# Employee AI security report review

Blank planning worksheet. It is not an Aona export, audit opinion or compliance determination.

## Define the review

- Question and audience:
- Review owner and date:
- Reporting period:
- Covered employee groups, devices and collection paths:
- Filters and included report components:
- Known gaps:

## Keep counts distinct

- Observed records:
- Evaluated records:
- Compliant:
- Redacted:
- Blocked:
- Warned:
- No Policy:
- Denominator used for each percentage:

No Policy is not a compliant or evaluated outcome. An intervention count does not establish risk reduction. The public events API excludes compliant records, so its total may differ from a configured report.

## Attach evidence and assign follow-up

- Relevant event identifier, time and available context:
- Applicable policy and configured response:
- Evidence source and collection date:
- Open question:
- Follow-up action and owner:
- Next review date:
- Observed result:

Do not include unnecessary sensitive content. Leave observed results blank until the supporting evidence is available.

Reference: https://aona.ai/solutions/ai-security-reporting/
