Sample Executive Compliance Report
A buyer-facing example of the report generated after an audit run.
Sample executive report generated from demo audit data. No live cloud writes, external API calls, or AI calls are used.
Overall compliance posture
12/100
Current readiness across adopted frameworks
Evidence completeness
29%
2 verified, 3 needs review
Cloud/API exposure
13 flags
9 pilot preview signals currently firing
Remediation velocity
72 hrs
Suggested SLA for high-priority findings
Unrestricted API key detected (frontend-exposed)
Restrict the key to specific APIs and HTTP referrers, then rotate it.
AI billing spike anomaly
Investigate the source of the spend increase and confirm it is authorized.
Missing AI system inventory coverage
Register the missing AI systems in the Governance module and re-import.
Missing human oversight evidence
Document human-in-the-loop procedures and collect owner attestations.
Missing / expired data retention policy
Refresh and re-approve the data retention policy; configure automated deletion.
Audit preparation time reduced
Consolidates framework status, evidence gaps, and remediation ownership in one view.
Cloud/API misuse exposure surfaced
Highlights credential, IAM, and AI billing risks before they become incident costs.
Executive reporting ready
Gives leadership a plain-language remediation plan with measurable posture movement.
ISO 42001
AI governance
EU AI Act
AI governance
GDPR
Privacy
ISO 27001
Security
ISO 28000
Supply chain
Cloud/API Guard
Cloud / API
Unrestricted API keys
Keys with no API/application restrictions.
1 flagged of 12 scanned
Exposed credentials
Secrets found in code, bundles, or public artifacts.
1 flagged of 340 scanned
Risky service accounts
Over-privileged or stale service accounts.
1 flagged of 9 scanned
Unexpected AI service usage
AI provider usage from unexpected projects or keys.
2 flagged of 5 scanned
AI billing spikes
Anomalous increases in AI provider spend.
1 flagged of 3 scanned
Dangerous IAM roles
Primitive or overly-broad role assignments.
2 flagged of 28 scanned
Newly enabled risky APIs
Recently enabled APIs with elevated risk.
1 flagged of 41 scanned
Unused but active keys
Active keys with no usage for an extended period.
3 flagged of 12 scanned
Frontend-exposed keys
Keys reachable from client-side bundles.
1 flagged of 4 scanned
1. Close the top AI governance gap
Register missing AI systems and attach human oversight evidence for ISO 42001 and EU AI Act readiness.
2. Remediate Cloud/API Guard flags
Rotate exposed credentials, restrict API keys, and investigate the sample anomaly.
3. Build the audit evidence pack
Request missing privacy, security, and supplier assurance evidence before the next review cycle.