Methodology · version 1.0
How future findings will earn publication.
This methodology is published before numeric findings so readers can evaluate the definitions, selection effects, controls and thresholds that will shape any later report.
Research objective
EvidenceFit intends to describe what small B2B suppliers are asked to provide, which people and records contribute, where claims lack support and what follow-up occurs. The unit of analysis is a reviewed observation about a compliance-request item or response event—not a company’s overall compliance.
What qualifies as a compliance request
An externally initiated questionnaire, tender requirement, audit request, evidence request or related follow-up that asks an organization to make or support a claim about governance, security, privacy, resilience, personnel, finance or assurance. Internal-only control testing is excluded unless it directly supports an observed external request.
Collection
Observations may be contributed by participating companies or advisers, or recorded during an EvidenceFit engagement with specific research consent. Each import passes through a reviewed JSON or CSV boundary. Google Sheets and Airtable exports use the same CSV validation path; the public site has no provider credentials.
Request classification
A reviewer assigns the most specific request type and one primary taxonomy category, then may record framework, contractual source and requester type where these are explicit. Classification uses the request’s assurance objective rather than spreadsheet section labels. Ambiguous cases are flagged rather than forced.
Evidence classification
Evidence is classified as policy, implementation evidence, operating evidence, self-attestation or unsupported claim, with more specific artifact types recorded separately. “Available” means identified for the response; it does not mean adequate, accepted or legally required.
Anonymisation
Public reports will not expose raw observations, company or requester names, questionnaire wording, domains, account identifiers, personnel, confidential contract text or sensitive evidence. Free text is excluded from public datasets by default. Published groups must be broad enough to avoid reasonable re-identification, and every release requires an anonymisation check.
Exclusions
Exclude observations without research consent, unverifiable synthetic records, duplicates that cannot be resolved, records containing identifying text that cannot be safely transformed, and entries whose source or meaning cannot be established. Product telemetry alone does not establish an accepted response outcome.
Duplicate treatment
Exact copies within the same request are one observation unless they concern distinct systems or owners. Reused wording across separate requesters remains separate only when each occurrence is independently observed. Reports must disclose whether their denominator counts questions, request packages, organizations or response events.
Outcome definitions
| Outcome | Definition |
|---|---|
| Accepted | Requester communicated acceptance or completed the relevant review without recorded follow-up on the item. |
| Rejected | Requester explicitly declined the response or evidence. |
| Follow-up | Requester asked for clarification, alternative evidence or remediation. |
| Unresolved | No reliable outcome was recorded by the observation cutoff. |
Lack of follow-up is not automatically treated as acceptance unless the collection context supports it.
Professional judgment
Record whether an appropriate participant identified a need for legal, privacy, audit, security, accounting, certification or other specialist interpretation. The flag describes coordination demand; it does not judge the advice or adviser.
Publication thresholds
A numeric benchmark remains unpublished unless it has at least 30 reviewed observations, a stated unit of analysis and collection period, complete methodology and limitations, an approved reviewer, a completed anonymisation check and a documented source-quality assessment. A report may set a higher threshold. Small or sensitive subgroups are suppressed even when the overall threshold is met.
Selection bias and limitations
Contributors are unlikely to represent all small B2B companies. Companies seeking help may receive harder requests, and advisers may see escalated cases. Wording, customer risk tolerance, industries and jurisdictions differ. Contributor recall, tool records and requester silence can be imperfect. Reports must state these limitations near findings and must not generalise beyond the observed sample.
Corrections and versioning
Material corrections will preserve a dated change note, affected finding, reason and recalculation status. Downloadable datasets receive a version and stable metadata. Previous files are retained where confidentiality and data rights allow.
Update cadence
The methodology is reviewed at least twice yearly while research is active. Reports set their own update cadence based on collection volume and material change. An update date never implies that every observation is recent.
Data access and citation
Only aggregate, disclosure-reviewed datasets may be downloadable. A release will state its licence or usage policy, schema, collection period, version, canonical URL and suggested citation. Confidential questionnaire text will not be published.