Board Reporting
Complete control index
Every failed control at every severity, which is what makes the capped narrative register a presentation choice rather than a disclosure limit.
What it is
A table listing every failed control, at every severity, with no cap.
Why it exists
Because the narrative risk register is capped, and a cap on the only place findings appear is a cap on disclosure.
An earlier design capped findings at eight. An assessment with 76 failed controls therefore showed eight and left 68 invisible. The index exists so that cannot happen: the capped register plus the index always account for the full failed count.
What it carries
The control identifier, its title, its severity and its service. Enough to look any finding up and to reconcile the totals.
It paginates
Pack length varies with the number of findings.
Where the actionable detail lives
The Evidence Register, which additionally carries the failing resource identifiers, the regions, the governance implication, the first action and the closure test. Produced with every assessment and available on request.
What it does not mean
A long index is not necessarily a worse environment. Control counts scale with the scanner catalogue and the size of the estate evaluated.
