# GRC Evidence and Review Checklist

- [ ] Define system, repositories, deployment environments, data classification, and accountable owner.
- [ ] Record the applicable policy/control identifiers and approval status.
- [ ] Confirm retention, residency, access, deletion, and legal-hold requirements before purchase.
- [ ] Map findings only as evidence relevant to controls; do not label the tool or organization certified.
- [ ] Retain analyzer/ruleset/parser versions, artifact hashes, timestamps, reviewer decisions, and exceptions.
- [ ] Require separation of duties for exception approval and production release.
- [ ] Record accepted risk rationale, approver, scope, compensating control, and expiry.
- [ ] Sample closed findings and verify remediation evidence each reporting period.
- [ ] Reconcile CI evidence to the exact deployed commit/image digest.
- [ ] Document gaps for unsupported languages and compensating scanners.
- [ ] Review access and revoke stale service identities quarterly.
- [ ] Test evidence export and auditor-readable retrieval before the audit window.

MetaSolve evidence can support assessment workflows. It does not itself grant certification, regulatory approval, or a complete control conclusion.
