Methodology

Requirements-to-Evidence Mapping

Governly is built around one methodology: every customer requirement should be mapped to verifiable evidence inside the vendor's own documentation. No questionnaire answers, no assumptions — only what the vendor has actually published.

How the mapping works

1. Define requirements

What does your organisation actually require from this vendor? MFA, EU hosting, ISO 27001 scope, sub-processor approval, encryption at rest, incident response SLAs — anything.

2. Upload vendor evidence

Any documentation that may serve as evidence: SOC 2, ISO 27001 certificate and SoA, DPA, security white paper, architecture, pen test, BCP, questionnaire.

3. Receive the mapping

Every requirement is mapped to its supporting evidence with source citations, an evidence strength rating, identified gaps and recommended follow-up questions.

Why evidence beats questionnaires

  • Questionnaires capture vendor opinions; evidence captures vendor proof.
  • Every finding cites the source document, page or section.
  • Reusable requirements library — assess every vendor the same way.
  • Traceable reports survive audits, procurement reviews and regulator questions.