LensReading which lens this session carries.
All controls

CTL-009 · Evidence integrity

Evidence records have no update path

The code contains no route that updates or deletes an evidence record. Correction is by superseding record only.

Effective
Domain
Evidence integrity
Scope
enterprise
Frequency
semi-annual
Operation
Manual
Control owner
Platform Engineering Lead · engineering
Tester of record
internal-audit
Last tested
Jul 02, 2026
Next due
Dec 31, 2026 · in 135d

What counts as evidence for this control

Written before the test, so a tester cannot choose the evidence that suits the result

Code review sign-off against the evidence module.

Test history

2 tests on record

102 items sampled
TestPeriodSample methodSizePassFailResultTesterTested
CT-009-01Q3 month 1 2026random attribute sample53530PassR. Whitfield
Internal Audit
Jul 02, 2026
CT-009-02Q2 2026random attribute sample49490PassS. Nakamura
Internal Audit
Apr 01, 2026

Exceptions raised against this control

None raised

No exception has been raised against this control.

What this page is, and what it is not

Read this before quoting a result

The test results on this page are a modeled test history for a modeled estate. They demonstrate the shape of independent control testing — a named tester outside the operating team, a stated sample method, a sample size, a pass and fail count, and evidence citations that resolve into the chain — not the audited results of a live enterprise.

8 of 8 evidence citations on this control resolve to a record in the evidence spine. Every citation resolves; each one links through to the sealed record it refers to.

A control shown as untested has no result at all. Coverage on this platform counts controls that were actually tested; it never counts a control as passing because it was designed.