Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in
Enterprise audit report preview

ZAGOS Compliance Automation report preview

Professional, buyer-facing report outline generated from sample readiness, evidence, findings, and workflow recommendations.

Build enterprise board pack
Report cover summary
Draft report header for an enterprise-oriented, pilot-ready engagement.

Scope

AI, privacy, security, supply chain, Cloud/API Guard

Readiness score

0/100

Mode

Hosted preview

Scope and frameworks
Adopted frameworks included in this report preview.

ISO 42001

Management system standard for responsible development and use of AI, covering AI policy, risk, and lifecycle controls.

62%

EU AI Act

Risk-based regulation for AI systems placed on the EU market, with obligations for high-risk systems including human oversight and transparency.

48%

GDPR

EU regulation on the protection of personal data and privacy, including lawful basis, retention, and data subject rights.

71%

ISO 27001

International standard for an information security management system (ISMS) and Annex A security controls.

66%

ISO 28000

Management system for security of the supply chain, including supplier risk and resilience controls.

41%

Cloud/API Guard

ZAGOS proprietary control set for cloud and API hygiene: key restriction, credential exposure, IAM risk, and AI usage/billing anomaly detection.

54%
Evidence gaps
Missing, weak, and expired evidence that affects readiness.

Missing evidence

27

Weak evidence

7

Expired evidence

1

Control status table
Appendix-ready control evaluation sample.
ControlFrameworkStatusEvidence gaps
A.6.2.2 - AI system inventoryiso-42001
partial
1 missing, 0 weak, 0 expired
Art.14 - Human oversighteu-ai-act
fail
2 missing, 0 weak, 0 expired
Art.13 - Transparency and provision of informationeu-ai-act
fail
2 missing, 0 weak, 0 expired
A.8.3 - AI system impact assessmentiso-42001
fail
1 missing, 0 weak, 0 expired
Art.5(1)(e) - Storage limitation / data retentiongdpr
fail
1 missing, 1 weak, 1 expired
Art.6 - Lawful basis for processinggdpr
partial
1 missing, 0 weak, 0 expired
Art.30 - Records of processing activitiesgdpr
pass
0 missing, 0 weak, 0 expired
Art.32 - Security of processinggdpr
fail
1 missing, 1 weak, 0 expired
Remediation roadmap
Workflow recommendations for the next pilot sprint.

Review AI system classification

Recommended because review ai system classification matches high ai governance remediation.

high

Request missing evidence

Recommended because request missing evidence matches high ai governance remediation.

high

Request missing evidence

Recommended because request missing evidence matches medium ai governance remediation.

medium

Review AI system classification

Recommended because review ai system classification matches high ai governance remediation.

high

Request missing evidence

Recommended because request missing evidence matches high privacy remediation.

high
Executive recommendations
Plain-language actions for leadership.
1.Triage preview finding: Missing scan result evidence: API key restriction.
2.Improve cloud api readiness, currently 0%.
3.Collect or refresh the evidence requested by the missing-evidence workflow preview.
4.Escalate critical preview findings before any formal audit package is produced.
5.Keep this preview read-only until the scoring and workflow mapping are accepted.
Appendices / evidence references
Sample evidence references for a future generated report.

AI Inventory export (ZAGOS Governance)

Supports 2 frameworks and 1 controls.

Encryption configuration scan

Supports 2 frameworks and 2 controls.

Data retention policy v3

Supports 1 frameworks and 1 controls.

Records of Processing Activities (RoPA)

Supports 1 frameworks and 2 controls.

IAM policy export

Supports 3 frameworks and 3 controls.

Supplier security questionnaire — Acme Logistics

Supports 1 frameworks and 2 controls.

Open full traceability view

Console Intelligence report package

Report-ready compliance intelligence assembled locally from Console question coverage, evidence support, findings, and framework linkage.

NOT READY (Gaps Present)

Local dry-run — not live-connected

This report was generated in local dry-run mode. No live connections to external systems were made during generation.

This package is NOT connected to any live Console Intelligence engine, production database, or external service.

Executive coverage summary

Coverage

20%

Minimal

Questions covered

0/692

Evidence items

781

39% with evidence

Connection

Local Dry-Run Mode

Evidence support

Questions with evidence77
Questions without evidence123
Average evidence / question3.9
Evidence coverageLimited

Findings & remediation

Findings linkedNo findings linked
Remediation tasksNo remediation tasks
Questions with findings0
Questions with tasks0

Framework / control coverage

Frameworks in scope5
Overall framework coverage42%
ISO_IEC_2389477/305 (25%)
ISO_IEC_4200177/166 (46%)
UK_GDPR___ICO35/35 (100%)
NIST_AI_RMF29/29 (100%)
EU_AI_Act10/10 (100%)

Linkage gaps & missing metadata

Total gaps250 (Notable Gaps)
Missing evidence0
Missing findings77
Ambiguous domains50

Review 77 question(s) for finding linkage; Clarify domain mapping for 50 question(s)

Report readiness decision

NOT READY (Gaps Present)

Report not ready: MISSING_FINDINGS: 77 question(s) have no linked findings, AMBIGUOUS_DOMAINS: 50 question(s) have ambiguous domain mapping, PARTIAL_COVERAGE: 271 question(s) are only partially covered

Blocked / missing reasons

  • MISSING_FINDINGS: 77 question(s) have no linked findings
  • AMBIGUOUS_DOMAINS: 50 question(s) have ambiguous domain mapping
  • PARTIAL_COVERAGE: 271 question(s) are only partially covered

Missing integration pieces

  • All questions missing evidence hints
  • All questions missing severity hints
  • Some domains lack Console intelligence mapping
  • 50 question(s) have ambiguous domain linkage

This is a preview/metadata-only report generated from local Console intelligence data. It is NOT a formal audit opinion and should NOT be treated as production-ready compliance assurance.