← All glossary terms

Evidence

Evidence gap

An evidence gap is a missing owner, status, date, decision, or record that weakens a governance claim.

Updated 24 July 2026

What it means

An evidence gap is a missing or weak piece of context that makes a governance record less useful. It might be a missing owner, unknown renewal decision, stale review date, missing purpose, unclear lifecycle status, incomplete access decision, or asset with unknown custody. Evidence gaps are not always technical failures; often they are missing operational context.

Why it matters

Gaps are useful when they are visible. A team cannot fix every record at once, but it can prioritize missing owners, stale reviews, and unclear decisions. Recording gaps honestly is better than producing a clean-looking report that hides uncertainty.

How CertPilot uses the term

CertPilot surfaces evidence gaps as review signals and summary counts across modules where appropriate. Those gaps do not always change technical health scoring. For example, domain governance gaps do not alter SSL or DNS status, and asset evidence-gap counts are summary evidence rather than a dedicated asset PDF.

What to record

  • Which field or decision is missing.
  • The record affected and owner responsible for follow-up.
  • Last reviewed date and next review target.
  • Whether the gap affects a report, queue, or management summary.

What not to assume

  • An evidence gap is not always an outage or security incident.
  • A gap should not be hidden to make a report look cleaner.
  • A gap count does not expose sensitive detail unless the report includes it deliberately.

How to use this term in a review

Use Evidence gap when you need a shared operating definition in a management report, access review, renewal review, domain review, or evidence-pack discussion. The goal is not to turn a glossary term into a control by itself. The goal is to make the scope, source, owner, status, date, and follow-up clear enough that a manager or client can understand what was reviewed and what still needs attention.

  • Use the related pages to move from definition to workflow.
  • Keep evidence wording precise and avoid audit, legal, or certification overclaims.
  • Record limitations when the source is public, manual, customer-entered, or incomplete.