KITE 2025 New Product Award — Local IT | SACEEC

How Do You Track and Report Compliance Status?

A compliance status that no one trusts is worse than none at all. Learn how to track and report status that holds up to scrutiny.

Free PDF GuideDownload this guide as a PDF

Leadership rarely asks for the detail behind your compliance programme. They ask one question: are we compliant? Answering it honestly requires a system for assigning, evidencing, and rolling up status across every obligation you track. This guide shows you how to build a status taxonomy, ground each rating in evidence, surface it in dashboards, and report it up the chain in a way that drives decisions rather than false comfort.

Watch: How to track and report compliance status Watch: Tracking and reporting compliance status (short tutorial)
i

What You'll Learn

By the end of this tutorial you will have a status taxonomy, a method for grounding each status in evidence, a dashboard structure with RAG reporting, a sensible review frequency, and a clear approach to reporting compliance status up to management and the board.

A Clear Status Taxonomy

Tracking starts with a shared vocabulary. If one team's "in progress" is another team's "compliant", your rollups are meaningless. Adopt a small, unambiguous set of statuses and define each one precisely. The four-state taxonomy below works for almost every programme.

Status Definition Evidence Expectation
Compliant The obligation is fully met and operating as required Current, verified evidence on file
Partially Compliant Some requirements met; identifiable gaps remain Evidence of what is met plus a documented gap and plan
Non-Compliant The obligation is not met Gap documented; remediation owner and date assigned
Not Assessed Status has not yet been evaluated None yet; flagged for assessment

"Not Assessed" is the honest status that most immature programmes hide. Pretending an unexamined obligation is compliant is the single most dangerous habit in compliance tracking. A register that openly shows what has not yet been assessed is far more trustworthy than one that is uniformly, and falsely, green.

!

Important

Never let "Not Assessed" silently collapse into "Compliant". An unassessed obligation is an open risk, not a passing grade. Report the count of not-assessed obligations as a headline metric until it reaches zero.

Evidence-Based Status

A status is only as credible as the evidence behind it. "Compliant" stated on someone's word is an opinion; "Compliant" backed by a dated, verifiable artefact is a fact. Tie every status to evidence using the principles covered in compliance evidence.

For a status to qualify as evidence-based, the evidence must be:

  • Specific: It addresses this exact obligation, not a general policy statement.
  • Current: It falls within the freshness window for that obligation. A penetration test from three years ago does not evidence current network security.
  • Verifiable: Someone other than the owner could examine it and reach the same conclusion.
  • Attributable: It is clear who produced it and when.
Example

From Opinion to Evidence

Obligation: Employees complete annual data protection training.

Opinion-based status: "Compliant, HR says everyone did the training."

Evidence-based status: "Compliant. The LMS completion report dated 14 Feb 2026 shows 98% completion; the remaining 2% are on leave with completion due by 28 Feb, tracked as an action."

The second version is auditable, time-stamped, and even surfaces a small gap, which is exactly what a regulator would want to see.

Want the full framework with worked examples?

Building a Compliance Dashboard

A dashboard turns hundreds of obligation-level statuses into a picture leadership can absorb in seconds. A good compliance dashboard answers four questions at a glance: How compliant are we overall? Where are the worst gaps? What is being remediated, and is it on track? What has not yet been assessed?

Structure your dashboard in layers so each audience sees the right altitude:

  • Summary tile: Overall RAG status and the percentage of obligations compliant.
  • Breakdown by domain or regulation: Status grouped by POPIA, health and safety, financial reporting, and so on, so you can see which areas are weakest.
  • Remediation tracker: Open non-compliant and partially compliant items, their owners, and due dates, with overdue items flagged.
  • Trend line: Compliance percentage over time, which matters far more than any single snapshot.

Your dashboard should draw directly from your compliance register rather than a separate spreadsheet maintained by hand. A dashboard fed by manual copy-paste drifts out of date and quietly loses credibility.

i

Pro Tip

Add a "last reviewed" date to each obligation and surface the oldest ones on the dashboard. An obligation marked compliant but not reviewed in 14 months is a hidden risk dressed up as green. Stale assurance is one of the most common things inspectors probe during a regulatory inspection.

RAG Reporting

RAG, short for Red, Amber, Green, is the universal shorthand for status reporting. Its power is also its danger: it is so simple that people game it. The fix is to define each colour by objective criteria, not gut feel.

RAG Maps To Trigger Criteria
Green Compliant Fully met, current evidence on file, reviewed within cycle
Amber Partially compliant or remediation on track Gap exists but has an owner and a date, and is not overdue
Red Non-compliant or remediation overdue Obligation not met, or remediation past its due date, or no plan

The crucial rule: an item turns Red the moment its remediation goes overdue, regardless of how minor the original gap was. This stops Amber from becoming a permanent parking lot for problems nobody is fixing. "Not Assessed" should be shown as a distinct neutral colour (often grey) so it is never confused with Green.

Rolling Up RAG

When summarising many obligations into one domain status, use a conservative rollup: a domain is only Green if every obligation in it is Green. One Red obligation makes the domain Amber or Red, depending on materiality. Averaging colours into a comfortable middle hides exactly the items leadership needs to see.

