Reports & Analytics
RAIC provides a comprehensive reporting suite spanning five categories: Enterprise Reports, System Register, Controls, Use Case Register, and AI Discovery. Reports are accessible from the central Reports page, organized by category tabs.
Executive SummaryProfessional+
A branded, board-ready PDF report that provides an executive-level overview of your AI governance posture. Includes aggregate statistics across systems, use cases, and controls, risk distribution summaries, compliance status, and key governance metrics.
Aslan AI Executive Summary
Click Draft with Aslan AI in the Executive Summary toolbar (right-aligned next to Export PDF) to generate a board-ready narrative across five sections — Overview, Key Metrics, Top Risks, Compliance Posture, and Recommendations — derived from your live org data (AI systems, controls, use cases, attestations, gap-analysis maturity, incidents, and the new use_cases_with_linked_policy_pct coverage metric measuring the share of use cases tied to at least one governance policy). Drafts render in an editable preview; accept to include them in the next branded PDF/DOCX export. Both AI_EXECUTIVE_SUMMARY_GENERATED and AI_EXECUTIVE_SUMMARY_ACCEPTED events are written to the org and platform audit logs. Server-side tier enforcement returns HTTP 403 for non-Enterprise tenants.
Trend AnalysisProfessional+
Time-series analytics showing governance portfolio evolution over configurable date ranges. Track changes in risk distribution, approval velocity, control effectiveness, and compliance posture over time.
Scheduled ReportsProfessional+
Configure automated report generation on daily, weekly, or monthly schedules. Reports are generated at 3 AM EST and delivered via branded email to designated recipients. The number of scheduled reports is determined by your plan tier.
Enterprise Reports
Cross-cutting reports that aggregate data across all governance modules:
Interactive Risk Heatmap
Visual matrix plotting AI assets by risk likelihood vs. impact across Systems, Use Cases, and Controls. Cells are color-coded by risk tier (Critical/High/Medium/Low) with drill-down capability.
EU AI Act Heatmap
Classification-specific heatmap showing the distribution of AI assets across EU AI Act risk categories (Unacceptable, High-Risk, Limited, Minimal). Only visible when EU AI Act framework is enabled for the organization.
Control Coverage Report
Maps Controls to AI Systems and Use Cases to identify coverage gaps — assets without linked controls or controls without linked assets.
Regulatory Framework Coverage
Calculates compliance coverage as (Approved/Conditionally Approved assets ÷ Total assets tagged to a framework) × 100. Covers EU AI Act, NIST AI RMF, ISO 42001, and other configured frameworks.
Overdue Attestations Report
Aggregates pending or overdue policy attestations with past-due dates. Features a collapsible employee summary grid and sortable table showing attestation status by user and policy.
Aslan AI Risk Assessment (DOCX/PDF)
Aslan AI-generated risk assessment report with risk narrative, likelihood × impact scoring, tier justification, and suggested controls with NIST AI RMF and ISO 42001 clause mappings. Available after generating and accepting a risk assessment for any AI system or use case.
Automated Gap Analysis
Identifies governance gaps across modules: Systems missing assessments/monitoring, Controls untested or with low effectiveness, Use Cases lacking PII assessments, and overdue Attestations. Enterprise users can generate Aslan AI-powered deep analysis with root cause narratives, business impact, framework references, and a 3-phase remediation roadmap. Each AI run is automatically saved and dated; the last 10 analyses per organization are retained and accessible via a History dropdown to track maturity progression. Branded DOCX and PDF exports are available.
