Skip to content

Reporting

Report without rebuilding the programme.

KaitoSec keeps status, owner, residual risk, approval and evidence with the work item. Security, management and audit each receive the right view of the same state.

Where friction starts today

The week before every audit, spent collecting screenshots

Reporting tends to mean a frantic week of gathering: screenshots of settings, exports from five tools, exercise notes someone has to track down, a board deck rebuilt from last quarter's. By the time the package is assembled it is already slightly out of date, and the next audit means doing the entire collection again because nothing about it was repeatable.

Evidence should be a by-product of working, not a separate project. The continuity exercise you ran, the risk you accepted, the vendor you reviewed, the policy people signed: each one already produced proof. When those moments are captured in the working process and assigned to the relevant requirement, the next report starts from a defensible state. Reporting hurts because evidence and operations usually live apart.

One data model

What you enter here, the other modules already know

Modules are views on the same record, not separate databases. A change made here is the change every other module reads, with no export step and no second entry.

A change in this module is written to the shared data model, which the other modules read immediately.

This module

Reporting

Shared data model

One asset, one risk, one control, one piece of evidence

  • Risk ManagementCurrent at once
  • Business ContinuityCurrent at once
  • Asset ManagementCurrent at once

Entry to evidence

Every change carries its own proof

An auditor rarely asks what the register says today. They ask who changed it, when, and on what basis. That trail is written while the work happens, so nothing has to be reconstructed at the end of the year.

One change writes its previous value, its owner and its date, and surfaces in the management report, the audit evidence and the customer questionnaire.

One change

A risk is re-assessed

Written with it

  • Previous value and version
  • Person responsible
  • Date and reason

Where it surfaces

  • Management report
  • Audit evidence
  • Customer questionnaire

What changes for your team

01

Show open decisions, not just metrics

One shared view connects control status, open risks, exercise outcomes, vendor follow-ups and policy acknowledgements across the active management systems.

02

Provide evidence with its context

KaitoSec groups control implementations, linked documents, exercise reports, vendor assessments and activity logs by requirement and management system.

03

Give each audience the right depth

Prepare PDF and CSV exports for management reviews, board presentations, regulator requests and customer due diligence from the same approved reporting state.

The workflow

01

Management view with decisions required

A one-page executive view shows overall risk posture, framework coverage by management system, BC readiness, top open risks and supplier hotspots. The view is designed for management reviews and board agendas and needs no technical translation.

02

Move from framework status to the next task

Drill into any framework to see control-level completion, owners and evidence status. Filter by domain, due date or owner so the team can focus effort where the next audit, exercise or regulator request needs it.

03

Version reporting states for traceability

Prepare recurring or event-driven reports for specific stakeholders. Each approved state remains versioned, so you can later show which information was shared at which point in time.

FAQ

Can we share reports with stakeholders who do not have a KaitoSec account?

Yes. Read-only report sharing works via secure link. A live dashboard or a point-in-time PDF can be shared with board members, auditors, customers or regulators without granting platform access.

How are audit evidence packages created?

Every control, BC plan, exercise, vendor record and AI system can carry linked documents, screenshots and activity logs. The evidence package builder brings approved content together by framework clause and management system in a structured PDF.

Are SOC 2 Trust Services Criteria covered in the reports?

Yes. SOC 2 reports map to the Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy). Each criterion shows implementation status, evidence attachments and owner assignments.

Can reports carry our company branding?

Yes. PDF exports include your logo, colour scheme and report header. Enterprise workspaces support full white-labelling for customer-facing reporting and board materials.

Relevant foundations