Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

How should missing records be reported?

State exactly what was not found, where and when it was expected, what material was searched and which explanations were tested. “No matching record located” is not automatically “the event did not occur”.

Define the evidential gap

Identify source system, event type, period, dataset and the reason the system should have created and retained the record. Document historical logging, retention, storage, collector health, permissions, filters and alternative sources.

Configuration, expiry, overwrite, outage, export limits and deliberate interference have different meanings and should not be collapsed into “deleted”.

Record query or method, date range, time zone, filters, date performed and result count. If source completeness is established, explain why absence has weight. If it is not, state the narrower limitation and any unresolved cause.

Do not fill the gap with unlabelled inference. The report should let another reviewer understand both the expected record and the boundaries of the unsuccessful search.

The point to remember

Report missing records through a defined, reproducible search and keep absence distinct from non-occurrence or deletion.

Reference: LOG-151Logs, Records & Provider Evidence