Reports, CSV export and audit bundles
Generate audience-specific PDF reports, export the obligation matrix as CSV, build a per-system audit bundle, and schedule any template to self-generate on a cadence.
Reports (under Prove it) is where you turn live status into presentable, evidenced packages for a regulator, an auditor, a customer or the board. A report is something you read; a document is something you produce, sign and hand to a regulator — those live on Documents, and the old statutory tab of this page now redirects there.
Generating a report
The Report templates tab lists the packages you can build; the audience filter (All · Board · Regulator / Auditor · Internal) narrows the set. The templates include:
- Organisation compliance report — the full PDF: executive summary, every system, every obligation, evidence status, classification history.
- Board summary — one page for a non-technical board: position, trend, risk breakdown, top risks, recommendations.
- Audit preparation report — inventory, classification reasoning, Art. 6(3) documentation, obligation and evidence status.
- Implementation timeline export — every obligation against its date.
- FRIA report (Art. 27), Serious incident register (Art. 73) and Conformity and CE readiness (Art. 43 / 47 / 48 / 49).
Press Generate PDF on a card. The first export asks you to acknowledge the document is a working draft for your review, not an attestation. The PDF opens in a new tab and is stored as a point-in-time snapshot. Report generation needs a paid entitlement; during early access every workspace has it.
The obligation matrix (CSV export)
Export CSV at the top of the templates tab produces the organisation's obligation matrix — one row per system × obligation, with status and metadata — the spreadsheet counterpart to the compliance PDF. The Dashboard's Export button is the same file.
The per-system audit bundle
The Compliance audit bundle card (shown under All and Internal) builds one merged PDF for a single system: choose the system and download. It contains the cover sheet, every completed obligation form, the risk management report and the classification dossier, closed with a SHA-256 integrity manifest. See Dossiers, tech docs and the regulator view.
Scheduling and re-downloading
Schedule on any template has it self-generate monthly, quarterly or annually. Add email recipients; each run stores a snapshot and emails a link. The Generated reports tab is the archive — every generation is kept as an immutable snapshot, so a re-download returns the document exactly as it was generated, and the list doubles as an audit trail of what was produced when.