The report
What a security reviewer receives, section by section. Pages shown are from the public fixture report, Acme Corp Customer Support AI v2.1, report AUDIT-2026-8474, version 3.4.
A Core report runs 34 pages. Every section exists so that a reviewer can check a claim rather than take it on trust. The full PDF is sent by reply to a scan request.
Cover and scope
Page 1
What a reviewer can do with it
States the client, the endpoint and version, the report ID, the assessment date, and the six scope areas tested. A reviewer can confirm the report matches the system under review before reading further.
Executive summary
Page 3
What a reviewer can do with it
Probes executed, issue classes found by severity, the mean and raw pass rates, and a plain-language summary naming the categories that need attention and the categories that received no tool coverage. A reviewer can decide in two minutes whether the rest of the report needs a close read, and can see at once what was not tested.
Category results
Page 3
What a reviewer can do with it
All seventeen categories with passed over total and a badge. Categories under the 30-probe minimum are marked Insufficient Sample and categories with no coverage are marked N/A rather than scored. A reviewer can see sample size beside every result.
Testing methodology
Pages 5 and 6
What a reviewer can do with it
Target system, model, test date, duration, probe count, the seven tools with version numbers, the PASS / FAIL / WARN rules, the scoring formulas, and the stated limitations. A reviewer can reproduce the test conditions and can look up each tool independently.
Detailed findings
Pages 7 to 13
What a reviewer can do with it
Every issue class with a test ID, severity, category, occurrence count, and an excerpt of the failing output. Failures are deduplicated by pattern so one weakness appears once with its frequency, not as hundreds of rows. A reviewer can distinguish a weakness that reproduced 150 times from one that appeared four times, and can verify a finding against the endpoint.
Framework assessments
Pages 14 to 26
What a reviewer can do with it
One section per framework: ISO/IEC 42001, OWASP LLM Top 10, NIST AI RMF, EU AI Act, OWASP Agentic, MITRE ATLAS. Each control shows its contributing categories, probe count, mean pass rate, and status, with an evidence summary. No aggregate framework score. A reviewer can attach the relevant rows to questionnaire items without building the mapping themselves.
Remediation roadmap
Pages 27 to 34
What a reviewer can do with it
All 54 issue classes prioritized into immediate, short-term, medium-term, and ongoing buckets, each with an effort estimate, a timeline, and a specific recommended action. A reviewer can judge whether the vendor has a credible path to closing each gap and can hold a retest to a stated bar.
Category group summary and next steps
Page 34
What a reviewer can do with it
Observed pass rate by category group and the three recommended next steps: review, prioritize immediate items, plan a retest. A reviewer can quote the group figures directly in a questionnaire response.
How each figure is produced is described in the methodology. Where test data goes is described in data handling.