How Often to Track and Report

Tracking and reporting run on two different clocks. Tracking is continuous; reporting is periodic. Match each to risk.

Activity High-Risk Obligations Standard Obligations
Status review by owner Monthly Quarterly
Evidence refresh Per evidence freshness window Annually or per window
Management report Monthly or quarterly summary
Board report Quarterly, with exceptions escalated immediately

The cadence you already use to track compliance obligations is the natural rhythm for status review. The key is that material changes, such as a new Red item or a missed statutory deadline, are escalated immediately rather than waiting for the next scheduled report.

Reporting Up to Management and the Board

The same data must be packaged differently for different audiences. Operational managers want the obligation-level detail; the board wants the exceptions, the trend, and the decisions required of them.

Reporting to Management

Management reports can be detailed: full RAG breakdown by domain, the remediation tracker with owners and dates, and any obligations slipping. The goal is to enable managers to reallocate effort and unblock their teams.

Reporting to the Board

Board reporting is an exercise in distillation. Directors do not want a 60-row register; they want to know whether the organisation is exposed and what they are being asked to decide. Lead with the headline RAG status and trend, then the small number of material exceptions, then any decisions or resources required. The detail of what belongs in that report is covered in what goes into a compliance report for the board.

Example

A Board-Ready Status Summary

Overall: Amber. 82% of obligations compliant, up from 76% last quarter.

Material exceptions: Two Red items. (1) Breach notification process untested; remediation due 31 March. (2) Three vendors operating without signed data processing agreements; legal review in progress.

Decision requested: Approve budget for an external breach-response tabletop exercise in Q2.

This fits on one slide, tells the board exactly where the risk is, and asks for a clear decision.

i

Pro Tip

Always show a trend, not just a snapshot. A board seeing "82% compliant" learns little; a board seeing "82%, up from 76% two quarters ago" understands that the programme is improving and that current investment is working. Direction beats position.

Common Mistakes to Avoid

1. A Sea of Green

A dashboard where everything is green almost always means status is being self-reported without evidence or genuine assessment. Reviewers should be suspicious of uniform green, not reassured by it.

2. Amber as a Comfort Zone

Items parked at Amber for months with no progress are really Red. Enforce the rule that overdue remediation turns an item Red automatically.

3. Status Without Evidence

A status nobody can substantiate collapses the first time it is challenged. Require evidence references for every Compliant rating.

4. Averaging Rollups

Averaging obligation statuses into a comfortable domain colour buries the exact items leadership needs to act on. Roll up conservatively.

5. Reporting Detail to the Board

Burying directors in obligation-level rows means the material exceptions get lost. Distil ruthlessly for the board; keep the detail for management.

Key Takeaways

Summary

  • Adopt a small, precise status taxonomy (compliant, partially compliant, non-compliant, not assessed) and never disguise "not assessed" as compliant.
  • Ground every status in specific, current, verifiable, attributable evidence.
  • Build a layered dashboard fed directly from the register, surfacing overall status, domain breakdown, remediation, and trend.
  • Define RAG by objective criteria; turn items Red automatically when remediation goes overdue, and roll up conservatively.
  • Match review frequency to risk, and escalate material changes immediately rather than waiting for the next report.
  • Package the same data differently: detail for management, distilled exceptions, trend, and decisions for the board.

Frequently Asked Questions

How many status levels should I use?

Four is enough for almost any programme: compliant, partially compliant, non-compliant, and not assessed. More levels create false precision and disagreement about boundaries; fewer hide important distinctions. The discipline is in defining each level precisely and applying it consistently.

What does "evidence-based status" actually mean?

It means each status is backed by a specific, current, verifiable artefact rather than someone's assertion. A compliant rating should point to a dated document, report, or record that an independent reviewer could examine and reach the same conclusion. Without that, the status is an opinion that collapses under challenge.

When should an item turn Red on a RAG report?

An item is Red when the obligation is not met, when there is no remediation plan, or, critically, the moment its remediation goes overdue, however minor the original gap. This automatic escalation stops Amber from becoming a permanent home for stalled problems and keeps the report honest.

How often should I report compliance status to the board?

Quarterly is standard for routine board reporting, with material exceptions such as a missed statutory deadline or a new high-severity gap escalated immediately rather than held until the next meeting. Management typically receives more frequent and more detailed reports, monthly or quarterly depending on risk.

Should a dashboard ever be entirely green?

Rarely, and it should prompt scrutiny rather than relief. Uniform green usually signals self-reported status without evidence or genuine assessment. A healthy dashboard typically shows some Amber items in remediation and an honest count of anything not yet assessed. Direction of travel matters more than a perfect snapshot.

Can I track compliance status in a spreadsheet?

Spreadsheets work when you start out, but they struggle with evidence links, audit trails, automatic RAG escalation, and dashboards that update without manual copy-paste. As the programme matures, a system that draws status directly from your register keeps reporting current and removes the drift that erodes trust in the numbers.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.