EvidenceSheet

MS-2.13 Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented

Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. The evaluation apparatus is itself evaluated, for whether the metrics still discriminate, whether they are be

4
artefacts
2
held by a system
1
at each review
easy
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Evaluation of whether the TEVV metrics remain effective and discriminating · Policy repository / GRC workspace
  • Consideration of gaming, saturation and drift in the metrics themselves · Policy repository / GRC workspace

periodic reviewEvidence produced at each review

  • Review of assumptions embedded in the measurement approach · Document repository

governing documentDocuments that govern the control

  • Changes made to TEVV processes as a result · Document repository

First move

Automate the pull from your Policy repository / GRC workspace. Version-controlled policy set with approval metadata; review dates tracked as records, not a calendar note.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

MS-2.12 Environmental impact and sustainability of AI model training and management activities as identified in the MAP function are assessed and documented · MS-3.1 Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts