ITIL 4 — Change Advisory Board (CAB) Evidence Report
ITIL 4 Change Enablement evidence — change authorization, risk assessment, emergency change control, and complete audit trail for every merged change.
Overview
ITIL 4's Change Enablement practice governs how changes are proposed, assessed, authorized, and audited across IT services. The Change Advisory Board (CAB) is the forum where non-standard changes are reviewed and approved.
Koalr's ITIL CAB report generates a formal Change Enablement evidence package suitable for CAB review, ITSM audit, or ISO 20000 assessment. It treats every merged pull request as an ITIL change record and maps each to the four core Change Enablement controls.
Controls covered
CHG.01 — Change Authorization
All changes to services and infrastructure must be authorized by a designated change authority before implementation.
Koalr evidence: Every merged PR has a recorded approver and review timestamp. PRs without a required approval are flagged as authorization exceptions.
CHG.02 — Change Risk Assessment
Each proposed change must be assessed for risk and categorized (standard, normal, emergency) prior to approval.
Koalr evidence: Automated deploy risk scoring categorizes every change with a 0–100 severity and signal breakdown. Changes are mappable to ITIL categories:
| ITIL category | Koalr mapping |
|---|---|
| Standard | Low risk (score < 40), no DDL, no CODEOWNERS violation |
| Normal | Medium/high risk (score 40–85), peer-reviewed and approved |
| Emergency | Critical risk (score > 85) OR DDL migration OR CODEOWNERS violation |
CHG.03 — Emergency Change Control
Emergency changes follow an expedited but auditable approval process.
Koalr evidence: DDL migrations and critical-risk changes are flagged in the audit trail for retrospective CAB review. The report lists all emergency-category changes with the reason flag (DDL, blast radius, high risk score).
CHG.04 — Change Record & Audit Trail
A complete audit trail of all changes, approvers, and outcomes must be maintained.
Koalr evidence: Full merged change log with PR number, title, repository, author, reviewer, risk score, and signal breakdown. Exportable as PDF for human review or CSV for GRC ingestion.
Report output
- Dark navy cover page with ITIL 4 Change Enablement control badges (CHG.01, CHG.02, CHG.03, CHG.04) and metadata block prepared for Change Advisory Board (CAB) review
- Executive summary with six KPI tiles
- Per-control detail blocks with status badge and evidence count
- Complete change log table — the primary artifact for CAB post-implementation review
- Page number footer with CONFIDENTIAL marking
- Machine-readable CSV export
CAB integration patterns
Weekly CAB meeting prep
Run the report for the previous week. The change log table becomes the CAB agenda.
Post-implementation review (PIR)
Run the report after a production incident. Filter to the window preceding the incident to identify which changes were in flight.
Quarterly ITSM audit
Run the report for the full quarter. Use the executive summary KPIs as inputs to the ITSM maturity review.
ISO 20000 surveillance
Pair the report with your broader ITSM process documentation for ISO 20000 surveillance audits.
Generating a report
- Navigate to Compliance → ITIL CAB
- Select your reporting period (weekly for CAB prep, quarterly for audit)
- Click Download evidence package (PDF) or Export CSV
Integration requirements
- GitHub (required) — provides all change management data
- Optional: PagerDuty/OpsGenie integration for incident-to-change correlation
Disclaimer
This report is designed to support ITIL Change Enablement evidence collection. It does not constitute formal ITIL certification.
PCI-DSS v4.0 Evidence Report
Change control evidence for PCI-DSS Requirement 6.5 — change management procedures, post-change compliance verification, environment separation, and separation of duties.
FedRAMP Moderate Evidence Report
NIST SP 800-53 Rev 5 configuration change control evidence for FedRAMP Moderate — CM-3, CM-4, CA-7, and SA-11.