Collect reusable evidence, carry out internal and external audits, and close findings using CAPA — without having to rebuild the file from scratch each time.
Evidence is what makes a claim of compliance defensible. At iComply, evidence does not belong to a framework or an audit — it belongs to the control. That is why it supports all audits that relate to that control, for as long as necessary.
All pieces of evidence are stored in a central library, in Evidências → Biblioteca. Each item has:
When evidence is attached to a control, it automatically satisfies all the requirements mapped to that control. A single penetration test report can satisfy ISO 27001, NIS2, DORA and SOC 2 at the same time.
The panel for each piece of evidence shows the full list of requirements it supports — which is useful when an auditor asks, ‘Where is the evidence for this?’, and the answer is just a click away.
Evidence with no expiry date is a pitfall. When uploading, set the validity period according to the nature of the document:
When the validity period is nearing its end, the platform notifies the person responsible and the control’s status changes to ‘Under review’. If it expires, the control is flagged and the dashboard highlights the gap — before the auditor spots it.
Replacing a document never deletes the previous version. The new version becomes the current one, and the previous versions remain accessible, showing the date, author and reason for the change. This is essential for retrospective audits: an auditor may wish to see what the policy was eighteen months ago, not just the current one.
In Auditoria → Auditorias, an internal or external audit is set up. The process is as follows:
For external auditors, create a user with the ‘Auditor’ profile and a scope limited to the audit. They can access the evidence they need without altering anything.
Each finding is linked to the relevant check, which means that a check’s history shows every time it has failed — valuable information for deciding where to invest.
A finding leads to a corrective (and, where applicable, preventive) action. The cycle has five stages:
A closed CAPA without verification of effectiveness is the most common non-conformity found in follow-up audits. The platform does not allow it to be closed without this step.
Between formal audits, the platform provides continuous assurance: expiring evidence, overdue tasks, controls under review and rising risks are automatically flagged. The practical result is that the next audit finds everything in order, because it has never been out of order.
We’ll show you how to put together your evidence file in days, not weeks.
Utilizamos cookies para melhorar a sua experiência no nosso site. Ao utilizar o nosso site, está a consentir a utilização de cookies.
Defina as suas preferências relativas aos cookies abaixo:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Pode encontrar mais informações na nossa Política de Cookies e na nossa Privacy Policy.