Go Back

Why Every Workflow Should Produce Evidence

Angus BowerPosted on 13 Aug 2026

Turn each workflow into a source of proof, so your governance record is current by default instead of assembled on demand.

Two earlier pieces on this blog set up the ground this one builds on. Governance Is Becoming Alpha argued that governance has shifted from a binder to a live output, and that the managers who can show operational discipline quickly are the ones who close faster and survive scrutiny without scrambling. Building Institutional Trust Through Better Governance named the three properties an institution tests for, transparency, repeatability and evidence, and drew the line between a firm that reconstructs its evidence and one that generates it.

This piece goes one level down, to the place where the record is created or lost: the individual workflow, beneath the audit and the policy. If you carry governance inside a firm as a GC or head of compliance, this is a framework you can run against your own operation.

The Unit of Governance is the Workflow

Where a governance record comes from.

Your governance record is the sum of your workflows. A capital call, a valuation sign-off, an investor onboarding, a distribution, a secondary transfer: each is a workflow, and each one either leaves a usable record behind or it doesn't. The annual audit does not create the underlying operational record. It collects and tests what the workflows have left behind.

The distinction that is most important is when the record gets made. Governance evidence is not created when someone asks for it. It is created at the moment the underlying action occurs, or it is not created then and has to be rebuilt later from memory and fragments. That has an awkward implication for how the work is divided. A GC may own the policy, a compliance team the control framework, an administrator the process, but the evidence is produced by the operation itself, by whoever or whatever runs the step. The record depends on how the work runs, not on who owns the governance on paper.

That reframes the question. It stops being "is our governance good," which is hard to answer and easy to argue about, and becomes "does each workflow that matters produce evidence as it runs," which you can check. This is what we mean by continuous governance, and the term is narrower than it sounds. It does not mean approvals or committees run without pause. It means the evidence of governance is generated continuously by normal operations, rather than reconstructed periodically before a deadline.

One limit keeps the claim honest, and it is the same one our earlier trust piece drew. Evidence proves what happened and in what order. It does not prove the decision was correct. A valuation committee can follow every step and still land on the wrong number. What evidence gives you is the ability to show the process was followed, consistently, and to have that hold up when someone outside tests it. That is the bar, and it is a defensible one to be measured against.

What "Evidence" Means At the Level of One Workflow

Four things a record needs before it counts.

A log alone is not evidence. A controlled system log can be strong evidence; a line in a spreadsheet usually is not. What separates them is context and provenance. A record becomes evidence when it can answer a question without you in the room. For a single workflow, that means four things:

  • What happened: The action taken, in enough detail to be unambiguous.
  • Who or what authorised it: The person, role or automated check that signed off, and the rule they signed off against.
  • Against what: The data and the version of the rule or policy in force at that moment, not the version you hold today. This is provenance: not just what was decided, but which information and which rule governed the decision when it was made.
  • When: A timestamp that fixes the sequence, with any later change to the record attributable and visible.

This is the line between documentation and evidence. A PDF that simply reads "Capital call: approved" is documentation of an outcome. It records the outcome, but not necessarily the context around it. A record that also holds the obligation behind the call, the rule applied, the person who approved it, the data in front of them and the time it happened is evidence, because the action produced it rather than someone writing it up afterward. Documentation tells you what someone says happened. Evidence lets someone else confirm it.

A record carrying all four turns a scrutiny moment into a retrieval task. A record missing one of them turns the same moment into an investigation. The difference rarely shows up on a normal day. It shows up the week an allocator's operational due diligence team asks how a valuation exception was handled six months ago.

The framework earns its keep on the exception, not the standard path. A routine capital call is easy to evidence, because it followed the rule. The hard cases are the ones that did not: the investor with a bespoke side letter, the amended commitment, the late payment, the approval granted outside the normal sequence. These are ordinary in alternatives and private markets, and they are exactly what firms struggle to reconstruct later. A workflow that produces evidence has to capture the moment the standard rule is overridden as carefully as the moments it is followed, including who authorised the departure and on what basis.

hero-framework

Generate or Reconstruct: A Test You Can Run This Week

A short diagnostic for your own operation.

