Evidence & Findings
From finding to control
How a raw scanner record becomes a scored control: status classification, identifier extraction, then collapse to distinct controls.
Currentengine 9.0.0Verified 2026-08-30
The four steps
- Admission. Only files recognised as control evidence are read. Anything else is listed in the assessment note and ignored.
- Status. Each record is classified as passing, failing, or unclassifiable. Anything that cannot be classified is excluded from both sides of the pass rate and counted separately.
- Identity. Each record yields the identifier of the control it evaluated, and the identifiers of the resources it evaluated it against.
- Collapse. Records are grouped by control identifier. A control failing on forty resources becomes one failed control carrying forty resources.
What survives the collapse
Everything a reader needs:
| Retained | Used for |
|---|---|
| The control identifier and title | Naming the finding |
| Severity | Weighting the score, and ordering the register |
| The failing resource identifiers | Acting on it, and computing reach |
| The regions those resources are in | Computing reach |
| The count evaluated, not only the count failed | Stating the denominator |
Why the resource identifiers are kept
They are what materiality is computed from. Deduplication sets the count aside for scoring; it does not discard it.
A bounded number of resource identifiers is tracked per control. Where the list was truncated, the pack says so rather than presenting a short list as complete.
Resource identity
A resource identifier is parsed to establish which region and which service it belongs to, and whether the control governs the account as a whole rather than any particular resource. Account-scoped controls reach everything, whatever their resource count.
