-
Notifications
You must be signed in to change notification settings - Fork 2
User Guide Reports

The deliverables that leave Cairn and land in an auditor's inbox, generated from live data rather than assembled by hand.
| Report | Format | Contents |
|---|---|---|
| Statement of Applicability | Every requirement, its applicability, its justification and its status | |
| Audit report | An assessment's findings, with the scope tree and per-requirement detail | |
| Risk register | XLSX | The register with initial, current and residual levels, and treatment |
| Meeting minutes | DOCX / PPTX | Management review minutes and steering decks |
Two properties are worth relying on.
Only records that count are counted. A report includes what its lifecycle marks as counting in reports, which is why a draft risk does not appear in the Statement of Applicability. This is the same rule the dashboard uses, so the two agree.
Your perimeter applies. A report is a read like any other and is filtered to your scopes. Two people generating "the" risk register can legitimately produce different documents.
Generated reports are listed under Governance -> Strategy -> Reports, so a deliverable you produced last quarter is retrievable rather than regenerated from data that has since moved.
The ISO 27001 clause 9.3 management review, structured as the clause requires rather than as a free-text meeting note.
A review has participants with roles, and it records:
Stakeholder feedback (clause 9.3.2.e), the formal input from interested parties.
Decisions, each categorised, tied to the input clause that prompted it, with a priority, an owner and a status. A decision that is recorded but never tracked is a decision that did not happen, and this is what stops that.
ISMS changes, the change log the standard expects : what changed in the management system, when, and why.
Comments on the record itself.
The review runs its own lifecycle, and can be cancelled from most steps with a recorded reason.
Minutes are generated as a document, so the record in Cairn and the document circulated afterwards come from the same source and cannot drift.
A management review is where the other modules converge : compliance status, open nonconformities, risk posture, incidents and their post-incident reviews, objective progress, stakeholder feedback.
The decisions it produces feed back out, into action plans, treatment plans and ISMS changes. That loop closing, and being visible, is what an auditor is looking for when they ask to see your management review.
Built from docs/ at v0.36.0. Edits made here are overwritten by the next release : open a pull request against the source instead.
- Administration
- Ask Cairn
- Assets and suppliers
- Compliance
- The dashboard
- Finding your way
- Getting started
- Incidents
- How records move
- Organisational context
- Reports and management review
- Risks
- Trust Center
- Architecture
- Configuration
- Contributing
- The documentation system
- Installation
- Internationalisation
- Operations
- Release process
- Security
- Testing
- Adding an assistant provider
- Adding a dashboard widget
- Adding a domain entity
- Declaring a lifecycle
- Adding an MCP tool
- Adding a REST endpoint
- Adding a report
- Interface conventions
- Dashboard widgets
- Lifecycles
- MCP tools
- MCP tool parameters : Assets
- MCP tool parameters : Compliance
- MCP tool parameters : Governance and context
- MCP tool parameters : General
- MCP tool parameters : Incidents
- MCP tool parameters : Reports and management review
- MCP tool parameters : Risks
- MCP tool parameters : System and administration
- MCP tool parameters : Trust Center
- Management commands
- Models
- Permissions
- REST endpoints
- Environment variables
- MCP server
- REST API
- Assistant module (Ask Cairn)
- Module 0: User Management and Access Control
- Module 1: Context and Organization
- Module 2: Asset Management
- Module 3: Compliance
- Module 4: Risk Management
- Module 4 bis - EBIOS Risk Manager
- Module 5 : Trust Center
- Module 6 : Security Incident Management
- Management review : ISO 27001:2022 compliance (clause 9.3)