Reports and compliance evidence
Generate Business and Enterprise evidence for AI governance without representing Orthalon as a certification.
Plan requirement: compliance evidence packs and audit export require Business or Enterprise.
Open Operations → Reports to generate evidence from the organization's discovered applications, policy controls, approvals, violations, and administrative audit records.
Available evidence mappings
| Framework | Orthalon evidence |
|---|---|
| EU AI Act | AI-system inventory, risk categorization, human oversight, and control records |
| ISO/IEC 42001 | Usage inventory, risk assessment, policy operation, and monitoring evidence |
| NIST AI RMF | Map, Measure, Manage, and Govern artifacts |
| Data protection | Metadata showing controls intended to prevent sensitive-data egress |
Create an evidence pack
- Verify the date range and organization.
- Confirm sensors and connectors were active during the selected period.
- Review unresolved events and incomplete coverage.
- Generate or export the available evidence.
- Validate sampled claims against their underlying Orthalon records.
- Store the output in the organization's approved evidence repository.
An evidence pack describes controls and observations. It does not certify the organization, guarantee legal compliance, or replace an auditor, counsel, vendor assessment, or management-system review.
Retention
Monitor defaults to 30-day event retention, Protect to 90 days, and Business to longer rollup retention for reporting. Enterprise retention and regional deployment requirements are contract and infrastructure decisions. Confirm the actual deployed configuration before stating a residency or retention promise.
Scheduled executive email and PDF reporting may not be available in every deployment. CSV/JSON evidence export is the current dependable path when those optional reporting capabilities are not enabled.