How will evidence quality, accountability and business impact be governed?
Trust is designed through records, responsibilities and review—not declared in a methodology statement. Evidence governance must make it possible to determine what was known, how it was produced, who challenged it, what decision followed and what later happened.
The system should be rigorous in proportion to consequence. Excessive control makes intelligence irrelevant; insufficient control makes it unsafe.
1. Evidence standard
Every material claim should record:
- original source and publisher;
- collection/access date and reference period;
- method, population and coverage where applicable;
- licence, consent and confidentiality constraints;
- transformations, calculations and AI involvement;
- corroboration and contrary evidence;
- analyst confidence and rationale;
- approved use and review date.
ISO 20252:2026 establishes service requirements for market, opinion and social research, including insights and data analytics.1 The ICC/ESOMAR Code adds principles of duty of care, minimisation, privacy, fit-for-purpose work, transparency and professional responsibility.2
2. Separate epistemic layers
Label:
- Fact: directly supported observation with scope and date.
- Estimate: modelled quantity with assumptions and uncertainty.
- Inference: interpretation connecting evidence.
- Scenario: plausible internally coherent future.
- Recommendation: proposed action based on objectives and trade-offs.
This prevents recommendation language from laundering uncertainty into fact.
3. Governance by risk tier
Tier 1 — routine
Public, low-sensitivity evidence; analyst review and sampled QA.
Tier 2 — material
Influences investment, proposition or customer action; named reviewer, triangulation and documented confidence.
Tier 3 — consequential
High financial, legal, privacy, safety or reputational consequence; independent challenge, specialist review, executive approval and retained audit package.
4. Review mechanisms
Use source verification, reproducible calculation, methodological review, privacy/security review, red-team challenge and decision-owner acceptance. Reviewers should test the strongest alternative explanation and identify what evidence would reverse the conclusion.
The 2026 Magenta Book describes good evaluation as useful, credible, robust, proportionate and tailored to decision makers; it also stresses transparency, preservation of materials, uncertainty communication and evaluation before, during and after action.3
5. Performance scorecard
Decision contribution
- priority decisions supported in time;
- option set or confidence materially changed;
- investment accelerated, adapted or stopped;
- avoidable exposure reduced.
Evidence quality
- traceable material claims;
- independent corroboration;
- correct and live source references;
- disclosed uncertainty and limitations;
- reproducible quantitative outputs.
Operational performance
- signal-to-review lead time;
- analyst effort by value tier;
- stale-source and duplicate rates;
- review completion and incident closure.
Learning and calibration
- forecast accuracy and confidence calibration;
- assumptions updated;
- post-decision reviews completed;
- recurring failure modes reduced.
6. Trend history
For each report, preserve version, evidence reference period, change record and earlier Git history. Classify updates as new evidence, changed signal, revised interpretation or changed recommendation. Never overwrite history merely to make past work appear current.
7. AI governance
Apply NIST’s Govern, Map, Measure and Manage logic.4 Maintain system inventory, purpose, data boundaries, evaluation set, access, incident process and named owner. Verify citation existence and support; language-model fluency is not evidence quality.
8. APAC and Hong Kong application
Govern source comparability, language and jurisdiction. Hong Kong personal-data use should align with applicable obligations and PCPD guidance; market-specific legal advice remains necessary.5 Regional synthesis should retain local caveats rather than erase them.
9. Research QA gate
Before website publication, confirm:
- decision and audience are explicit;
- primary sources support material facts;
- dates, definitions and geographies align;
- facts, inference and recommendations are separate;
- contrary evidence and limits are visible;
- AI-generated text and calculations are verified;
- links resolve and citations are complete;
- APAC/Hong Kong claims have local evidence;
- editorial language remains business-first and accessible;
- approval and next-review date are recorded.
11. Decision playbook
Create an evidence-control matrix that matches claim consequence to required provenance, corroboration, reviewer and retention. A routine descriptive signal may need one verified source; a recommendation affecting major capital should require independent evidence, model review and recorded challenge.
Use a quality incident taxonomy: nonexistent source, source does not support claim, stale evidence, definition mismatch, calculation error, privacy breach, undisclosed AI transformation, overconfident inference and missed contrary evidence. Track root cause and recurrence rather than correcting only the visible sentence.
Governance should also stop low-value work. Review whether an intelligence product reached a decision, arrived in time and altered action or confidence. Retire recurring outputs that have no accountable user.
12. Failure modes
Avoid citation counts as a proxy for truth, review checklists without challenge, confidence labels with no calibration, and audit trails that cannot reproduce the conclusion. Independence matters: the person advocating an investment should not be the only reviewer of the evidence supporting it.
The repository itself is part of governance. Git history preserves prior interpretation; report metadata preserves reference dates; the research index preserves programme logic. Public pages should link only to editorially approved versions, while deeper working evidence remains controlled according to rights and sensitivity.
Sources
1International Organization for Standardization, *ISO 20252:2026*. https://www.iso.org/standard/88881.html
2ICC and ESOMAR, *International Code* (2025 revision). https://community.esomar.org/uploads/public/knowledge-and-standards/codes-and-guidelines/ICCESOMAR-International-Code_English.pdf
3HM Treasury and Evaluation Task Force, *Magenta Book* (2026). https://www.gov.uk/government/publications/the-magenta-book/magenta-book-central-government-guidance-on-evaluation-html
4NIST, *AI Risk Management Framework 1.0*. https://www.nist.gov/itl/ai-risk-management-framework
5Office of the Privacy Commissioner for Personal Data, Hong Kong, *AI Model Personal Data Protection Framework* (2024). https://www.pcpd.org.hk/english/resources_centre/publications/files/ai_protection_framework.pdf
Apply this research
Turn the framework into a decision, evidence plan and practical next move for your organisation.
