Sheet MER-14 — Audit & Compliance Manual
Executive Summary
Leadership-facing posture views, concise status communication, and the summaries used to explain program state without flattening it.
Scope
Leadership summaries only work when they stay grounded in the same operating truth the compliance team is using. This page keeps the public-safe communication model and strips implementation-level detail.
Period, freshness, unknown-data, and governed-export truth is generated in the
Audience: Compliance leads preparing board, audit-committee, and executive posture updates. Last verified: 2026-08-12
Open the summary
Open Programs, select a program, then choose Executive Summary. The route is
The page distinguishes live metrics from persisted trend observations:
-
The readiness dial, controls, alerts, findings, MAP count, and framework coverage are computed when the page loads.
-
The trend contains only persisted daily observations within the visible inclusive period.
-
Current, Stale, or Unknown describes the newest persisted observation. The page also shows the latest snapshot date and observed versus expected calendar days.
-
Missing dates remain visible gaps because chart positions use actual elapsed calendar time.
- An unavailable value is shown as N/A with its server-provided reason. It is never changed to
zero. A real zero remains
0.
Choose 7, 30, 90, or 180 days in Trend period. The selection is saved in the URL
as trend_days, so a bookmarked link reopens the same view.
Create a governed board artifact
Users with Meridian.reports.view can choose Export board PDF. Meridian generates the PDF from
the same server projection used by the page and the exact selected period. The button remains
disabled while generation is in progress.
The artifact visibly includes the period, generation time, freshness, observation coverage, and all unknown-data disclosures. Meridian records an audit receipt containing the actor, tenant, program, period, canonical projection hash, output hash, and byte count. Response headers expose the projection and content hashes for verification.
If export fails, no success or download is claimed. The error remains visible and Retry repeats the same program and period. Do not substitute screenshots or direct API calls for this workflow.
Interpret the metrics
-
Readiness credits applicable controls whose tests pass or that have an approved exception. A control without tests remains unverified and reduces readiness.
-
Controls shows total controls and the narrower fully implemented count.
- Open alerts includes
openandacknowledged, matching the linked active Alerts view. - Open findings excludes
remediatedandclosedfindings. -
Open MAPs includes
openandin_progressplans. N/A means the remediation ledger did not return an authoritative count. -
Framework coverage uses the same projection as the program dashboard.
Recovery
| State | Safe action |
|---|---|
| Summary load failed or response is invalid | Choose Retry. Prior data is cleared; cross-program or incoherent responses are not rendered. |
| Freshness is stale | Confirm the latest snapshot date, then investigate the snapshot scheduler before presenting the trend as current. |
| Freshness is unknown | No persisted observation exists in the period. The live readiness dial can still be read, but do not claim a trend. |
| A metric is N/A | Read its unknown-data reason and retry. Do not report it as zero. |
| PDF export failed | Use the export error’s Retry action. It preserves the exact selected period. |
| Export permission is absent | Request Meridian.reports.view; page access alone does not authorize board artifact generation. |
Dashboard and Alerts links retain the same program scope. Tenant isolation is enforced by the API; an inaccessible or other-tenant program returns not found.