Configuring Compliance Reports
LT Auditor MP includes built-in compliance reporting capabilities that produce structured, audit-ready documentation of your environment’s security activity mapped to specific regulatory framework requirements. This article covers how to configure compliance frameworks, set up compliance rules, generate compliance reports, and schedule automated delivery — drawing on the full capabilities of the Comply module.
Understanding compliance reporting:
Compliance reports in LT Auditor MP are generated from the Comply module and differ from standard reports in that they are directly tied to configured compliance frameworks and rules. Each report documents the compliance status of specific requirements, provides evidence links to supporting audit log data, and highlights violations that need to be addressed.
Effective compliance reporting requires:
- Compliance frameworks configured with the relevant regulatory requirements
- Compliance rules linked to audit environments, categories, and operations
- Reports linked to compliance rules as evidence sources
- A schedule for automated delivery to stakeholders and auditors
Supported compliance frameworks:
| Framework | Focus Areas |
| GDPR | Data access logging, deletion tracking, consent management, breach notification |
| HIPAA | Patient data access, PHI auditing, security incident tracking |
| NIS 2 | Network and information security requirements |
| NIST 171 | Controlled unclassified information protection |
| ISO 27001 | Security event monitoring, incident management, access control |
| DORA | Digital operational resilience |
| PCI-DSS | Cardholder data access, network security monitoring, access control |
| FFIEC | Financial institution security and audit requirements |
| FDIC | Federal deposit insurance compliance |
| SOX | Financial system access, change management, audit trail integrity |
Step 1 — Configure a compliance framework:
If a framework has not yet been created:
- Navigate to Comply in the main navigation menu
- Click Add Compliance Framework
- Configure the framework:
| Field | Description |
| Name | Framework name (e.g., HIPAA Compliance) |
| Description | Purpose and scope of the framework |
| Reference Code | Standard identifier (e.g., HIPAA-45-CFR) |
| Category | Industry or regulation type |
| Priority | Critical, High, Medium, or Low |
- Click Save
Step 2 — Create compliance rules:
Each compliance framework requires rules that define specific requirements and how the system monitors them.
- Select the compliance framework
- Click Add Rule
- Configure the rule:
| Field | Description |
| Rule Name | The specific requirement (e.g., PHI Access Must Be Logged) |
| Description | Detailed explanation of the requirement |
| Reference | The section or clause number from the framework |
| Severity | Impact level if violated |
- Link the rule to audit data:
| Field | Description |
| Environment | Which environment this rule monitors |
| Category | Which log category provides evidence |
| Operations | Which specific operations must be present |
| Required Frequency | How often events should occur |
| Alert Threshold | When to trigger a compliance alert |
- Define compliance criteria:
| Criteria | Description |
| Must Exist | Specific events must appear in the audit data |
| Must Not Exist | Specific events must never occur |
| Count Thresholds | Minimum or maximum event counts |
| Time Constraints | Events must occur within defined timeframes |
- Click Save
Step 3 — Link reports to compliance rules:
Linking standard reports to compliance rules automates evidence collection and makes compliance reports significantly more useful for auditors.
- Open the compliance rule configuration
- Navigate to the Linked Reports tab
- Click Link Report
- Select the reports that provide evidence of compliance for this rule
- Click Save
Link at least one report to each compliance rule before generating compliance reports. Rules without linked reports will not have associated evidence for auditors to review.
Step 4 — Generating compliance reports on demand:
- Navigate to Comply → Reports
- Select the compliance framework to report on
- Choose the time period to cover
- Select which rules to include:
| Option | Description |
| All Rules | Include every rule in the framework |
| Non-Compliant Rules Only | Focus on violations requiring attention |
| Critical Rules | Include only Critical severity rules |
| Custom Selection | Choose specific rules manually |
- Click Generate Report
- Download in your preferred format:
- PDF — for auditor submission and formal documentation
- Excel — for detailed internal analysis
- CSV — for data processing and further analysis
Step 5 — Scheduling compliance reports:
Automate compliance report generation and delivery ahead of known audit periods or as part of ongoing compliance monitoring:
- Navigate to Comply → Scheduled Reports
- Click Add Schedule
- Configure the schedule:
| Field | Description |
| Framework | Which compliance framework to report on |
| Frequency | Weekly, Monthly, Quarterly, or Annually |
| Recipients | Email addresses for report delivery |
| Format | PDF, Excel, or CSV |
- Click Save
Compliance report contents:
Generated compliance reports include the following sections:
| Section | Contents |
| Executive Summary | Overall compliance score, rules met vs. violated, critical findings, trends over time |
| Framework Coverage | All rules with compliance status and evidence references |
| Violations and Findings | Non-compliant rules, timestamps, affected systems or users, severity |
| Supporting Evidence | Links to audit logs, linked report references, timestamps and metadata |
| Remediation Status | Actions taken, responsible parties, resolution timelines |
Monitoring compliance status between reports:
Use the compliance dashboard to monitor status in real time between scheduled report runs:
- Navigate to the Compliance Dashboard
- Review:
- Overall Compliance Score — percentage of rules currently met
- Compliant Rules — rules currently satisfied
- Non-Compliant Rules — rules with active violations
- Pending Rules — rules awaiting validation
- Drill into individual frameworks and rules to view violation details and evidence
- Manually trigger rule evaluation using Evaluate Now if immediate status is needed following a system change or incident
Compliance alerts:
Configure alerts so your team is notified immediately when a compliance violation is detected rather than discovering it during a scheduled report review:
- Open a compliance rule
- Navigate to the Alerts tab
- Click Add Alert
- Configure:
| Field | Description |
| Trigger Condition | When to send the alert |
| Recipients | Email addresses or user groups |
| Alert Frequency | Immediate, Daily, or Weekly |
| Escalation | Who to notify if the violation is not resolved |
- Click Save
Compliance audit trail:
Maintain an auditable record of all changes to your compliance configuration:
- Navigate to Comply → Audit Log
- Review:
- Framework creation, updates, and deletions
- Rule modifications
- Report access history
- Alert history
- Filter by date, user, or framework
- Export the audit trail for external auditors when required
Best practices:
- Configure all frameworks and rules well in advance of known audit periods — do not wait until an audit is imminent to set up compliance monitoring
- Link reports to every compliance rule before generating compliance reports — rules without evidence links provide limited value to auditors
- Schedule compliance reports to deliver automatically at a frequency appropriate for each framework — monthly for ongoing monitoring, quarterly for formal audit preparation
- Review compliance status on the dashboard regularly between scheduled report runs so violations are identified and addressed promptly
- Document remediation actions taken for each violation and retain that documentation alongside the compliance reports
- Restrict compliance configuration access to authorized personnel only
- Retain all generated compliance reports according to your organization’s regulatory retention requirements
- Test compliance rules with sample data before relying on them for formal audit reporting
[Your administrator should review all configured frameworks and rules prior to any external audit to confirm they accurately reflect your organization’s compliance obligations and that linked reports are providing appropriate evidence.]