Verification

Why this section exists

A governance assessment nobody can check is an opinion. This section is how to check GovIntel rather than take its word for anything.

Currentengine 9.0.0Verified 2026-08-30

GovIntel asks you to create a role in your production AWS account, and then asks your board to rely on what it reports. Both are trust requests, and both should be verifiable.

What you can check yourself

ClaimHow
The access is read-only and denies data-plane readsRead the role in your own IAM console
Only one workflow can assume itRead the trust policy conditions
Access expires on the date you setRead the same conditions, and the deny statement
GovIntel did only what it saysFilter your CloudTrail on the session name
The score follows the published methodRecompute it from the pack's own methodology page
A finding is realOpen the resource the register names
Movement since last time is realRead the comparison states and their gating

None of those require GovIntel's cooperation. All of them use information you already hold.

What you cannot check, and should know

The correctness of an individual control result against the account it describes has not been independently audited. That is stated plainly rather than left to be discovered. See What GovIntel validates about itself.

Who this section is for

Security reviewers, auditors, technical evaluators and anyone conducting diligence. It assumes technical literacy but no knowledge of GovIntel.

Where to start

Verify the access boundary is the one that matters most, because it is the claim with the most consequence if it were false.