Evidence & Findings

The Evidence Register

A derived, customer-safe file listing every failed control with the resources it was observed on. Produced with every assessment, available on request.

Currentengine 9.0.0Verified 2026-08-30

The board pack is written for a board. The Evidence Register is the same assessment in a form an engineering team can work through.

The columns

ColumnContent
RankPosition in the register
Control identifierThe scanner's own identifier
Control titleWhat the check asserts
SeverityCritical, high or medium
AWS serviceThe service the resources belong to
Failing resource countHow many distinct resources failed
Evaluated resource countHow many were evaluated, so the denominator is visible
Failing resource identifiersThe full identifiers, unmasked
RegionsWhere the failures were observed
Resource identifiers completeWhether the list was truncated
Governance implicationWhat the failure means
First actionWhat to do first
Closure evidenceWhat would demonstrate it is closed

One row per failed control, all of them, at every severity.

It is derived, not an evidence dump

Deliberately absent: the raw scanner records, the scanner's own remediation text, its product fields, compliance framework annotations, and cost telemetry. The register is not the evidence set by another name.

The evidence set itself is a separate internal artefact with a short retention, and this file must never become a way around that.

Why the identifiers are unmasked here

You own the account and cannot act on a masked identifier. The board pack masks them instead, because the pack is the document that circulates.

How to obtain it

The Evidence Register is produced with every successful assessment and is available on request. It is not currently delivered automatically alongside the pack through your portal. Ask your GovIntel contact.