EVIDENT

Methodology

How a conclusion is reached, and what is deliberately left unconcluded

A governance conclusion is only worth as much as the reasoning behind it. This page describes that reasoning in enough detail to be argued with.

The first question a data protection officer asks about any statement is what kind of statement it is. Was this observed in a system, asserted by somebody, written in a policy document, or worked out from other facts? Those four are not the same, and a tool that presents them identically forces every reader to go and ask a person.

EVIDENT keeps them apart, by construction.

Four classes of evidence

Observed
A fact read directly from a system. The column customers.email exists, is of this type, and is referenced by this code.
Declared
An assertion made by the organisation. The purpose of this table is account management; this field is kept for two years.
Documentary
Evidence carried in a controlled document. Retention policy v2, section 4.
Inferred
A conclusion derived from other evidence, with a confidence and a rationale. These two fields together create a possible re-identification risk.

Rules are deterministic, versioned and readable

Classification is done by explicit rules, not by a model deciding for itself. Each rule has a version, and every finding records the exact version that produced it — so a report from six months ago can be understood in the terms that applied six months ago, rather than the terms that apply today.

A pattern match is treated as a candidate and never as a conclusion. Context decides: the semantics of the table, the neighbouring fields, the foreign keys, the declared types, the comments, and the vocabulary of the organisation itself. A column named orientation in a table of solar panels is not a special category of personal data, and the distinction is the whole difference between a useful tool and a noisy one. Where the context says nothing at all — no comment, no mapped property, nothing in the table around it — a critical conclusion is proposed for review rather than asserted, because silence is not agreement. What needs no corroborating is a word with no second meaning: there is no ordinary sense in which a column called BiometricTemplate is about anything but a person.

Candidate detection -> Context enrichment -> Classification
                                 -> Confidence -> Review threshold

What comes out of that is two values, and they never share an enumeration. The legal category is what the regulation calls the data: personal data under Article 4(1), a special category under Article 9, conviction data under Article 10, or not established. The sensitivity level — standard, elevated, high — is EVIDENT’s own ordering, so a reviewer with six thousand fields in front of them starts with the ones that matter.

The GDPR defines no such scale. The básico, medio and alto that everybody remembers came from RD 1720/2007, which attached a closed list of mandatory measures to each level and is repealed; Article 32 replaced the levels with a criterion — measures proportionate to the actual risk, judged case by case. So every surface that shows a level says whose scale it is.

Articles 9 and 10 are held apart rather than stacked, because they are distinct regimes rather than two steps of one scale: Article 9 prohibits processing subject to its own exhaustive list of exceptions, and Article 10 permits it only under official authority or where a law provides safeguards. Folding the second into the first would put the wrong legal regime in front of somebody looking at a criminal-records table.

Between the two dimensions sits a mapping rule that belongs to EVIDENT and carries its own version, separate from the version of the naming rules. That separation is the point of the whole arrangement: the ordering can be argued with, and changed, without changing anything this product asserts the law says. And the citation is tied to the category rather than to the level, so a field ordered high whose category is not established cites neither Article 9 nor Article 10.

UNKNOWN is a result

Where the available evidence cannot support a conclusion, EVIDENT returns UNKNOWN and names the evidence it would need in order to decide. It does not guess, and it does not average a missing answer into a percentage.

This matters more than it sounds. False certainty is the failure mode of the whole category: an assessment that quietly assumes the best produces a number that looks like progress and hides the four places that would actually have mattered.

What we measure, and what we refuse to measure

We reportWe never report
Evidence Coverage — how much of the required evidence can actually be demonstratedA compliance score
Evidence relevant to, or mapped to, a controlThat you comply with a control
Possible or inferred risk, with confidenceA legal violation
Requires human reviewAI has determined
Evidence not found, or UNKNOWNAn assumption that things are fine

The human keeps the judgment

Findings are proposed, not imposed. A reviewer confirms what the analysis proposed, rejects a false positive with a reason, overrides it by naming the element it should have mapped to, or accepts a risk with an owner and a justification. Every decision records who made it, when, and why, and no decision is ever overwritten — a later one supersedes it and both remain readable.

Confirming and overriding are not the same act, and only one of them closes anything. A confirmation is a person agreeing with the analysis, and it settles the field. An override is a person saying the analysis mapped it to the wrong place and naming the right one — which is a better proposal, not an answer. It is recorded with who changed it and when, and the field stays open for review, now carrying the correction and the name of whoever made it. One person correcting something nobody has checked is exactly what this product refuses to print as settled.

Those decisions accumulate into something the organisation owns: validated classifications, false positives that will not be raised again, and policies that encode judgments already made. That accumulation is why a second assessment costs less than the first.

And a field is settled where it is drawn. Anything waiting on a person carries the control that decides it — in the field list and inside the schema diagram, on the row itself rather than on a mark beside it. Correcting a mapping by hand records who changed it and when, and leaves it unconfirmed: a correction one person made and nobody checked is a better proposal, not a settled answer, so it stays in the queue naming who changed it and to what.

Where AI is allowed, and where it is not

AI explains evidence, summarises findings, drafts remediation text and translates for an executive audience. It references the evidence it is talking about, and its output is always visibly distinguishable from evidence.

It does not create facts, declare compliance, override a deterministic rule, confirm a control, or turn a low confidence into a high one. Evidence-powered, AI-assisted — with humans keeping the judgment that matters.