Compliance Report Template

Report MONITOR

Purpose

A quarterly compliance report template summarizing control status, audit findings, incidents, and training completion.

Related Controls

ISO Clause 9 NIST MS-1

1. Executive Summary

Provide a high-level overview of compliance posture for leadership.

AI Governance Compliance Report — [QUARTER] [YEAR]

Prepared By: [NAME], [ROLE TITLE]

Date: [DATE]

Overall Compliance Status: On Track / Needs Attention / At Risk

Key Highlights:

  • [X] of [Y] controls fully implemented ([Z]%)
  • [X] audit findings open ([Y] overdue)
  • [X] AI incidents this quarter ([Y] previous quarter)
  • Training completion: [X]%

Top Risks:

  1. [RISK DESCRIPTION]
  2. [RISK DESCRIPTION]

Recommendations:

  1. [RECOMMENDATION]
  2. [RECOMMENDATION]

2. Control Implementation Status

Summarize the implementation status of all 43 controls by domain.

DomainTotal ControlsImplementedIn ProgressNot StartedCompletion %
GOVERN7
BUILD7
SECURE8
DEPLOY7
MONITOR7
IMPROVE7
TOTAL43

3. Audit Findings

List all open audit findings with status and ownership.

Finding IDDescriptionSeverityStatusOwnerDue Date
AF-001[FINDING DESCRIPTION]Critical / High / Medium / LowOpen / In Progress / Closed[NAME][DATE]
AF-002[FINDING DESCRIPTION]
AF-003[FINDING DESCRIPTION]

Findings Summary

  • New this quarter: [COUNT]
  • Closed this quarter: [COUNT]
  • Overdue: [COUNT]
  • Average days to close: [COUNT]

4. Incident Summary

Summarize AI-related incidents during the reporting period.

Incident IDDateTypeSeveritySystemStatusRoot Cause
INC-001[DATE][TYPE][SEVERITY][SYSTEM]Resolved / Open[BRIEF ROOT CAUSE]
INC-002

Incident Trends

  • Total incidents: [COUNT] (previous quarter: [COUNT])
  • Mean time to detect: [HOURS]
  • Mean time to resolve: [HOURS]
  • Recurring issues: [DESCRIPTION]

5. Training Completion

Report on AI governance training program completion rates.

Training ProgramTarget AudienceTotal EnrolledCompletedCompletion %Target
AI Awareness TrainingAll Employees95%
AI Security TrainingEngineering/Dev95%
AI Risk ManagementManagers90%
AI Ethics & BiasML Engineers / Data Scientists95%

6. Risk Assessment Updates

Summarize changes to the AI risk landscape since last report.

New Risks Identified

  1. [RISK — Likelihood — Impact — Owner]
  2. [RISK — Likelihood — Impact — Owner]

Risk Level Changes

  1. [RISK] — Changed from [PREVIOUS] to [CURRENT] because [REASON]

Risks Closed/Accepted

  1. [RISK] — Closed because [REASON] / Accepted by [NAME] on [DATE]

7. Next Quarter Priorities

Outline focus areas and key milestones for the next quarter.

Priority Actions

  1. [PRIORITY — Owner — Target Date]
  2. [PRIORITY — Owner — Target Date]
  3. [PRIORITY — Owner — Target Date]

Key Milestones

  • [MILESTONE — Date]
  • [MILESTONE — Date]

Resource Needs

  • [RESOURCE REQUEST — Justification]

Appendices

  • Appendix A: Detailed control implementation status
  • Appendix B: Full incident reports
  • Appendix C: Audit evidence index
  • Appendix D: Risk register extract
← Back to all templates