Evidence has a half-life.
Green that ignores age is not a control status. It is a story about last quarter.
Most GRC programs treat evidence as a file you have or do not have. Auditors treat it as a claim about a period. Those are different jobs. A screenshot taken the week of fieldwork, an access review 97 days old, and a SOC 2 report from last year are not equally current, even if all three sit in the same “evidence” folder. When a tool keeps status green after the evidence has aged past the control’s cadence, it is not monitoring. It is decorating.
- Your dashboard is green and last quarter’s evidence is what it is green about
- A Type II period or an exam will ask what was true across months, not a week
- Screenshots are still the main evidence type
What decays, and how fast
| Kind of evidence | Typical half-life | What goes wrong |
|---|---|---|
| System configuration (MFA, encryption, branch protection) | Hours to days | The screenshot is false the next time someone changes a policy |
| Access reviews and change tickets | Weeks to a quarter | The population drifted; the sign-off did not |
| Policies and standards | Months | The document is current; the practice is not |
| Third-party reports (SOC 2, ISO, HITRUST) | The report period, then the gap to now | Customers treat last year’s report as today’s posture |
| Vendor questionnaires | Until the relationship or the stack changes | Answers from onboarding outlive the access the vendor actually has |
The operational rule
Every control needs a cadence. Inside the window, a passing check is current. Past the window, status should drop or go to review, not stay green. A questionnaire answer and a tool check that disagree should be flagged, not overwritten. That is the difference between continuous control monitoring and a dashboard fed by last quarter’s export. See CCM and what counts as evidence.
Bring one real document. Watch the program get set up from it.
What this looks like in TruOps
Each control is checked on its own cadence, from hourly to quarterly. Results are timestamped and stored with the payload. Stale evidence lowers status. Conflicts between a self-attestation and a tool go to a person. Type II periods and examiner dates become retrievable because completed assessments freeze as of their date.
When this becomes a buying decision
If status stays green after evidence ages past the control's cadence, you are buying a dashboard. Continuous has to mean dated.
If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.
Questions
Are screenshots ever enough?
Sometimes, for a point in time. They are a weak substitute for a timestamped result pulled from the system that enforces the control.
Does a SOC 2 Type II report stay current after the period ends?
It is evidence of the period it covers. It is not a substitute for controls still operating today.
Related
What counts as good evidence, and how to keep it.
→PlatformContinuous monitoringControls checked on your schedule, with stale evidence flagged.
→Use casesContinuous complianceStatus that reflects today, not the last audit.
→LearnSOC 2 Type I vs. Type IIDesign at a point in time vs. effectiveness over a period.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.