Buyer-ready executive view

Sample Executive Compliance Report

A buyer-facing example of the report generated after an audit run.

Sample executive report generated from demo audit data. No live cloud writes, external API calls, or AI calls are used.

Return to demo journey

Overall compliance posture

12/100

Current readiness across adopted frameworks

Evidence completeness

29%

2 verified, 3 needs review

Cloud/API exposure

13 flags

9 pilot preview signals currently firing

Remediation velocity

72 hrs

Suggested SLA for high-priority findings

Framework readiness
Adopted framework posture in the demo workspace.

ISO 42001

AI governance

in progress
62%

EU AI Act

AI governance

in progress
48%

GDPR

Privacy

mostly ready
71%

ISO 27001

Security

in progress
66%

ISO 28000

Supply chain

in progress
41%

Cloud/API Guard

Cloud / API

in progress
54%
Cloud/API exposure summary
Sample Cloud/API Guard signals for the buyer story.

Unrestricted API keys

Keys with no API/application restrictions.

critical

1 flagged of 12 scanned

Exposed credentials

Secrets found in code, bundles, or public artifacts.

critical

1 flagged of 340 scanned

Risky service accounts

Over-privileged or stale service accounts.

high

1 flagged of 9 scanned

Unexpected AI service usage

AI provider usage from unexpected projects or keys.

high

2 flagged of 5 scanned

AI billing spikes

Anomalous increases in AI provider spend.

critical

1 flagged of 3 scanned

Dangerous IAM roles

Primitive or overly-broad role assignments.

high

2 flagged of 28 scanned

Newly enabled risky APIs

Recently enabled APIs with elevated risk.

medium

1 flagged of 41 scanned

Unused but active keys

Active keys with no usage for an extended period.

medium

3 flagged of 12 scanned

Frontend-exposed keys

Keys reachable from client-side bundles.

critical

1 flagged of 4 scanned

What ZAGOS recommends next
Recommended buyer-facing remediation plan.

1. Close the top AI governance gap

Register missing AI systems and attach human oversight evidence for ISO 42001 and EU AI Act readiness.

2. Remediate Cloud/API Guard flags

Rotate exposed credentials, restrict API keys, and investigate the sample anomaly.

3. Build the audit evidence pack

Request missing privacy, security, and supplier assurance evidence before the next review cycle.