メインコンテンツへスキップ

Controls and evidence

The Controls and evidence page is the central compliance management tool in the MSP workspace. It helps you track and complete the evidence tasks for your MSP certification.

Dashboard

In the MSP Workspace, select Controls and evidence under Evidence workspace in the sidebar to launch its dashboard.

MSP Control and evidence

The dashboard consists of the following parts:

  • Phase tabs: Filter controls by certification phase: Phase one – Prerequisites or Phase two – Technical Validation.

  • Domain summary cards: Display how many controls are completed for each domain.

  • Filters: Let you narrow the table by search term, workspace section (domain), evidence status, or assignee.

  • Control breakdown table: Displays basic information for each control.

    • Evidence status: Each control moves through the following statuses:

      • Not started: No work has begun on the control's evidence tasks.

      • In progress: At least one evidence task has moved to an active state. This transition happens automatically.

      • Awaiting completion: All evidence tasks have reached a "done" state. The control is ready for a Section Owner to review and complete. This transition happens automatically.

      • Complete: The Section Owner has reviewed and marked the control as complete.

    If an auditor flags a control during a certification package review, that control will show an Auditor flagged badge and requires remediation before it can proceed.

Control detail

When you select a control from the breakdown table, a side panel shows its full details.

MSP Control detail side panel

  • Control details: Basic information of the control, including the Owner, the Due date (the target completion date or the overdue days), and the Approver who approves the control once all evidence tasks are complete.

    • A Section Owner or a Workspace Admin can edit the due date of a control.
  • Control requirements and AI assessment: The criteria that must be satisfied for the control.

    If the control has an AI assessment available, the panel displays the assessment results to help you identify gaps. The AI assessment is for advisory purpose only. Human approval is required before a control can be marked as complete.

  • Auditor feedback: When a control has the Auditor flagged status, a banner appears with the auditor's feedback. If the control was flagged more than once, select View earlier feedback to expand a list of previous comments.

  • Evidence tasks: All tasks associated with the control. You can select the name of an evidence task to open the task detail side panel, or select an associated artifact name to open a full-page preview of the artifact.

  • Comments and activity: Displays a unified feed of comments and activity events on the control. Activity events include user actions such as uploading artifacts and AI actions such as identifying gaps. Any active workspace member can post a comment using the text composer at the bottom of the section.

  • Complete control: Available when all evidence tasks for the control are done. The control reaches Awaiting completion, and a Section Owner can mark it as complete.

Evidence task detail

The task detail side panel displays full details about that task.

MSP evidence task detail side panel

  • Evidence details: Displays basic information about the evidence task:

    • Assignee: The assignee of the task.

    • Due date: The target completion date or the number of overdue days. Section Owner, Workspace Admin, and other roles that can manage task actions (same as task reassignment) can edit the due date of an evidence task.

    • Approver: The workspace member to approve the evidence task once all artifacts are approved.

  • Evidence acceptance criteria and AI assessment: Displays the criteria that must be satisfied and the AI assessment results.

  • Comments and activity: Displays a unified feed of comments and activity events on the evidence task. Any active workspace member can post a comment using the text composer at the bottom of the section.

Reopen a completed task

When an evidence task has a status of Done, you can reopen it directly from the task view page or the task detail side panel.

The ability to reopen a task depends on your workspace role:

  • Workspace Admin and Section Owner: Can always reopen tasks.

  • Contributor: Can reopen a task only if they are the current assignee.

  • Approver and Informed: Cannot reopen tasks.

Once reopened, the task transitions back to In progress.

Artifacts

Uploaded artifacts appear in the detail side panel of the control as well as the associated evidence task.

Select the artifact name (or select the kebab menu () and then select View artifact) to open a full-page preview of the artifact. Files that cannot be previewed inline display a download button instead.

MSP evidence task detail - View artifact

Choose an action from the Artifact options dropdown:

  • Download artifact: To download the artifact.

  • Upload new version: To upload a new version of the artifact. See Upload artifacts.

  • Delete artifact: To permanently remove the artifact. You'll be prompted to confirm the deletion before its execution.

Review an artifact

Approvers can approve, request a change, or reject an artifact.

  1. In the artifact side panel, select Review artifact.

  2. Select a review type. If you choose Comment / Request changes or Reject, you must provide a review summary.

    MSP - Review artifact

  3. Select Submit review.

Upload artifacts

You upload artifacts as evidence for compliance controls by attaching files (documents and images) or link URLs that point to publicly accessible web pages.

  • Each evidence task accepts up to five documents and 20 images.

  • Individual file size limits depend on the file type: the maximum size for a document is 50 MB, while for an image is 3.75 MB.

  • Link URL artifacts do not have file size limits.

The Upload artifacts dropdown on the task detail side panel provides two options:

  • Upload new artifact: To attach one or more new evidence files or link URLs to the task.

    Link artifacts are stored as-is and go directly to human review without AI assessment. Only public URLs that are reachable without a login are supported.

    MSP - Upload new artifact

  • Update an existing artifact: Available when the task has at least one artifact.

    This option lists all artifacts currently attached to the task. Select the one you want to replace, then upload a replacement file. See also Upload a new artifact version

    MSP - Update an existing artifact

AI assessment

The system runs an AI assessment to evaluate uploaded documents against the control's requirements.

  • AI assessment applies only to file-based documents; images and link URL artifacts are not assessed by AI but go to human review.

  • AI assessment has a separate size threshold of 4.5 MB. Documents larger than 4.5 MB are accepted for upload and available as evidence for human reviewers.

There are three AI assessment results:

  • Pass: The document satisfies the control's requirements.

  • Gaps detected: The AI identified gaps between the document and the control's requirements.

  • Not assessed: AI assessment was skipped, typically because the document exceeds the size limit. A human reviewer can still evaluate the document as evidence.

Select the assessment result to view assessment details.