Compliance Reporting
Compliance evidence mapped to OJK, ISO 27001, NIST, and PDPA out of the box
Claro tracks 23 controls across four regulatory frameworks and turns your simulation and training data into board-ready, audit-ready PDF reports and evidence packages, without a spreadsheet in sight.
A control-coverage view shows how simulation and training activity maps to each OJK, ISO, NIST, and PDPA control.
Compliance teams at Indonesian financial institutions and government agencies are expected to show examiners exactly how their security awareness program maps to specific regulatory controls, not just that a program exists. Claro's control-coverage engine tracks 23 controls across OJK POJK 11/2022, ISO 27001:2022, NIST CSF 2.0, and PDPA Indonesia, and continuously scores each one against the campaigns, training assignments, and phishing reports actually running in your tenant, so the mapping is current rather than a document someone updates once a year.
When it's time to produce evidence, Claro generates Claro-branded, bilingual PDF reports server-side using Handlebars and Puppeteer, across four full report types plus a per-campaign summary report, complete with server-rendered SVG charts for bar, line, and donut visualizations that hold up in a board deck. An evidence-package export bundles the PDFs with supporting CSV exports and a README into a single ZIP, and a scheduled report job runs daily at 04:00 WIB so recurring reports are ready in each recipient's chosen locale without anyone requesting them manually.
What you get
23 controls across four frameworks
Control coverage is tracked against OJK POJK 11/2022, ISO 27001:2022, NIST CSF 2.0, and PDPA Indonesia, continuously scored from live campaign, training, and reporting activity.
Four full report types, plus per-campaign summaries
Generate a complete framework report or a focused summary for a single campaign, each rendered from the same underlying data so figures always reconcile.
Bilingual, Claro-branded PDF generation
Reports render server-side with Handlebars and Puppeteer into branded, bilingual PDFs, so the document you hand to an examiner looks and reads like a professional deliverable.
Board-ready SVG charts
Bar, line, donut, and KPI visualizations are rendered server-side as SVG, giving you defensible, consistent figures for a board pack rather than an inconsistent screenshot.
One-click evidence packages
Bundle generated PDFs with the underlying CSV exports and a README into a single ZIP evidence package, ready to hand to an internal or external auditor.
Scheduled report delivery
A daily scheduled job at 04:00 WIB generates and delivers recurring reports automatically, in each schedule's chosen locale, so nobody has to remember to run them.
Built for Indonesia
Built around Indonesian regulation, not retrofitted to it
Claro's control-coverage mapping starts from OJK POJK 11/2022 and BSSN guidance, then extends to ISO 27001, NIST CSF, and PDPA, rather than starting from a US or European framework and asking your compliance team to reinterpret it for local examiners. Reports render in Bahasa Indonesia and can be generated and stored entirely on-premise.
- Control coverage maps directly to OJK POJK 11/2022 and PDPA Indonesia, not just ISO or NIST
- Bilingual PDF reports, generated per schedule in the recipient's chosen locale
- Evidence packages (PDF + CSV + README) ready for OJK or internal audit review
- On-premise generation and storage for institutions that cannot let compliance evidence leave their infrastructure
Frequently asked questions
Claro tracks 23 controls across OJK POJK 11/2022, ISO 27001:2022, NIST CSF 2.0, and PDPA Indonesia, continuously scored against your actual campaign, training, and reporting activity.
Related pages
On-Premise & Data Residency
Deploy Claro entirely on your own infrastructure with per-tenant encryption, crypto-erasure, and configurable retention, no required third-party data egress.
Learn moreRisk Scoring & Analytics
A behavior-driven human risk score built from clicks, reports, and training activity, with department views, benchmarking, and board-ready exports.
Learn morePhishing Reporting
A one-click Outlook and Gmail report button that matches reported emails to simulations, rewards reporters, and routes real threats to your admins.
Learn moreSee it running on your own domain
Book a walkthrough with our team and we'll show you this capability configured for your organization's compliance requirements and language needs.
Book a walkthrough