Evidence & Findings
The evidence ledger
The page of the board pack that states which collectors ran, which did not, and what the assessment is therefore able to conclude.
Currentengine 9.0.0Verified 2026-08-30
Every board pack carries an evidence ledger. It is the page that says what the assessment could actually see.
What it shows
| Element | Content |
|---|---|
| Evidence capture status | Each collector, and which of the eight states it ended in |
| Scan scope | The account and the regions covered |
| Assessment notes | Evidence confidence, the control population, records excluded, and any file that was ignored |
Why it is a page and not a footnote
A governance rating without its coverage is an assertion. A reader deciding how much weight to put on a red security band needs to know whether it was measured over 400 controls or 30, and whether the resilience domain was rated at all.
Putting that on its own page, before the detailed findings, is what lets a director calibrate everything that follows.
What the assessment note states
- Evidence confidence, and how many governance domains were actually scored
- The control population, so an unusual number is visible
- The count of records excluded as unclassifiable, which usually indicates a permission gap
- Any evidence file that was not recognised and was therefore ignored
- Confirmation that the assessment was read-only and made no production change
