Board Reporting

Complete control index

Every failed control at every severity, which is what makes the capped narrative register a presentation choice rather than a disclosure limit.

Currentengine 9.0.0Verified 2026-08-30

What it is

A table listing every failed control, at every severity, with no cap.

Why it exists

Because the narrative risk register is capped, and a cap on the only place findings appear is a cap on disclosure.

An earlier design capped findings at eight. An assessment with 76 failed controls therefore showed eight and left 68 invisible. The index exists so that cannot happen: the capped register plus the index always account for the full failed count.

What it carries

The control identifier, its title, its severity and its service. Enough to look any finding up and to reconcile the totals.

It paginates

Pack length varies with the number of findings.

Where the actionable detail lives

The Evidence Register, which additionally carries the failing resource identifiers, the regions, the governance implication, the first action and the closure test. Produced with every assessment and available on request.

What it does not mean

A long index is not necessarily a worse environment. Control counts scale with the scanner catalogue and the size of the estate evaluated.