Risk

Materiality

Materiality is how far one control failure reaches in one account, computed only from observed resources, regions and account scope.

Currentengine 9.0.0Verified 2026-08-30

What it is

Materiality is GovIntel's measure of how far a particular control failure reaches in this account. It is computed from four observed properties: how many distinct resources failed, whether the failures span more than one region, whether the control governs the account as a whole, and whether the concern is reachable from outside.

Why it exists

Severity is the scanner's judgement of a control in the abstract, and it is identical for every customer in the world. It cannot distinguish a medium control failing on forty resources across five regions from a critical failing on one.

A board asking "how much of our estate does this touch" is asking about reach, and severity does not answer it.

How GovIntel computes it

BandCondition
Estate-wideThe control governs the account as a whole, or failed on 10 or more distinct resources, or failed in every region it was evaluated in
BroadFailed on 2 or more distinct resources, or failures span more than one region
ContainedExactly one distinct resource failed
Not determinableThe evidence carried no resource identifier. Reach is not guessed at, and the control is still reported in full

Two adjustments apply. A critical control whose concern is externally reachable and whose class is preventive is escalated one band, capped at Estate-wide — an open door anyone can reach carries further than its resource count suggests. A detective control is never escalated by severity: a missing alarm is a visibility gap, not an open door, and inflating it would make the band meaningless where it matters.

Every band carries the identifiers of the rules that produced it, and the board pack prints them. A band a reader cannot check is an opinion.

What it does not mean

Materiality models nothing about your business. It does not incorporate revenue, data value, workload criticality, customer impact, regulatory position, or the probability of compromise. The assessment observes none of those and must not imply them.

It is a statement about the reach of a configuration failure, and nothing more.