SCF Findings Application Overview
The SCF Findings application captures compliance audit findings and links them to controls, evidence, and remediation plans. Findings can be ingested through the SCF Data Import application, managed manually, or exported for offline editing and re-import.
This application provides traceability by connecting gaps (findings) to their associated controls, evidence, and remediation activities.
SCF Findings Record Fields
- Control Reference – Linked SCF Library control.
- Finding Title / # – Identifier and short description.
- Finding Summary – Overview of the issue.
- Owner – Assigned individual responsible for managing the finding.
- Selected Frameworks – Framework(s) where the finding applies.
- SCF Domain & Control – Contextual information about the related SCF control.
- Evidence Request List (ERL) # – Linked evidence requirement.
- Analysis Source – Example: Internal Review, External Audit.
- Reference Year – Applicable reporting year.
- Discovery Date – Date the finding was identified.
- External Auditor – Auditor contact responsible for validation.
- Certification Owner Team – Team accountable for certification.
- Expired Finding / Requirement – Boolean indicators.
- Notes – Additional context.
- Comments – Rich text editor for collaborative updates.
- Audited – Checkbox to indicate whether the finding has been formally audited.