Illustrative sample: This page shows the structure of an Evidence Pack. It is not a customer record, audit report, certification, or evidence that any event, test, or control occurred.
1. Pack identity and scope
- Customer and covered site(s)
- Reporting period and pack version
- Prepared by, prepared date, and scope exclusions
- Related order confirmation and operating contacts
2. Controls summary
- Control area and customer-specific description
- Responsible party: State Street, customer, or third party
- Evidence reference and review date
- Status vocabulary defined for the pack
- Exceptions, limitations, and follow-up owner
3. Vendor register
- Provider, service supplied, and relationship owner
- Data or access involved
- Contract or terms reference and review date
- Known dependency, transfer, and exit notes
4. Update and change log
- Date, system or component, and change category
- Requester, implementer, and approval reference where used
- Validation performed and result
- Rollback or follow-up reference where applicable
5. Backup and restore evidence
- Customer-specific backup responsibility and configuration
- Evidence source and observation date
- Restore exercise date, scope, and result when one occurred
- Exceptions and corrective action without invented RPO/RTO claims
6. Incident record
- Incident identifier, reported time, and reporting source
- Affected site or service and observed impact
- Actions, communications, resolution, and follow-up
- “No incidents recorded in this period” only when supported by the customer record
7. Quarterly posture summary
- Period reviewed and evidence sources consulted
- Material changes, open exceptions, and dependency changes
- Upcoming actions with owner and target review date
- Items requiring customer or CCO decision
8. Customer and CCO review
- Customer reviewer / title / date
- CCO or compliance reviewer / title / date, if applicable
- Questions, requested corrections, and acceptance notes
- Acknowledgment that review is not regulatory approval
Evidence handling rule
A field is marked not observed, not tested, not applicable, or pending when the underlying record is unavailable. Empty space is never converted into a passing claim.
See the Trust & Evidence Center for the compliance boundary, ownership, dependencies, and exit process.