A governance professional reviewing evidence beside a digital workspace
Pre-launch concept

Evidence in.Judgement stays human.

Proof GRC is being designed as an AI-assisted evidence workspace that helps teams organise material and surface possible gaps for accountable review - not replace an auditor or guarantee compliance.

Follow the evidence line

Illustrative product direction. The pictured workspace and examples are not released functionality or customer evidence.

Evidence line / 01

From source material to a reviewable decision.

The useful part of assistance is not simply producing a result. It is preserving enough of the path for an accountable person to challenge it.

Retain the source

Keep the relevant policy, control statement, record or supporting material connected to the working item.

Propose a relationship

Surface a candidate mapping, gap or question with enough context to inspect why it appeared.

Open a review gate

Let an authorised reviewer accept, reject, correct, request evidence or mark the item unresolved.

Record the decision

Retain the reviewer, rationale, status and evidence trail needed for the relevant workflow.

Not an auditor

Proof GRC is not represented as legal advice, an audit opinion, certification, accreditation or a guarantee of compliance.

Workspace / 02

Keep the source beside the suggestion.

Governance professional comparing source material with a review workspace
Illustrative review state

Candidate relationship

A source passage, a proposed relationship and an unresolved question belong in the same review context. The final decision remains explicitly assigned to a person.

Fictional evidence

Design intentions / 03

Selected frameworks.
One evidence view.

01 / Evidence

Evidence review

Highlight source material and candidate gaps for a person to assess.

02 / Applicability

Control selection

Support authorised users maintaining scope, rationale and review state.

03 / Privacy

Assessment prompts

Structure privacy-impact questions without replacing legal or privacy advice.

04 / Risk

Risk context

Keep risks, candidate mappings, notes and decision status together.

05 / Trace

Review history

Record what changed, who reviewed it and which questions remain open.

06 / Export

Prepared material

Prepare reviewable material without presenting a system-generated conclusion as an assurance opinion.

Service boundary / 04

Make the service boundary explicit.

A serious product conversation needs a product- and engagement-specific record.

Proof GRC briefing topics
TopicWhat should be documentedCurrent public position
ArchitectureSystems, integrations, storage, processing, environments and material data flows.Not asserted universally.
ProvidersProvider identity, purpose, access, location, retention and training terms.No common list published.
IdentityRoles, authentication, administration, support and access review.To be defined for the service.
Evidence lifecycleCollection, use, retention, export, correction and deletion responsibilities.To be agreed for the use case.
AssuranceTesting, incident response, vulnerabilities and contractual commitments.No certification or maturity claim.
Trust centre

See the public trust position for group-level boundaries and the Essential Eight evidence register.

Prepare the evidence.
Keep judgement human.

Tell us about the evidence, framework and accountable reviewer in view.

Discuss Proof GRC