Pick your five highest-stakes workflows. For most managers that is onboarding, a capital call, a valuation exception, a distribution and a secondary transfer. Run each one against these six questions.

  1. If an allocator asked how this was handled six months ago, could you produce the approval chain inside the meeting, or would you need to call finance, operations and the administrator first?
  2. Is the record generated by the workflow itself, or assembled afterward from application forms, PDFs and email chains?
  3. Does the record capture the rule and the data version in force at the time, or only the outcome?
  4. Can the record or its history be changed without leaving a trace?
  5. Does it read the same regardless of who ran the workflow, or does it depend on one person's habits?
  6. When the workflow leaves the standard path, does the exception, and who approved it, become part of the record automatically, or does someone have to remember to note it?

Count the workflows that generate on all six. That count, more than the length of your compliance manual, is a fair proxy for how you will look under an ODD call or an audit. It is also a cleaner place to spend effort than adding another policy to the binder.

diagnostic-checklist

A regulator has put the same point in writing. In its March 2025 review of private market valuation practices, the UK Financial Conduct Authority found that nearly all the firms it looked at had valuation governance in place, usually a valuation committee, yet in a number of cases the record of how a decision was reached was too thin to show the process behind it. Having the control was not enough. Firms also had to show how it operated in practice. That is the gap this test is built to find.

two-paths

Where the Workflow Becomes Evidence

The layer that lets a workflow record itself.

A workflow can only produce reliable evidence if the system running it already holds the four things evidence needs: the data in play, the rule that applies, the approval required and the order the steps run in. Keep those together and the system can generate the record as the work moves. Scatter them across inboxes and spreadsheets and the record has to be rebuilt by hand. That is the difference an orchestration layer makes. Making one workflow behave this way is a matter of discipline. Making every workflow behave the same way, across entities, cycles and staff turnover, is a matter of infrastructure.

In the Tranche:os stack, route is that layer. It sequences tasks, approvals, checks and reporting for back- and mid-office workflows, so each step carries the context the next one needs and the compliance check sits inside the workflow rather than beside it. A step can be configured so capital does not move without the required sign-off. Because the work runs through that layer, the record of what happened, who approved it, against which rule and when is written as the step completes. It then persists in the registry that source holds, where it stays verifiable.

Notice what that changes. The evidence is generated as the work happens, not written up afterward. The governance record stays current because it is a by-product of the operation.

None of this presumes a single fixed setup. Which checks are embedded, which steps need a human sign-off, which run automatically, and where each record is written are configured to your structure and your obligations. Used this way, route can sit above the systems you already run, governing what is in place, or operate as part of the full stack. The point is not a particular rail. The point is that the workflow leaves the evidence behind either way.

What This Can Move for Compliance and Legal

The job changes shape.

This moves the compliance and legal job away from repeatedly reconstructing evidence and toward maintaining the controls that generate it. It does not remove evidence-gathering. It changes the balance of the work. The binder stops being a document you refresh once a year and set aside. It becomes a live output of how the business runs, consistent across every cycle and available to anyone who asks.

That matters more as routine external checking thins out. Oversight of wholesale structures has been lighter in Australia than in comparable regimes, and ASIC is closing that gap: a private credit programme that opened with Report 814 in late 2025 has carried into 2026 as a named enforcement priority, including a June 2026 call for funds to stand behind their 30 June valuations. Where no outside party checks your practices as a matter of course, your own operating evidence is what allows you to demonstrate how the control actually operated. A workflow that generates its record is how you hold up that end without a scramble.

Start With One Workflow

A practical first step.

You do not need to instrument every workflow at once, and most operators don't. Start with the one that would be hardest to explain six months from now. If its evidence still has to be assembled from people, systems and inboxes after the fact, that is where the work begins.

That is the workflow that needs mapping first. A walkthrough can show where its evidence is generated today, where it is reconstructed, and what would need to change.

Tranche:os Whitepaper Cover