Use Case
For Auditors
A structured evidence record: every control, its status, its supporting evidence, and a certification statement, formatted for a compliance file rather than a conversation.
Why It Matters
Why Auditors Need This
Assurances Aren't Evidence.
An organization saying it takes AI governance seriously doesn't hold up in an audit. What holds up is a specific control, a specific status, and a specific piece of evidence behind it.
Frameworks Are Voluntary, but Reviewers Still Expect Them.
NIST AI RMF isn't legally mandated, but it has become the reference point most reviewers measure an organization against. Without a structured self-assessment, that comparison has to be built from scratch every time.
Findings Need to Be Traceable.
An auditor needs to know exactly where a claim came from — which questionnaire answer, which log evidence, which control it maps to — not just a final score with no paper trail behind it.
Report Contents
What's in the Auditor Evidence Package
This is the same underlying assessment used across every Compass report — upload a log, detect AI tools, answer the governance questionnaire — just formatted as a structured evidence record instead of a technical or leadership one.
Assessment Metadata
Assessment type, methodology, scope, and a clearly stated limitation: this is a self-assessment based on DNS log evidence and self-reported answers, not a formal third party audit.
Summary Statistics
Tools detected, governance risk score, controls flagged, gap score, and overall risk posture, presented as fixed figures rather than visual summaries.
NIST Function Compliance Summary
Gap score, maximum potential, and percentage unmet for each of the four functions, giving a reviewer the top level compliance picture before they reach individual controls.
Control Status Matrix
All 19 controls in one table, each with its function, severity, and status, so a reviewer can confirm coverage at a glance.
Structured Findings
Every unmet or partially met control, documented with its NIST reference, the questionnaire question behind it, the evidence basis, and a recommended remediation, ranked by severity.
Evidence Summary
A table describing exactly where each type of evidence came from — DNS log analysis, the governance questionnaire, the AI domain registry, and the NIST control mapping — along with the limitations of each source.
Certification Statement
A closing statement summarizing what was assessed, what was found, and an explicit note that this document should be reviewed by a qualified information security professional before use in a formal filing.
Questions
Frequently Asked Questions
Does this count as a NIST certification?
No. NIST AI RMF is a voluntary framework, not a certification. This package is a structured, evidence backed self-assessment against that framework, not a third party certification, and the document says so directly.
What counts as evidence in this report?
Two things: DNS log data submitted by the organization, and self-reported answers to the governance questionnaire. Both are documented plainly as their own evidence type, along with what each one can and can't confirm.
Why do so many findings share the same evidence basis?
Because they do. A single "unsure" answer to one questionnaire question can leave several related NIST controls only partially demonstrated at once. The evidence record reflects that honestly rather than fabricating separate justifications for each one.
Can this replace an external audit?
No, and the document says so in its own limitations section. It's meant to prepare an organization for an audit, by giving a reviewer a structured starting point, not to substitute for independent controls testing.