Route 12 of 176
Compliance Evidence
QRCompliance.us · Validation Layer · Source of truth: QRCodex.us
Summary
Compliance evidence is what remains after a compliance condition is reached: the basis record, the timestamp, the retained state of the facts that were compared, and the artefacts proving verification actually happened. It is the durable proof that a finding occurred and on what grounds — not the finding, and not the full audit history built on top of it.
Evidence proves a condition existed and why. It does not restate the condition, and it is not the audit trail — those live in category 07.
A compliance condition (Route 03) is a finding: satisfied, failing, expired, restricted, exception. The moment that finding is produced, a second and separate question arises — can anyone, later, prove it happened, on what basis, and when? That proof is compliance evidence.
Without evidence, a condition is a claim nobody can verify after the fact. A dispute, an audit request, a certification review or a regulator's inquiry does not ask for the finding restated — it asks for the record that supports it. Evidence is what answers that request.
Compliance evidence belongs to category 01 because it is a fundamental property of every condition the validation layer produces: it must be provable, not just stated. The deeper mechanics of audit history, event logs and retrieval access across the operational record are handled by category 07 and are not restated here.
01Plain-English Definition
Compliance evidence is the retained set of facts, timestamps and artefacts that proves a specific compliance condition was reached on a specific basis, at a specific moment, for a specific registered identity.
It is produced as a byproduct of evaluation, not manufactured separately after the fact. When a condition is composed (Route 03), the same process that assembles the result also fixes the basis it rested on — and that basis, once fixed, becomes evidence the moment it is retained.
Evidence exists to answer one question honestly, indefinitely: on what grounds was this finding made? If that question cannot be answered from the retained record, the condition — however correct it may have been — is not evidenced, and an unevidenced condition cannot survive a dispute, an audit, or a certification decision built on top of it.
02What Counts As Evidence
Not everything touched during evaluation qualifies. Evidence is the subset of material that is retained, time-stamped, and sufficient on its own to reconstruct why a condition came out the way it did.
- Basis records — the specific record facts (registration state, certification state, jurisdiction assignment, flags) that were compared against applicable requirements.
- Timestamps — the exact moment evaluation occurred, since a condition's validity is time-bound and evidence must fix that moment precisely.
- Retained conditions — the composed finding itself, kept as a historical artefact rather than overwritten by the next evaluation.
- Verification artefacts — proof that a scan, check or lookup actually took place: which mechanism ran, against which source, with what result.
- Applicable requirement references — which governed rules were in scope at that moment, so the comparison can be reconstructed later even after amendment.
A screenshot of a status label, a verbal assurance, or a re-derived guess about what the record probably said at the time are not evidence. Evidence is retained at the moment it is created; it cannot be reconstructed convincingly after the fact from memory or inference.
03Evidence Versus The Finding
The most common confusion is treating the condition and its evidence as the same thing. They are produced together but serve different purposes and answer different questions.
| Concept | Question It Answers |
|---|---|
| Compliance condition | What is the current state, right now, for this identity? |
| Compliance evidence | What proves that state was reached honestly, and on what basis? |
| Compliance status | What label is published for the public or a scanning party to see? |
| Audit history (category 07) | What is the full sequence of events, changes and evaluations over time? |
A condition can be correct without being evidenced — briefly, before retention completes. It cannot be defensible without being evidenced. Defensibility is the whole point of keeping evidence at all.
This route deliberately stops short of the audit trail. Category 07 routes — event history, status change history, verification and certification evidence, evidence preservation and evidence retrieval among them — govern the deeper mechanics of how evidentiary material accumulates into a queryable history over the life of an identity. This route describes what qualifies as evidence and the obligations around it at the point of creation; it does not restate that machinery.
04Who Can Retrieve Evidence
Evidence is only useful if the right parties can reach it and the wrong parties cannot. Retrieval is governed, not open by default.
- 1Identify the requesting party's authorizationA request to retrieve evidence is evaluated against the requester's role and standing before any material is returned.
- 2Match the request to the identity and windowEvidence retrieval is scoped to a specific registered identity and, typically, a specific time window or event.
- 3Return the basis, not a reinterpretationWhat is returned is the original retained material — basis, timestamp, artefacts — not a fresh summary or a newly computed opinion about what it means.
- 4Log the retrieval itselfThe act of retrieving evidence is itself recorded, so that access to sensitive proof is traceable in turn.
Typical authorized parties include the issuer or company the identity is associated with, operators with a recognised compliance role, regulatory or audit parties acting under recognised authority, and governance itself where a rule's application is in question. A member of the public presented with a scan result does not automatically gain the right to pull the evidence behind it — the published status and the underlying evidence sit at different access levels for a reason discussed further in the privacy and authorized-access category.
