Use Case
For Executives
One page. One score. Three priorities. Everything a leadership briefing on AI risk actually needs, and nothing it doesn't.
Why It Matters
Why Executives Need This
A Board Doesn't Need 19 Controls, It Needs One Number.
Asked how exposed the organization is on AI, an executive needs an answer that fits in a sentence, not a walkthrough of every NIST subcategory.
Technical Reports Don't Travel to a Boardroom.
A report built for a security engineer, full of control IDs and severity weights, doesn't hold up in a ten minute leadership update. Something always gets lost translating it, or someone has to spend hours turning it into slides.
Without Ranking, Everything Looks Equally Urgent.
A list of eighteen unmet controls, with no order to it, doesn't tell leadership what to greenlight first. Priorities need to already be sorted by the time they reach the top.
Report Contents
What's in the Executive Summary Report
This is the same underlying assessment used across every Compass report — upload a log, detect AI tools, answer the governance questionnaire — just formatted for a leadership audience instead of a technical or audit one.
Key Metrics
AI tools detected, how many are high risk, the governance gap score, and the overall governance risk score, all visible in a single row.
Executive Overview
A short, plain language paragraph explaining what was found and what it means in practice, written the way someone would actually say it out loud, not the way a control matrix would phrase it.
Governance Gaps by NIST Function
A simple breakdown of Govern, Map, Measure, and Manage, showing which function has the largest gap, without requiring familiarity with individual control IDs.
AI Tools Detected
The tool inventory, presented for context rather than as a technical worklist.
Priority Actions
The highest severity gaps translated into four concrete next steps, each with a plain explanation of why it matters, backed by the same platform specific detail the Security Team report uses, so nothing has to be re-derived later.
Questions
Frequently Asked Questions
Is the Executive report a simplified version, or a different assessment?
The same assessment. It draws from the identical inventory and questionnaire data as the Security Team and Auditor reports, just reordered and summarized for a non technical audience.
Where do the four priority actions come from?
They're the highest severity confirmed gaps in the assessment, the same ones documented in full technical detail in the Security Team report. Nothing is invented for the executive version; it's the same findings, explained differently.
Can I hand this directly to a board or a client?
It's designed to be read in a short meeting without requiring a translator, but it's still generated by an automated assessment. We'd recommend a quick review by whoever owns AI governance internally before it leaves the building.
Does the executive summary hide anything that's in the other two reports?
No information is hidden, only reordered and summarized. The full control level detail remains available in the Security Team and Auditor reports for anyone who needs it.