← Compliance as Infrastructure Reference Specification · Concept 05 of 05
Concept 05

Versioned Evidence

Canonical definition

Versioned Evidence is the immutable record generated automatically at the moment of every compliance decision: the object, the actor, the regulatory condition, and the timestamp. Records are supplemented by new versions. No silent overwrite is allowed. Ever.

What it is not. Versioned Evidence is not audit documentation, and it is not assembled for the occasion. Evidence produced after the fact is reconstruction, and reconstruction is the condition it exists to eliminate.

Specification

Building the architecture is not enough. The architecture must demonstrate that it works. Not in theory. Not in the next audit. In the transaction, at the moment it occurs.

Compliance theater is the program that looks functional on paper. The policies exist. The training records are complete. The audit passes. And underneath it the architecture has gaps that no audit ever reaches, because the audit checks what the program says it does, not whether the system actually enforces it.

Compliance infrastructure proves itself through evidence. Not the evidence assembled for the audit. The evidence generated as a byproduct of normal operations, continuously, automatically, at the moment of every compliance decision. When a compliance decision is made, the architecture must be able to answer four questions about it instantly:

Object
The specific product, customer, shipment, or supplier. Identified precisely, by the unique identifier that links every system that touched it. Not by description.
Actor
The human who ran the screening or the system that evaluated the condition, with the identity, the role, and the authorization that justified the action.
Condition
The specific regulatory requirement that governed the decision. The ECCN. The sanctions list screened against. The license number and its conditions. The ownership analysis.
Timestamp
The precise moment the decision occurred. Not the date of the audit. Not the date the report was assembled.

Object, actor, condition, timestamp. These four elements are the minimum viable evidence record for every compliance decision in the enterprise. When they exist, the architecture is self-authenticating. When they do not, the enterprise is relying on memory, reconstruction, and the goodwill of the regulator.

Immutability

Normative rule

A compliance record that can be altered after the fact is not evidence. It is a document. Documents can be changed. Evidence cannot. Once a decision is recorded, the record can be supplemented. It is never silently overwritten.

This is why the concept is named Versioned Evidence. Reality changes: a classification is revised, a screening result is refreshed, an ownership analysis is updated. Each change produces a new version linked to the prior one. The original record stands. The regulator who receives the record does not have to trust the company's narrative. The tamper-proof log provides the objective account of what the system did, when it did it, and what it decided.

Of the four elements, identity is the most frequently missing. Every compliance-relevant action in every system must be logged with the identity of the actor: the user ID, the system, the role, the version, the configuration at the moment of evaluation. When identity is synchronized and logged across systems, every decision is attributable to an actor with the authority to make it. When it is absent, the accountability chain breaks.

Retrieval, not reconstruction

When an enforcement inquiry arrives, most companies begin an investigation. They pull emails, interview employees, and reconstruct the sequence of decisions. That process takes weeks, sometimes months, and it communicates something no company wants to communicate: the compliance decisions that governed this transaction were not recorded at the time they occurred. That is an aggravating factor in every enforcement guideline.

The company that can produce the evidence instantly, from the operational record, demonstrates it had functioning compliance infrastructure at the time of the decision. That is a mitigating factor, and a significant one. The difference between the two is not the violation. The violation may be the same. The difference is the architecture that existed before the violation occurred.

When the regulator asks what happened, the answer is retrieved, not reconstructed. An audit reads the object. It does not rebuild it.

Lifecycle closure and retention

Evidence must survive the objects it describes. Products are discontinued. Licenses expire. Customer relationships end. Each is a lifecycle closure event: the deliberate, documented transition of a compliance object from active governance to retained evidence, closed with a date, a reason, and a reference to the last transaction it governed. Closure is not deletion.

Retention follows the statute of limitations of the governing regulation. For EAR and OFAC matters, the statute is five years for civil violations and ten years where criminal liability may attach. A license that expired last year may be relevant to an enforcement inquiry for the next nine. The evidence fabric is the complete operational history of every compliance object the enterprise has ever governed: active, closed, and archived. That completeness is what makes it defensible.

Diagnostic question
If the inquiry arrived this morning, would we retrieve or reconstruct?

Pick one transaction from last quarter and attempt to produce the four elements for every compliance decision it passed through. The time it takes to answer is the measure of the evidence architecture. Minutes is infrastructure. Weeks is exposure.

Experience this concept
Make a decision, watch the evidence appear, verify the chain →
Normative source
Compliance as Infrastructure, Gloria Gallo, 2026. Part II, Architecture Must Prove Itself. The complete evidence record for one transaction, field by field, appears in Appendix F. This page is the specification. The book is the full treatment.
← Previous concept
Enforcement Gates