Reporting and governance
The web report mirrors the current workbench state. Save before export so the server-generated PDF matches the visible record.
The comprehensive report includes context, readiness, assumptions, evidence gaps, risk and opportunity register, inherent and residual exposure, individual assessments and spread, controls, signposts, overdue or triggered items, acceptance, conditions, reservations, handoff, references, and method safeguards.
The branded PDF includes model and version identifiers, organization context, generation time, references, page numbers, and a machine-readable JSON attachment containing the normalized model and generated report.
Governance practices
- Create a version before material review or acceptance.
- Lock or archive a finalized record according to local governance.
- Reopen the process when a signpost triggers or source evidence changes.
- Compare versions rather than overwriting why a rating changed.
- Restrict access when records contain sensitive personal, legal, security, or commercial assessments.
- Treat AI suggestions as drafts and preserve human authority.
The report is decision support, not legal, financial, safety, or regulatory certification.