Add evidence where it is used: a framework requirement, policy, control, system, third party, risk demand, risk assessment, remediation plan, audit response or business profile record. Confirm the selected item and version before attaching anything.

Add a file

  1. Open the source record and its Evidence or Evidences action.
  2. Choose the file attachment action when it is available. For example, a system record offers Add evidence → Upload file → Choose files.
  3. Check the displayed restrictions and workspace storage availability.
  4. Select the intended files. In the attachment controls, choosing a file can start its upload immediately; it is not just a preview.
  5. Wait for the upload result, then verify that each expected attachment appears on the source record.
Evidence attachment controls with Upload file and Add link tabs, Choose files drop zone and Cancel.
Upload file opens the source record’s attachment controls. Choosing files can start their upload immediately. Open full-size screenshot.

Use clear names that identify the subject and assessment period. Where a newer document supersedes an older one, follow your retention process before removing the original. Evidence attachment is separate from saving other fields on the page.

Use the link attachment option, enter a descriptive name and the full HTTP or HTTPS address, then submit the link. A name such as “Access review — Q3” is more useful than an unexplained URL.

Add link controls with empty Name and URL fields, Cancel and disabled Add the link action.
A link attachment needs a descriptive name and destination URL. Add the link stays disabled until the required values are supplied. Open full-size screenshot.

A link keeps its target in the external system; it does not copy the target document into CSFaaS or grant readers access there. Check that the intended reviewers can open the destination and that it will remain available for the required retention period.

If an action is unavailable

Attachment rights follow the source module and record state. Check that you are working on the intended editable version and have the required permission. A read-only or completed record may restrict changes.

When workspace file storage is disabled, the interface provides links-only behavior for new attachments. Existing stored evidence is not erased by that setting. Review the current allowance and configuration in the workspace before relying on an old quota or price from previous documentation.

After attaching, open the item in Evidences to verify its source association and available preview. Form answer uploads are managed with the response rather than added automatically to this central library.