Skip to main content
Evidence & Documentation
5 min readUpdated 2026-02-15

Evidence Vault Overview

Learn how to organize, manage, and maintain audit-ready compliance evidence in Klarvo's Evidence Vault — the secure repository for all your compliance documentation.

Evidence Vault Overview

The Evidence Vault is Klarvo's secure repository for all compliance documentation. It stores, organizes, and manages every artifact needed for EU AI Act compliance — from vendor DPAs to transparency notice screenshots.

What Goes in the Evidence Vault?

Evidence TypeExamplesTypical Source
Vendor documentationDPAs, security whitepapers, model cards, SOC 2 reportsVendor / procurement
Internal policiesAI acceptable use policy, oversight procedures, incident response planCompliance / legal
Training materialsCourse content, completion certificates, quiz resultsHR / training
Risk assessmentsFRIA reports, DPIAs, internal risk reviewsCompliance
Monitoring reportsPerformance metrics, bias test results, drift analysisEngineering / data science
Incident documentationIncident logs, postmortem reports, corrective actionsOperations / security
Transparency noticesDisclosure screenshots, notification copy, accessibility statementsProduct / UX
Oversight documentationSOPs, authority delegation, training recordsCompliance / HR

Evidence Organization

Evidence can be attached to multiple entities:

  • AI System: System-specific documentation (the most common linkage)
  • Control: Proof that a specific control is implemented (e.g., evidence for DEP-02 "Human Oversight Assigned")
  • Vendor: Vendor due diligence records
  • Policy: Supporting materials for a policy document
  • Task: Completion evidence for a compliance task
  • Incident: Investigation and resolution records
  • Evidence Metadata

    Every file in the vault carries metadata:

  • Name & Description: What this document proves
  • Evidence Type: Policy, screenshot, report, attestation, certificate, training record
  • Uploaded By / Date: Who added it and when
  • Status: Draft → Pending Approval → Approved (or Rejected → back to Draft)
  • Expiration Date: When this evidence needs to be refreshed
  • Confidentiality: Internal Only / Shareable with Auditor
  • Tags: Custom labels for filtering and organization
  • Linked Entities: Which systems, controls, or vendors this evidence supports
  • Evidence Completeness Score

    Each AI system shows an Evidence Completeness percentage:

  • Calculated based on required evidence for applicable controls
  • Missing evidence is listed in the Gap Checklist
  • Improving this score directly improves your Audit Readiness Score
  • Security & Access

  • Role-based access: Who can view, upload, and approve evidence is controlled by role
  • Audit trail: Every action (upload, approve, delete, download) is logged
  • Version history: When you upload a new version of a document, previous versions are preserved
  • Encryption: Files are encrypted at rest and in transit
  • Best Practices

    📁 Link evidence to controls: Don't just upload files — connect them to the specific control they support
    📅 Set expiration dates: Vendor certifications, training records, and risk assessments all have limited validity
    Use approval workflows: For audit-critical documents, require formal approval before they count toward compliance
    🏷️ Tag consistently: Develop a taxonomy (e.g., "vendor-security", "training-completion", "transparency-notice") and use it
    🔄 Quarterly review: Schedule a quarterly evidence hygiene review to catch expired or outdated documents