Mapping evidence to controls shows auditors how your controls are implemented and maintained. This is especially important for controls that don’t rely on automated monitoring tests and instead require manual proof, such as policies, screenshots, reports, or tickets.
By mapping evidence directly to controls in Drata, you keep audit documentation centralized, current, and easy to review, which reduces audit back-and-forth and improves control readiness.
Prerequisite
Drata roles: Admins, Information security leads, Workspace managers, Control managers, DevOps engineer have access to this section within Drata.
Map Evidence to Controls
You can link evidence to controls from either the Controls page or the Evidence Library.
Option 1: Map Evidence from a Control
Use this method when you want to attach manual evidence (files or URLs) directly to a specific control.
Go to Controls.
Select a control to open its details page.
Open the Evidence tab.
Select Add evidence.
From here, you can either:
Select existing evidence from the Evidence Library, or
Add new (miscellaneous) evidence by uploading a file or adding a URL.
Upload a File as Evidence
Use file-based evidence for items such as screenshots, reports, exports, or written procedures. When uploading a file:
Enter a name and description (optional; the file name is used if omitted).
Enter a creation date and renewal date.
These dates affect control readiness.Upload a supported file type.
Supported file types: CSV, DOCX, GIF, JPEG, JSON, ODP, ODS, ODT, PDF, PNG, PPTX, TXT, XLSX, ZIP
File size limit: 25 MB per file
Add a URL as Evidence
Use URL-based evidence when proof lives outside Drata, such as:
Ticketing system links (for example, Jira or ServiceNow)
External dashboards
Hosted documentation or internal tools
When adding a URL:
Enter a name (required).
Enter creation and renewal dates.
Optionally add a description.
Select Save.
Save the Evidence
Once all required fields are complete, select Save. The evidence is now linked to the control and contributes to control readiness.
Option 2: Map Controls from an Evidence Item
Go to Compliance > Evidence.
Select an evidence and then the Control tab.
Map the desired control.
If the control you need does not exist yet, you can create a new control from this flow and then link it to the evidence.
Map Policies to Controls
Policies document intent, governance, and expectations for controls. Mapping policies to controls improves traceability and makes audits easier to follow. To map a policy:
Go to Controls.
Open a control.
Select the Policies tab.
Select Map policies.
Choose one or more policies and Save.
You can also select Create a new policy from the modal if needed.
Note: Drata’s templated policies are automatically mapped to applicable controls. You can unmap any policy at any time.
