Methodology
Requirements-to-Evidence Mapping
Governly is built around one methodology: every customer requirement should be mapped to verifiable evidence inside the vendor's own documentation. No questionnaire answers, no assumptions — only what the vendor has actually published.
How the mapping works
1. Define requirements
What does your organisation actually require from this vendor? MFA, EU hosting, ISO 27001 scope, sub-processor approval, encryption at rest, incident response SLAs — anything.
2. Upload vendor evidence
Any documentation that may serve as evidence: SOC 2, ISO 27001 certificate and SoA, DPA, security white paper, architecture, pen test, BCP, questionnaire.
3. Receive the mapping
Every requirement is mapped to its supporting evidence with source citations, an evidence strength rating, identified gaps and recommended follow-up questions.
Why evidence beats questionnaires
- Questionnaires capture vendor opinions; evidence captures vendor proof.
- Every finding cites the source document, page or section.
- Reusable requirements library — assess every vendor the same way.
- Traceable reports survive audits, procurement reviews and regulator questions.