracking and renewal reminders
  • AI-parsed form fields from uploaded documents
  • Configurable evidence templates per standard
  • Maker-checker-approver workflow on every artefact
  • Full audit trail: who uploaded, who verified, when

See it on your standards.

Talk to us about running this on your compliance programme.