As already introduced in a previous post on “The EMERALD Compliance-as-a-Service workflow” and further detailed in “The EMERALD Stream 1: Certification Schemes – Structuring Compliance Through Metrics Mapping”, the EMERALD user interface is structured around three complementary visualization streams:
- Stream 1: Certification Schemes: Allows users to upload, compare, customize, and map certification schemes and controls.
- Stream 2: Targets of Evaluations: Allows users to define certification targets, link evidence tools, and manage access rights.
- Stream 3: Audit Scopes: Combines schemes and targets to review results, assign tasks, and generate assessments and reports.
This post takes a closer look at Stream 2: Targets of Evaluation, with a particular focus on policy document evidence and the compliant / non-compliant assessment decision.
Overview of Targets of Evaluation
Stream 2 is a core component of the EMERALD Compliance-as-a-Service workflow and supports the management of targets for certification (e.g., cloud services, …). Upon entering the Targets of Evaluation (ToE) section of the EMERALD UI, users are presented with a consolidated overview of all ToEs they have access to, as shown in Figure 1. For each entry, the resource status is displayed at a glance: green indicates that all assessment results retrieved from the underlying resources are compliant, while red flags that some results require closer review. The overview also shows the type of the ToE, a short description, and allows a user to delete an existing ToE.
After initially setting up a target of evaluation, the user can manage it within the EMERALD UI. This includes updating general information (such as name, TWS, and user assignment), managing evidence extractors (e.g., downloading installation guidelines, updating statuses, and providing data for the Ai-Sec), uploading policy documents, reviewing resources and evidence, and managing certifications.

Reviewing Evidence and Compliance
One of the most important functionalities of Stream 2 is the assessment decision of evidence as shown in Figure 2. Here, every piece of extracted evidence is listed with its assessment decision, evidence ID, status, related metric ID, and extraction date. For each item, the user can open a detailed metric view showing the general file, metric, and assessment information, and can inspect the underlying evidence as either an HTML or a PDF rendering.
Based on this information, the user has to set the compliance: deciding whether the evidence proves the metric by selecting either “compliant” or “non-compliant” and adding an assessment comment to justify the decision. Since AMOE’s extraction is AI-supported, every piece of content generated with AI assistance is explicitly marked with an AI icon, which keeps automated suggestions clearly distinguishable from the human decision. Once all evidence for a document has been reviewed, it can be committed to the Evidence Store.

Figure 2 shows that for each selected control, EMERALD presents a ranked list of suggested metrics, including metric identifiers, similarity scores, short descriptions, sources, and operators. Users can remove unsuitable metrics, add missing ones from the complete metrics catalogue, and finalize the mapping by saving it. Saving a mapping simultaneously marks it as approved.
This final approval step marks the mapping as validated and ensures that all AI-assisted recommendations are transparent, accountable, and explicitly approved by domain experts before use.
From Individual Decisions to Target-Level Compliance
This human oversight process ensures that organizational evidence is not just automatically extracted but explicitly validated before it counts toward compliance. These reviewed and committed decisions then become part of the resource and metric information shown for the ToE, and ultimately feed into Stream 3, where they are aggregated across controls to assess the compliance of the whole audit scope.
In summary, Stream 2 of the EMERALD interface’s evidence workflow turns policy documents into structured, human-verified compliance decisions, providing a transparent and auditable basis for everything built on top of it.