Skip to main content

Compliance Reports

The Compliance page in the Customer Portal is where a compliance officer reads the organisation's current posture per jurisdiction, generates a report over a date range, and exports the underlying evidence.

Calling the API directly?

This page is the portal walkthrough. If you are generating reports programmatically rather than from the UI, see the Compliance Reports API reference for the create/poll/download endpoints, report_state semantics, and error codes.

Eight regulatory frameworks are selectable. Availability note: the three US regulators (usinsurance, usbanking, ussecurities) all ship in platform v10.1.0; a deployment on v10.0.0 or earlier refuses them with 400 UNKNOWN_REGULATOR.

JurisdictionFrameworkWhat the report coversRetention expectation
European UnionEU AI ActConformity assessments, risk management (Arts. 9-17), accuracy and bias monitoring, audit trail, Article 43 conformity summaryLogs at least 6 months; technical documentation 10 years
India (securities markets)SEBI AI/ML guidelinesReadiness across the six pillars, audit export, retention posture, decision-chain lineage5 years
India (banking)RBI FREE-AIBoard report, incidents, kill-switch history, model validations, AI system registerAs set by the FREE-AI framework
SingaporeMAS FEATFEAT four-pillar assessments, system registry, kill-switch history7 years
IndonesiaOJK, Bank Indonesia, UU PDPAI governance summary, policy violations, LLM and decision activity, human oversight, PII redactions, cross-border transfers, 72-hour breach log, BI PJP section5 years
United States (insurance)NAIC AI Systems Evaluation Tool, NYDFS Circular Letter No. 7, Colorado Regulation 10-1-1Exhibit A "Quantify Regulated Entity's Use of AI Systems", Exhibit B "AI Systems Governance Risk Assessment Framework" (narrative or checklist variant), Exhibit C "High Risk AI Systems Details" with exceptions and overrides, Exhibit D "AI Systems Model Data Details", a fairness-testing pointer, the NYDFS CL7 and Colorado 10-1-1 annexes, scope, completeness and form versionThe NAIC exhibits are an examination information request and set no retention period of their own; for the documentation it describes, NYDFS CL7 points at 11 NYCRR 243, New York's insurance records-retention regulation
United States (banking)US banking supervision, federal and Farm CreditScope and completeness, AI and agent inventory, per-decision reconstruction, human oversight register, kill-switch and containment attestation, data-boundary report, third-party AI annex, monitoring summary, board pack, NIST AI RMF cross-indexSet by the instrument in scope: BSA SAR support 5 years; GLBA information-security records under the interagency Guidelines (12 CFR 30 App. B and companions) with their annual board report; Reg B adverse-action records 25 months where AI touches consumer credit
United States (securities)US securities examination (ussecurities): SEC advisers and FINRA broker-dealers, via the SEC_EXAM, FINRA_SUPERVISION and REG_SP frameworksEight sections in the order the SEC/FINRA AI sweep letters ask for them: AI-use inventory and observed responsible persons, interaction archive with the attribution chain in band on the json and jsonl formats, consequential-output log with human dispositions, supervision evidence, Regulation S-P annex, disclosure-vs-reality reconciliation, financial-crime evidence, and scope, completeness and instrumentsSet by the registration in scope: an adviser under Advisers Act rule 204-2, generally 5 years; a broker-dealer under Exchange Act rules 17a-3 and 17a-4, generally 3 to 6 years by record type, on WORM media or under the audit-trail alternative the 2022 amendments to rule 17a-4 added. AxonFlow provides no archival storage under either option

Selecting a jurisdiction loads that jurisdiction's data only. The page does not open every module's worth of requests to show you one.

The NAIC instrument behind the US insurance report is formally titled "Artificial Intelligence Systems Evaluation: Optional Supplemental Exhibits for State Regulators" and is known as the NAIC AI Systems Evaluation Tool. It comes from the NAIC Big Data and Artificial Intelligence (H) Working Group, and it is an examination information request that supplements market conduct, financial analysis and financial examination review procedures. It is not an annual-statement filing, and it is not run only by your domiciliary regulator.