System Register Reports
- Summary Matrix — Risk Tier × Lifecycle Stage cross-tabulation showing the distribution of all registered AI systems All Tiers
- AI System Summary — Branded one-page PDF with 50+ fields covering identity, ownership, security, risk, and compliance Professional+
- Pending Reviews — Systems with review or approval expiration due within 30 days All Tiers
- Vendor Exposure — Vendor concentration risk analysis across the AI portfolio Professional+
- Ownership Gaps — Identifies systems with missing or incomplete ownership assignments Professional+
- Aging & Staleness — Flags systems with outdated reviews or stale governance data Professional+
- Time-to-Compliance — Registration-to-approval duration analytics measuring governance velocity Professional+
- Data Sensitivity — PII/PHI distribution map across AI systems showing data classification exposure Professional+
- Incident Density — Risk-tier incident correlation analysis showing incident counts by risk classification Professional+
- Full CSV Export — Complete data export of all system fields for offline analysis All Tiers
Controls Reports
- Overview Dashboard — Controls by Risk Tier (pie chart) and Controls by Approval Status (bar chart) All Tiers
- AI Control Summary — Branded PDF with 35 fields covering identity, risk, ownership, and testing Professional+
- Control Effectiveness Trend — Tracks effectiveness scores over time across all controls Professional+
- Testing Compliance — Identifies controls with overdue or missing tests and upcoming test schedules Professional+
- KCI Performance Dashboard — Visualizes Key Control Indicator metrics across the control portfolio Professional+
- Full CSV Export — Complete data export aligned with the 35 summary report fields All Tiers
Use Case Register Reports
- Overview Dashboard — Use Cases by Risk Tier (pie chart) and by Approval Status (bar chart) All Tiers
- AI Use Case Summary — Branded PDF overview with submission-to-approval timeline, risk classifications, and cross-module mappings Professional+
- Full CSV Export — Complete data export of all use case fields for offline analysis All Tiers
AI Discovery Reports
Branded inventory exports of all AI applications detected across the org by the Shadow AI Browser Extension and Microsoft Graph API integration. Includes a sortable summary panel with totals for registered, unregistered, sanctioned, and high-risk apps, plus First Seen / Last Seen timestamps and detected model metadata.
- AI Discovery Report (PDF) — Branded landscape PDF with summary stat cards and a full inventory table including risk tier color coding Professional+
- AI Discovery Report (Word) — Branded DOCX with cover page, summary metrics, and complete app inventory Professional+
- Full CSV Export — Complete export of all discovered apps with discovery source, detection type, user counts, and risk scores All Tiers
Exports emit the AI_DISCOVERY_REPORT_EXPORTED event to the org and platform audit logs.
ISO 42001 Annex A CoverageProfessional+
Tracks RAIC's coverage of all 38 ISO/IEC 42001:2023 Annex A controls. Each control can be marked Full, Partial, Gap, or N/A, with evidence summaries and reviewer notes. Coverage % excludes N/A controls from the denominator.
- Auto-Suggest — Seeds default statuses based on RAIC's built-in capability map; existing manual overrides are preserved.
- Per-Control Editor — Side drawer for status, evidence summary, notes, and last-reviewed metadata.
- Branded ZIP Export —
RhindonCyber_ISO42001_AnnexA_Report.zipcontaining CSV control list, Markdown summary, raw JSON, and amanifest.jsonwith SHA-256 checksums.
Gated by Professional/Enterprise tier and the per-org iso_42001_enabled toggle in Org Settings. Emits ISO_42001_AUTO_SUGGESTED and ISO_42001_REPORT_EXPORTED to the org and platform audit logs.
Audit-Ready Evidence BundleProfessional+
A single ZIP package generated server-side that consolidates the org's governance evidence into branded CSV files for auditor handoff. Scope can be set to the entire org, a single AI system, or a regulatory framework, with an optional date range and PII redaction toggle.
Bundle contents (8 files):
RhindonCyber_EvidenceBundle_Manifest.txt— generation metadata and scopeRhindonCyber_SystemRegister.csvRhindonCyber_ControlsRegister.csvRhindonCyber_UseCaseRegister.csv— now includes Linked Policies (pipe-delimitedTitle v#) and Linked Policy Count columnsRhindonCyber_AttestationRecords.csvRhindonCyber_AuditLog.csvRhindonCyber_PolicyLibrary.csv— now includes Referenced By Use Cases (pipe-delimited Use Case IDs) and Use Case Reference Count columnsRhindonCyber_UseCasePolicyLinks.csv— new mapping file with one row per use-case-to-policy link (use_case_id, use_case_name, policy_id, policy_title, policy_version)
Export Standards
- All downloadable files are prefixed with
RhindonCyber_ - CSV date columns use
MM/DD/YYYY HH:MMformat - PDF reports use branded headers with gold (#D9A032) accent styling and the Rhindon Cyber logo
- Scheduled reports are rendered server-side (jsPDF) and stored in a private bucket with 7-day signed URLs for secure delivery
