Use four evidence cases
For the encryption example in Create a custom control:
Also inspect mixed populations: a known failure can make the control fail while other subjects remain unknown. Failure does not imply complete evidence coverage.
Check the boundaries
- Try the threshold itself and values on either side. “At most five” includes five.
- Confirm Boolean, numeric and text values are not being confused.
- Inspect excluded and filtered-out subjects, not just the ones that remain.
- Review observation time, source eligibility and stale evidence handling.
- Check the same subject is used across sources; a similar display name is insufficient.
- Review client overrides and the disabled state of the control and its parent standard.
Roll out in a reviewable sequence
1
Prepare an editable draft
Copy a suitable library template or create a standard. Library copies start disabled; clear Enabled when drafting an individual custom control.
2
Check evidence coverage
Use a test workspace or an agreed representative client context. Confirm the relevant integrations are connected, mapped and supplying the required predicates.
3
Inspect the definition and settings
Review scope, filters, expectations, thresholds and autonomy with the person responsible for the standard.
4
Enable deliberately and run checks
Account for the standard’s scope and client overrides before enabling it. Use Run checks and inspect the resulting assessments, evidence and evaluation time.
5
Review the wider impact
Investigate unexpected failures and gaps before relying on the standard across clients. Document intentional exceptions and identify who handles follow-up.