I have divided compliance policies into separate policies so we can leverage end user email notifications that precisely describe the issue and remediation options which is not possible for a single bulky policy.
Each check has its own policy now. It's also much better for reporting purposes.