The US insurance report is source evidence for your response to a regulator's information request, not a finding and not a compliance certification. Its fairness section is a pointer: it names the instrument and what AxonFlow holds that supports it, and states that AxonFlow performs no statistical fairness or bias testing. The NYDFS CL7 three-step quantitative analysis stays your own actuarial work. AxonFlow also does not classify a system as high risk (that is your determination), does not discover AI outside the paths routed through it, does not hold your line-of-business mapping or ECDIS register, and does not compute the share of adverse decisions. The Tool is at version 4.0, every page of it is marked DRAFT, and a multi-state pilot is running, so the artifact names the form revision it renders against; the adopted form may differ.

The US banking package renders in one of two supervisory vocabularies, and the Framework you choose decides which. FCA_EM31 renders the Farm Credit profile: the oversight register takes FCA Exam Manual EM-31.1's when/what/who/approver change-log form, the board pack is quarterly, and the 12 CFR Part 609 36-hour incident clock is stated. The other four render the federal profile, citing SR 26-2 / OCC Bulletin 2026-13 as current with SR 11-7 as its predecessor, on an annual board cadence. There is no separate profile control, so a request cannot ask for a combination that contradicts itself.

The US securities package works the same way: the Framework you choose decides the supervised population the artifact is cited against. SEC_EXAM renders the investment-adviser vocabulary, FINRA_SUPERVISION the broker-dealer vocabulary, and REG_SP reaches both, because the amended Regulation S-P applies to advisers and broker-dealers alike. There is no separate population control, for the same reason. The jsonl format is offered for this jurisdiction alone: one self-describing record per line, for the line-oriented systems that ingest into a broker-dealer's rule 17a-4 recordkeeping - whether on WORM media or under the audit-trail alternative the 2022 amendments to that rule added.

Reading a section

Each section is rendered in one of three states, and they mean different things.

The section has data

The tables show what the module holds for your organisation right now: your conformity assessments, your registered AI systems, your incidents, your kill-switch history. Nothing on this page is a sample or a placeholder.

The section is empty

An empty section says so plainly, with the count and the action that would fill it, for example:

0 conformity assessments Start one to populate this section. Assessments are created in the EU AI Act module; the console reads them.

This module is running and reachable. There is simply nothing recorded yet.

This is not an error and not a sign that the module is missing. It means the module answered normally and your organisation has not recorded anything in it yet. A new deployment starts here for most sections.

The section is not available

When a section cannot be shown, the page tells you which of five reasons applies, because each needs something different from you.

What you seeWhat it meansWhat to do
Not included in your licenceYour plan does not cover this module or this export. The message shown is the server's own, including any upgrade link. Daily export caps appear here too.Nothing is wrong with your data. Upgrading unlocks the section.
Your role cannot do thisYour role can read, but this particular action needs administrator authority on your team.Ask an admin on your team to run it. Everything you can read stays readable.
Your session has endedYou are signed out, or the deployment's internal authentication is not configured.Use Sign in again. Nothing is wrong with your data, your licence or your role.
Not available on this deploymentThe endpoint is not served by the platform version you are running.Nothing is wrong with your data. A newer platform version adds it.
Could not load this sectionThe server did not answer, or answered with an error. The HTTP status is shown.Use Retry. This is a temporary failure, not a licence or permission problem.

The distinctions matter in practice. A viewer, a non-paying account and a signed-out session each see a different message, and only one of the three is fixed by buying something.

Who can do what

Compliance reporting uses two separate permissions, and they are genuinely different questions.

ActionRequirement
Read any compliance sectionAudit read access on your organisation
Generate a reportAdministrator, owner or policy admin role
Download a generated reportAdministrator, owner or policy admin role
Export evidenceAdministrator, owner or policy admin role

Report viewing and report exporting are deliberately split. A reviewer with audit access can read every section on this page all day; a whole-tenant export is an administrator action, because a compliance artifact covering every user's activity is not a per-user read. If your role cannot export, the page says exactly that rather than implying the module is switched off.

