Controls
Control identifier
The scanner's own stable name for a check. It is what deduplication groups on and what makes movement between assessments comparable.
What it is
The scanner's identifier for a check, extracted from each record.
Why it matters twice
For scoring. It is the key records are collapsed on. Without a stable identifier there is no way to say that forty records describe one control.
For comparison. Control identifiers are stable across engine versions, which is why control-level movement between two assessments can still be reported even when the scores themselves are not comparable.
How GovIntel applies it
Every failed control appears in the register and the index under its identifier, so a reader can look the check up at source rather than relying on GovIntel's description of it.
What it does not mean
It is not GovIntel's identifier and not a stable public API. It belongs to the scanner, which is why the scanner version is pinned and published.
