Compliance Report Template
Report
MONITOR
Purpose
A quarterly compliance report template summarizing control status, audit findings, incidents, and training completion.
Related Controls
ISO Clause 9
NIST MS-1
1. Executive Summary
Provide a high-level overview of compliance posture for leadership.
AI Governance Compliance Report — [QUARTER] [YEAR]
Prepared By: [NAME], [ROLE TITLE]
Date: [DATE]
Overall Compliance Status: On Track / Needs Attention / At Risk
Key Highlights:
- [X] of [Y] controls fully implemented ([Z]%)
- [X] audit findings open ([Y] overdue)
- [X] AI incidents this quarter ([Y] previous quarter)
- Training completion: [X]%
Top Risks:
- [RISK DESCRIPTION]
- [RISK DESCRIPTION]
Recommendations:
- [RECOMMENDATION]
- [RECOMMENDATION]
2. Control Implementation Status
Summarize the implementation status of all 43 controls by domain.
| Domain | Total Controls | Implemented | In Progress | Not Started | Completion % |
|---|---|---|---|---|---|
| GOVERN | 7 | ||||
| BUILD | 7 | ||||
| SECURE | 8 | ||||
| DEPLOY | 7 | ||||
| MONITOR | 7 | ||||
| IMPROVE | 7 | ||||
| TOTAL | 43 |
3. Audit Findings
List all open audit findings with status and ownership.
| Finding ID | Description | Severity | Status | Owner | Due Date |
|---|---|---|---|---|---|
| AF-001 | [FINDING DESCRIPTION] | Critical / High / Medium / Low | Open / In Progress / Closed | [NAME] | [DATE] |
| AF-002 | [FINDING DESCRIPTION] | ||||
| AF-003 | [FINDING DESCRIPTION] |
Findings Summary
- New this quarter: [COUNT]
- Closed this quarter: [COUNT]
- Overdue: [COUNT]
- Average days to close: [COUNT]
4. Incident Summary
Summarize AI-related incidents during the reporting period.
| Incident ID | Date | Type | Severity | System | Status | Root Cause |
|---|---|---|---|---|---|---|
| INC-001 | [DATE] | [TYPE] | [SEVERITY] | [SYSTEM] | Resolved / Open | [BRIEF ROOT CAUSE] |
| INC-002 |
Incident Trends
- Total incidents: [COUNT] (previous quarter: [COUNT])
- Mean time to detect: [HOURS]
- Mean time to resolve: [HOURS]
- Recurring issues: [DESCRIPTION]
5. Training Completion
Report on AI governance training program completion rates.
| Training Program | Target Audience | Total Enrolled | Completed | Completion % | Target |
|---|---|---|---|---|---|
| AI Awareness Training | All Employees | 95% | |||
| AI Security Training | Engineering/Dev | 95% | |||
| AI Risk Management | Managers | 90% | |||
| AI Ethics & Bias | ML Engineers / Data Scientists | 95% |
6. Risk Assessment Updates
Summarize changes to the AI risk landscape since last report.
New Risks Identified
- [RISK — Likelihood — Impact — Owner]
- [RISK — Likelihood — Impact — Owner]
Risk Level Changes
- [RISK] — Changed from [PREVIOUS] to [CURRENT] because [REASON]
Risks Closed/Accepted
- [RISK] — Closed because [REASON] / Accepted by [NAME] on [DATE]
7. Next Quarter Priorities
Outline focus areas and key milestones for the next quarter.
Priority Actions
- [PRIORITY — Owner — Target Date]
- [PRIORITY — Owner — Target Date]
- [PRIORITY — Owner — Target Date]
Key Milestones
- [MILESTONE — Date]
- [MILESTONE — Date]
Resource Needs
- [RESOURCE REQUEST — Justification]
Appendices
- Appendix A: Detailed control implementation status
- Appendix B: Full incident reports
- Appendix C: Audit evidence index
- Appendix D: Risk register extract