Case Study 02Audit readiness · Collections & lending

What You Cannot Prove: The Evidence Gap Nobody Finds Until an Auditor Asks

Ask a collections floor to prove its agents did not use threatening language last quarter. The honest answer is: here are the forty calls we reviewed. This case study is about the other 7,960 — and why evidence has to be produced at the time of review, not assembled the week an auditor calls.

Verbatim
quote required on every flag
1 click
from a finding to the audio
5 × 3
perspectives × severity grades
0
evidence for calls nobody heard
A register of calls. Most records are hollow because nobody reviewed them; a reviewed one opens into a verbatim quote, a timestamp and a link back to the audio.

Key findings

  1. Evidence has to be produced at the time of review. A binder assembled the week an auditor calls is not evidence — it is an artefact of the audit.
  2. The evidence gap sits downstream of the coverage gap and cannot be closed independently of it.
  3. A finding without a verbatim quote and a timestamp is an opinion. Compliance teams cannot defend opinions.
  4. Publishing what you do not certify is a trust asset. We do not claim HIPAA or PCI certification, and we say so before anyone asks.

The question that has no good answer

A compliance officer at a lending client asks your collections floor a simple question: show me that your agents did not use threatening language last quarter.

The honest answer, on most floors, is: here are the forty calls we reviewed.

For the other 7,960 there is no finding. No note. No reviewer’s name. No record that a review ever happened at all. Not because anything was concealed — because nobody listened, and nothing that nobody listened to leaves a trace.

This is the moment the coverage gap stops being an operational inefficiency and becomes a legal exposure. Up until the question is asked, a 5% sample feels like prudent resource allocation. The instant somebody says show me, it becomes 7,960 calls about which your organisation has no position, no evidence, and no defence.

Zero. That is the number of calls you can produce evidence for, out of everything nobody reviewed.

Why nobody catches this in advance

Because evidence is not a document you can produce later. It has to be created at the time of review.

A binder assembled in the week an auditor calls is not evidence. It is an artefact of the audit — and any competent reviewer will treat it as one, because its existence is explained entirely by the audit rather than by the process it claims to document. Retrospective review of a call from eight months ago tells you what a reviewer thinks today, not what your quality process caught at the time.

Which means the evidence gap is structurally downstream of the coverage gap. You cannot produce evidence for every call without reviewing every call. The two problems are the same problem, and no amount of documentation discipline closes the second one while the first is open.

There is a second reason it stays hidden: nothing on a QA dashboard displays it. Dashboards report on what was reviewed. The reviewed set looks complete because it is complete — of itself. The denominator never appears.

What an evidence trail has to survive

The bar is not “we have a report.” The bar is a specific, adversarial question, asked months later by somebody with no interest in your process:

  • Which call? — identified, retrievable, dated.
  • Where in the call? — a timestamp, not a summary.
  • What exactly was said? — the words, verbatim, not a paraphrase.
  • Who decided it was a problem, and how serious did they call it? — a named grade from a stated scale.
  • What did you do about it? — an owner, an action, a date it closed.

A finding that cannot answer all five is an opinion. Compliance teams cannot defend opinions, and they know it, which is why they discount QA findings that arrive without provenance.

What we changed: evidence as a constraint, not a convention

Three mechanisms, all enforced by the system rather than encouraged by policy. That distinction matters — conventions decay under deadline pressure, constraints do not.

1. Every flag carries an exact transcript quote, mandatorily

The analyst instruction is not a guideline. A flag without an exact transcript quote attached does not ship, because without it the client’s compliance team cannot defend the finding to anyone. There is no “summary” fallback and no paraphrase path.

This has a cost we accept deliberately: it constrains what the system is allowed to assert. A pattern that cannot be tied to specific words in a specific call does not become a flag. We would rather report less and have all of it hold up.

Each flagged moment in the weekly report carries a link that opens the recording at the second it occurred. The report is a funnel back into the evidence, not a substitute for it. Somebody challenging a finding does not have to take our word, or the analyst’s word — they can listen to it in one click and form their own view.

That is also, quietly, the strongest quality control we have on ourselves. A finding that anyone can check in one click is a finding we have to be right about.

3. Even the scoring has to be defensible

The principle the pipeline is built to: every point of a call’s negative percentage must be defensible against a specific segment and the words in it — because a customer can and will ask “you said X% negative; where, and for what words?”

A sentiment number that cannot be decomposed back to the segments that produced it is a number nobody should act on. So the decomposition is not an optional drill-down; it is the thing the number is made of.

The shape this produces

Findings are graded across five review perspectives at three severity levels — fine, small, or serious — and the grades never blend into a single composite. The result is a severity-graded audit trail that builds continuously, week by week, rather than being assembled on demand.

That is precisely the shape an RBI review, a DRA-code review, or a client’s quarterly business review expects: not a summary produced for them, but a record that already existed before they asked.

What we do not claim

We do not claim HIPAA or PCI certification.

We put that in writing on the FAQ, in the documentation, and here, because a buyer evaluating a compliance-adjacent vendor is entitled to know the boundary before they are three months into an implementation. Recordings are hosted in AWS ap-south-1 (Mumbai) and the data stays in India — that is architectural, not a policy statement. But region residency is not a certification, and conflating the two would be exactly the kind of over-claim this case study is arguing against.

If a certification is a hard requirement for your procurement process, that is a real constraint and you should weigh it. We would rather you find out from us now than from your auditor later.

Where to start

The fastest way to see whether you have an evidence gap is to run the test yourself. Pick a compliance question your regulator or your largest client could plausibly ask about last quarter. Then try to answer it from what your QA function actually holds.

If the answer is a number of reviewed calls rather than a position on the period, the gap is open.

Book a demo and we will show you the evidence trail the platform produces, quote by quote.


Related: The 5% Illusion covers the coverage gap this one sits downstream of.

Curious what is in the 95% you never hear?

Book a demo and we will walk you through the platform — how the reviews work, what the reports contain, and how the evidence trail is built.

Book a Demo