Valeo · security governance / January 2026
An evidence filename is not a source of truth
The same control could have several filenames, folders and human labels. The important question was not what the document was called, but how to prove which source was current and authoritative.
Situation
In a large organization, evidence naturally appears across several channels: SharePoint, tickets, exports, reports and team-owned folders. That becomes painful during an audit. Two files with the same name may represent different points in time, and the filename alone says nothing about how either one was produced.
Approach
The register therefore captured more than a document name: source system, responsible system or role, validity period, and the exact question the evidence was meant to answer. Wherever practical, I referenced the system that generated an export rather than treating the exported file itself as the authority. The goal was that another engineer or auditor could later reproduce the evidence through the same path.
Outcome
There were fewer arguments about whether two similarly named files were 'the same thing', and stale or manually copied material became easier to identify. Evidence started to be treated as the result of a reproducible query or process rather than as a final file, which also made future refreshes faster.