A compliance report has exactly two audiences, and they want different things.
Your management team wants to know whether the programme is on track and where the risk sits. Short, comparative, and honest about what is slipping. Your auditor wants to see that a control operated, on which dates, with evidence attached. Not a summary of it.
Most reporting problems come from trying to serve both with one artefact. A board deck full of audit details gets skimmed. An audit file made of board slides gets rejected.
Compliance tooling tends to answer reporting with a percentage and a ring chart. It is genuinely useful for the person running the programme day to day, and it is not a report.
An auditor cannot accept a screenshot of a completion figure. The question is always narrower: show me this control, show me it ran in March, show me who reviewed it. That means records with dates and owners, not an aggregate.
And a board does not need the aggregate either. It needs to know what changed since last time, what is at risk of missing a date, and what decision is being asked for. A 94% that was 93% last quarter tells them nothing they can act on.
So the honest version is three outputs from one set of records: a standing management summary, an evidence file per framework, and an exception list. The last one is the only one anybody reads closely.
Reporting fails on frequency far more often than on format. A monthly board report nobody has time to write becomes a quarterly one written the night before.
For a team of one or two people carrying compliance alongside another job, this holds up: exceptions reviewed monthly, taking fifteen minutes because it is a list of what went past due. A management summary quarterly, aligned to the meeting that already exists rather than a new one. The evidence file continuous, because it is a by-product of doing the work rather than a document you assemble.
One rule makes the difference. Whoever owns a control owns its evidence at the moment it is produced. Evidence collected retroactively before an audit is where the late nights come from, and it is also where gaps get discovered too late to fix.
Name an owner for the report itself, not just for the controls. Reports without an owner? are the ones that quietly stop.
The reason reporting turns into a project is usually that the evidence lives somewhere other than the report.
ISOPlanner™ runs inside Microsoft 365, so controls, risks, suppliers and evidence sit in the tenant your team already signs into. The management view and the exception list are drawn from those same records rather than from a copy that has to be kept in step, and they surface in Teams next to the work rather than behind another login.
That removes the step where somebody exports, pastes and reconciles. It also removes the failure that this step causes, which is a report that was true on the day it was assembled and drifted afterwards.
The test is simple. If producing your quarterly report takes more than an hour, you are not reporting, you are rebuilding. Fix the place the evidence lives and the report stops being work.
Log in to your ISOPlanner™ workspace, or start a free trial.
Log in Start your free trial