Generating a report

  1. Select the jurisdiction.
  2. Set the From and To dates. The range is what the report covers.
  3. Choose a Format. Only the formats that jurisdiction supports are offered. Where a deployment's export can only produce one of them, the page says so after the download rather than silently handing you a different file type.
  4. Where the framework has sub-frameworks (SEBI, OJK including Bank Indonesia PJP, United States insurance, United States banking, and United States securities), choose one under Framework. For Indonesia, United States insurance, United States banking and United States securities the choice is required: each reports against several instruments (three, three, five and three respectively), and picking one for you would produce the report against the wrong instrument.
  5. Select Generate report.

If the report is produced immediately, a Download button appears with the record count. If it is queued, the page shows the job status and checks again every 30 seconds; Check now polls immediately rather than waiting for the next check. If the job is still running after ten minutes the page says so instead of spinning silently.

A failed job is reported as a failed job, with the server's reason. Nothing is downloaded in that case.

What the page tells you after a download

A confirmation, naming the file and its size:

Downloaded axonflow-sebi-report-2026-01-01-to-2026-06-30.json (14,220 bytes).

If the delivered file type is known and differs from the one you picked, that sentence continues:

This deployment's export returns JSON, not CSV; the other formats arrive with the compliance report facade.

A capped result set, in amber, as an alert, alongside the confirmation:

Export capped at 50,000 rows (most recent first). Narrow the date range to export the rest - the file you just downloaded is partial.

Treat that one as load-bearing. A compliance artifact that is silently partial is worse than one that is missing. A capped file is still a file, so the confirmation above stays on screen next to it: you can see both what arrived and that it is incomplete.

A signed-storage handoff, instead of the confirmation:

Your download has started from signed storage. The portal does not see that file, so check its name and row count before filing.

Large reports are delivered as a signed link straight from object storage. Your browser fetches them directly and names the file from storage's own headers, so the portal can tell you neither the filename nor the row count. It says so rather than reporting figures it never saw.

Exporting evidence

The Evidence export card is available whichever jurisdiction is selected. It bundles audit logs, workflow steps and approvals for your entitled window into a single JSON file, and shows the record counts before you download.

Two things worth knowing:

  • Your licence sets the window. If you ask for a range longer than your tier allows, the platform exports the part it can and the page tells you the range the file actually contains, rather than naming the file after the range you asked for.
  • Evaluation licences watermark the bundle. The disclaimer shown on the card is included in the exported file.

Frequently asked

A section says 0 records. Is the module broken? No. An empty section is a working module with nothing recorded yet. A broken module reads "Could not load this section" and shows an HTTP status.

I can read the page but the Download evidence button gives me a refusal. Your role has audit read access but not administrator authority. Ask an admin on your team; the export is theirs to run.

Report generation says it is not available on this deployment. On-demand generation is being rolled out per jurisdiction. Where it is not yet served, the sections on the page remain live and evidence export still works.

Can I generate a report for a jurisdiction we do not operate in? You can select any of the eight. The report will reflect what your organisation has actually recorded, which for an unused framework is an empty report.

What do the US packages NOT claim? Every US banking artifact carries five disclosures on its face: it reports what routes through AxonFlow's governed paths and does not discover AI elsewhere in the institution; kill switches are triggered manually, because AxonFlow does not automatically evaluate their thresholds; no statistical fairness or bias testing is performed; nothing classifies a system's risk tier or analyses any law's applicability; and the package is not a model validation or an effective-challenge record. It is also scoped to the requesting tenancy, and it states how many records in the period carry no organization attribution.

The US securities artifact makes the same coverage and containment disclosures, plus three of its own: AxonFlow provides no archival storage (rule 17a-4 is satisfied on WORM media or under the audit-trail alternative the 2022 amendments added, and the package is an export for whichever the firm operates); no output is classified as a recommendation, because that is a Regulation Best Interest legal judgment - the consequential-output log renders what the firm's own policies flagged; and the disclosure-vs-reality reconciliation adjudicates nothing - its declared column is empty by construction, for the firm to complete from its own Form ADV, brochure and marketing materials.