05Preservation Obligations
Evidence that can be quietly altered or lost defeats its own purpose. Preservation is the set of obligations that keep retained evidence trustworthy for as long as it might be needed.
- ✓Evidence is retained in a form that cannot be silently edited after the fact.
- ✓Evidence is not deleted because the underlying condition later changed or was superseded.
- ✓Evidence tied to an active dispute, investigation or certification decision is held beyond any ordinary retention window until that matter resolves.
- ✓Evidence retention periods are set by governed policy, not left to case-by-case discretion.
- ✓Where evidence must eventually be purged, the fact that it existed and was purged under policy is itself recorded.
Preservation does not mean every piece of evidence is kept forever without limit — that is a retention-policy question outside this route's scope. It means that whatever the policy sets, evidence cannot be overwritten, contradicted or quietly discarded outside that policy simply because it becomes inconvenient later.
06System Relationship
Compliance evidence is what lets every other layer trust a condition without re-deriving it from scratch each time.
System Chain — Six Locked Entities
- 1QuickResponseCode.usRoot / System EntryPublic entry point to the QR infrastructure.
- 2QRProtocol.usGovernance (Rules)Writes and governs the applicable rules.
- 3QRCompliance.usValidationValidates compliance readiness against applicable rules and conditions.
- 4QRCertified.usCertification AuthorityAuthorizes the QR for certification.
- 5QRRegistered.usRegistration ResultMandatorily registers the authorized QR.
- 6QRCodex.usOperations / RecordsRecords, operates, logs and preserves canonical operational truth.
No registration → no certified QR output.
| Layer | Relationship To Compliance Evidence |
|---|---|
| ROOT — QuickResponseCode.us | Establishes that any identity capable of holding a condition can also hold evidence for it. |
| GOVERNANCE — QRProtocol.us | Sets retention policy and the rules for what must be captured as evidence. |
| VALIDATION — QRCompliance.us | Produces the basis and fixes the timestamp at the moment a condition is composed. |
| AUTHORIZATION — QRCertified.us | Relies on retained evidence when a certification decision is challenged or reviewed. |
| REGISTRATION — QRRegistered.us | Supplies the identity-level record facts that become part of the evidentiary basis. |
| OPERATIONS — QRCodex.us | Holds the durable audit history that evidence feeds into over the identity's lifetime — see category 07. |
Where retained evidence appears to conflict with QRCodex.us history, Codex governs and the discrepancy is investigated, not resolved by preferring one record silently.
What This Does — And Does Not — Do
Does
- ✓Capture basis records, timestamps and verification artefacts at the moment a condition is composed
- ✓Distinguish the finding (condition) from the proof of the finding (evidence)
- ✓Scope retrieval to authorized parties and log the retrieval itself
- ✓Preserve evidence tied to open disputes or reviews beyond ordinary retention windows
- ✓Retain requirement references so past comparisons can be reconstructed after later amendment
Does Not
- ✕Restate or duplicate the deeper audit-history mechanics governed by category 07
- ✕Allow evidence to be edited or quietly discarded outside governed retention policy
- ✕Grant public scan access the same retrieval rights as an authorized compliance party
- ✕Treat a published status label or a screenshot as a substitute for retained evidence
- ✕Reconstruct evidence from memory or inference after the original basis was not retained
Related Routes
Common Questions
Is compliance evidence the same as the compliance condition?
No. The condition is the finding — satisfied, failing, and so on. Evidence is the retained proof that the finding was reached on a specific basis at a specific time. They are produced together but answer different questions.
Who can pull compliance evidence for a given identity?
Retrieval is scoped to authorized parties — typically the associated issuer or company, recognised operators, regulatory or audit parties, and governance — and each retrieval is itself logged. A member of the public viewing a scan result does not automatically gain retrieval rights.
Can retained evidence be edited if the underlying condition later changes?
No. Evidence is retained in a form that cannot be silently edited, and it is not deleted or rewritten because a later evaluation produced a different condition. The original basis stays intact.
How is this different from the audit history discussed in category 07?
This route defines what qualifies as evidence and the obligations around capturing, retrieving and preserving it at the point of creation. Category 07 covers the deeper mechanics of how that material accumulates into a queryable event history, status-change history and verification trail over an identity's lifetime.
Does evidence have to be kept forever?
Not necessarily. Retention length is set by governed policy rather than case-by-case discretion, though evidence tied to an open dispute or review is held beyond the ordinary window until that matter resolves, and any eventual purge is itself recorded.
What happens if evidence was never captured for a condition?
The condition may still have been correct, but it is not defensible. Without retained basis, timestamp and verification artefacts, nobody can later prove on what grounds the finding was made.