Skip to content

Reports & Exports

Where to find it: Reports (/reports).


Operational reports

ReportWhat it shows
Portfolio aggregateCompliance, determination, governed ownership, attestation, findings, action plans and evidence, with by-framework slices
Regulatory reporting viewRequirement-grained governed compliance plus operational open and overdue items, per-rule breakdown, department breaches, aging and a next-7 and next-30-day deadline drilldown
Evidence freshnessFreshness state across expected evidence

The regulatory reporting view filters by country and regulator, drawn from regulation library metadata, and by department, derived from the governed owner's organisational unit.

Department here is the governed owner's unit

Department filtering uses the governed owner's organisational unit, not a department field on the library item. It is best-effort: owners without a unit are absent from the filter.

This is the more useful definition — it answers "which department is accountable?" rather than "which department was this filed under?"


CSV exports

ExportContents
FreshnessEvidence freshness state
FindingsThe findings register
Action plansRemediation plans and status
EvidenceThe evidence register
Audit operationalOperational audit data
DeterminationsCompliance determinations
RequirementA single requirement's data
Statement of ApplicabilityThe governed SoA for an adoption, with as-of support
CrosswalkMapping datasets, with as-of support

Requires export.data, and for crosswalk export, mapping.export.


Requirement evidence pack

A requirement pack assembles everything supporting one obligation: its determination, mapped controls, evidence, assertions, assurance posture and history.

This is the artefact to hand an auditor who asks about a specific requirement. It answers the whole chain — what the obligation is, what addresses it, what proves it, what the position is and who signed it — in one place.


Report packs

Report packs generate and store a report artefact, so a generated pack remains available as it was produced.

ConceptMeaning
Pack runOne generation
ArtefactThe stored output

A stored artefact is a point-in-time document. Where you need a reconstructed position rather than a stored one, use historical reconstruction instead.


Scheduled reports

Recurring generation can be configured for board and periodic reporting: what to generate, on what schedule, in what state.

Requires report.schedule.

Report schedules are technical schedules

Like collector runs and indicator evaluations, scheduled report generation does not appear on the GRC Calendar. The calendar holds governance obligations people must meet, not machine executions.

The reporting deadline — the board meeting, the regulatory submission date — is a calendar entry. The generation job is not.


Exports and permissions

An export contains what you can see. Two people exporting the same report with different permissions produce different files, and both are correct.

Exports are read-only: generating one changes nothing and produces no audit event against the records exported.


Preparing an evidence package for an external party

A practical sequence for an external audit or a regulatory information request.

  1. Establish the as-of date. Almost every external request is about a period, not about today.
  2. Export the Statement of Applicability for the relevant adoption, with the as-of date set. See Statement of Applicability.
  3. Export the crosswalk as of the same date, so the mappings match the SoA.
  4. Generate requirement packs for the obligations in scope of the request.
  5. Export findings and action plans to show the remediation position.
  6. Export evidence for the artefact list.

Everything in that package reconstructs to the same instant, which is what makes it internally consistent — a common failure in manually assembled packages.


Permissions

ActionPermission
View dashboards and reportsreport.read
Download CSV and exportsexport.data
Export crosswalk datasetsmapping.export
Create and manage recurring generationreport.schedule

Example

An external audit information request covering the prior financial year.

ArtefactAs-ofContents
Statement of Applicability, FAD-2026-0004Year end93 obligations, 81 applicable, 12 excluded with justifications
Crosswalk exportYear end187 approved mappings valid at that date
Requirement packsYear end14 obligations the auditor selected
Findings exportCurrent41 findings, 29 closed, 12 open
Action plans exportCurrent38 plans, status and owners
Evidence exportCurrent1,840 artefacts with dates and links

Why the first three are as-of and the last three are current: the auditor is testing the position at year end, and the remediation position now. Mixing the two would produce a package that contradicts itself.

The 14 requirement packs are the substance. Each answers the full chain for one obligation, and the auditor can trace every claim in it.


Troubleshooting

"An export is missing rows I can see elsewhere." Exports respect permissions and any filters applied. Check both.

"A stored report pack disagrees with the register." A stored artefact is a point-in-time document; the register has moved on. Use historical reconstruction if you need the position as of a date.

"Scheduled reports are not appearing on the calendar." Correct. Report generation is a technical schedule.

"I cannot export." Requires export.data, plus mapping.export for crosswalk data.


OrviQ Enterprise Governance, Risk & Compliance Platform