Skip to content
ComplyMynt

Sample report

A report your board and your engineers can both use.

Below is the report structure, live scorecards, and a set of redacted findings drawn from real engagements.

pages
24–60

pages

business days
10–15

business days

severity scoring
3-axis

severity scoring

evidence-backed
100%

evidence-backed

Preview of a ComplyMynt audit report showing the executive summary and scored findings register
Redacted excerpt — severity scoring, evidence links, and the remediation backlog are included in the full document.

Scorecards

Domain scores, with the evidence behind every number

Scores are recalculated on each re-scan so you can show progress rather than assert it.

0

Privacy & consent

12 findings

0

Accessibility

9 findings

0

Public security

4 findings

0

AI governance

7 findings

Structure

What is inside every report

  1. 1. Executive summary

    One page. Posture, top three exposures, and the recommended sequence of work.

  2. 2. Scope & method

    Surfaces tested, jurisdictions considered, tooling used, and explicit exclusions.

  3. 3. Compliance scorecards

    Domain-level scores with the evidence behind each number, trended across re-scans.

  4. 4. Findings register

    Each finding scored by likelihood, exposure, and remediation cost, with evidence attached.

  5. 5. Remediation backlog

    Written as tickets: owner, acceptance criteria, effort estimate, and regression test.

  6. 6. Monitoring plan

    What to re-verify, how often, and which signals indicate drift.

Redacted findings

Example entries from the register

Expand any finding to see the evidence attached and the remediation we would ship.

CM-014CriticalConsent

Analytics and ad trackers fire before consent

Six third-party trackers set identifiers on first paint, ahead of any banner interaction, in all tested EU sessions.

Evidence attached

  • HAR trace of first paint showing tracker requests before consent
  • Annotated screenshots of the banner in the pre-interaction state
  • Reproduction steps for a clean EU session profile

Remediation shipped

  • Gate all non-essential tags behind the CMP consent signal
  • Add a server-side check that blocks tag injection without a stored consent record
  • Ship a CI test asserting zero third-party requests before consent
CM-027HighAI

AI feature lacks required automated-processing disclosure

Model-assisted scoring affects user outcomes with no disclosure, opt-out path, or human review documented.

CM-033HighTCPA

SMS opt-in lacks express written consent language

Checkout capture bundles marketing SMS into terms acceptance and stores no timestamped consent record.

CM-041MediumAccessibility

Primary onboarding flow is not keyboard operable

Custom dropdowns trap focus at step two, blocking screen reader and keyboard-only account creation.

Coverage

Every domain, counted and evidenced

The register opens with this table so leadership can see the shape of the risk in ten seconds.

Example findings coverage by domain and severity
DomainCriticalHighMediumMethod
Privacy & cookies246Network traces, CMP behavior, policy review
AI governance133Model/data flow mapping, vendor terms, disclosures
TCPA & marketing122Form capture, opt-out testing, record review
Accessibility036WCAG 2.2 AA automated + manual AT testing
Public security013Header/TLS posture, exposed surface, disclosure

Remediation

What the same surface looks like after the fix

Remediation impact

After

After remediation

  • Zero non-essential requests before consent, enforced in CI
  • Express written consent captured and stored with proof
  • Full keyboard and screen-reader path through onboarding
  • Automated-processing disclosure with human review path

Audiences

One document, three readers

For your board

A one-page posture read, the three exposures that matter, and what each costs to close.

For your counsel

Evidence-backed findings mapped to GDPR, CPRA, TCPA, ADA/WCAG, and state privacy expectations.

For your engineers

Reproduction steps, acceptance criteria, effort estimates, and regression tests per ticket.

Timeline

From kickoff to walkthrough in 15 business days

  1. Day 1

    Kickoff & scope sign-off

  2. Day 2–6

    Evidence collection under NDA

  3. Day 7–10

    Analysis & severity scoring

  4. Day 11–13

    Draft report & internal QA

  5. Day 14–15

    Live walkthrough & backlog handoff

ComplyMynt risk dashboard showing tracked findings and remediation progress over time

Questions

About the report itself

Get the full 40-page sample report

Sent within one business day, under NDA if you prefer. No sales sequence attached.