A control backed by a check is not an assertion. Each one runs a deterministic test over data polled from the systems you have connected, on a schedule, and a run records pass or fail alongside the raw API response and the moment it was read. That payload is the evidence an auditor gets — a dated reading, not a colleague's word.
- Scheduled check runs against connected systems
- Pass/fail bound to the control it evidences
- Raw response retained and timestamped with each run
- Verdict visibility carried through to the standards view
- Inheritance along mapped frameworks — evidence once, answer in both directions
This is the mechanism the American trust-management platforms repositioned around. The difference is where it runs: on your infrastructure if you want it there, against your own read-only credentials, with the evidence staying inside your trust boundary.