SAMPLE EVIDENCE PACK — NOT REAL EVIDENCE ======================================== Every record in this pack is fictional. It was generated by Policyflow's real evidence export using invented data, to show the shape of the output. It is not evidence about any organisation, and it is not an audit result. What this pack is ----------------- A worked example of what Policyflow exports after a policy acknowledgement campaign. It was produced by the product's own export code, using invented data for a fictional company. Fictional workspace: SAMPLE — Northwind Instruments (fictional) Fictional campaign: SAMPLE — Information Security Policy acknowledgement (Q1 review) Policy version: SAMPLE — Information Security Policy — version 3 (policy_version_id 5a11e000-0000-4000-8000-00000000d003) Recipients: 8 Acknowledged: 5 Outstanding: 3 Export date shown: February 20, 2026 What the records show --------------------- * Which policy version each acknowledgement is bound to, by version id and by content hash. An acknowledgement does not move to a later version. * Who was asked, who confirmed, and the timestamp of each confirmation. * Who has not confirmed, and why — not yet opened, opened but not confirmed, escalated to a manager, or covered by an approved exception. * Reminders sent, escalations sent, and any recipient removed from scope. What the records do not show ---------------------------- * That anyone read or understood the policy. A confirmation is a recorded act of acknowledgement, nothing more. * That anyone complied with the policy afterwards. * That a certification body has accepted this as sufficient evidence. Sufficiency is the auditor's judgement, against your own ISMS scope. Files ----- SAMPLE-policy-acknowledgement-evidence-log.csv bytes: 7092 sha256: ea0cb1fe5d1a82ef126da6f893eb7a15c105ab4d3115206f0473102ca3c02aff SAMPLE-policy-acknowledgement-summary.pdf bytes: 236971 sha256: 2933729e542022527c35fe59ebd915aec54836465c136d024ccca941eefdfecc Every file above is byte-identical each time this pack is regenerated, so the checksums can be used to confirm the copy you are reading has not been altered. The CSV additionally carries a per-row sha256, so a single edited cell is detectable without re-checking the whole file.