Documentation

Reports and compliance evidence

Generate Business and Enterprise evidence for AI governance without representing Orthalon as a certification.

Plan requirement: compliance evidence packs and audit export require Business or Enterprise.

Open Operations → Reports to generate evidence from the organization's discovered applications, policy controls, approvals, violations, and administrative audit records.

Available evidence mappings

FrameworkOrthalon evidence
EU AI ActAI-system inventory, risk categorization, human oversight, and control records
ISO/IEC 42001Usage inventory, risk assessment, policy operation, and monitoring evidence
NIST AI RMFMap, Measure, Manage, and Govern artifacts
Data protectionMetadata showing controls intended to prevent sensitive-data egress

Create an evidence pack

  1. Verify the date range and organization.
  2. Confirm sensors and connectors were active during the selected period.
  3. Review unresolved events and incomplete coverage.
  4. Generate or export the available evidence.
  5. Validate sampled claims against their underlying Orthalon records.
  6. Store the output in the organization's approved evidence repository.

An evidence pack describes controls and observations. It does not certify the organization, guarantee legal compliance, or replace an auditor, counsel, vendor assessment, or management-system review.

Retention

Monitor defaults to 30-day event retention, Protect to 90 days, and Business to longer rollup retention for reporting. Enterprise retention and regional deployment requirements are contract and infrastructure decisions. Confirm the actual deployed configuration before stating a residency or retention promise.

Scheduled executive email and PDF reporting may not be available in every deployment. CSV/JSON evidence export is the current dependable path when those optional reporting capabilities are not enabled.