Primary workflowTemplateIntermediatePlanning aid

Patch compliance Prove the Number monthly evidence pack

A ready-to-fill monthly record that turns patch-compliance methodology into a defensible reporting package: population reconciliation, denominator rules, unknown/stale systems, exclusions, applicability, evidence coverage, exceptions, signoff, and management summary.

Good For

  • monthly Windows patch reporting

  • proving a compliance percentage

  • audit and management evidence

  • SCCM/Arc/AD population reconciliation

  • preventing unknown systems from disappearing

How to Use It

  1. Record reporting month, baseline date, update source, report owner, technical approver, and management audience.

  2. Reconcile counts from each authoritative discovery/inventory source, matched systems, source-only systems, duplicates, decommission candidates, and unresolved ownership.

  3. State exactly which systems belong in the denominator and why; unknown, unreachable, stale, or missing-evidence systems must remain visible rather than silently disappearing.

  4. List every exclusion with owner, reason, approval, start date, expiry/review date, and whether it remains in the denominator or is reported as an exception.

  5. Record OS/build families, required monthly baseline, Build + UBR or other evidence rule, and unsupported/out-of-scope classification.

  6. Count systems with current proof, stale proof, no proof, conflicting proof, and collection failures.

  7. Record compliant, noncompliant, exception, unknown, total denominator, and the exact formula behind the headline percentage.

  8. Reconcile the denominator back to population evidence and explain every delta; the percentage is not publishable until the denominator can be reproduced.

  9. Management summary: state percentage, denominator, unknown/unproven count, major exclusions, material risks, and change from last month.

  10. Completed example: 1,000 expected systems; 960 current compliant; 20 current noncompliant; 10 approved exceptions; 10 unknown/unreachable. Report 960 of the defined 1,000 population as 96.0% and call out the 10 unknowns rather than reporting 960/980 as 98.0%.

Execution Modes

  • local

Inputs and Outputs

Inputs

  • inventory/discovery source counts
  • patch evidence source
  • monthly baseline
  • exception approvals
  • unknown/stale system list
  • prior-month report

Outputs

  • operator-notes
  • csv
  • future-html-report

Validation

  • Population reconciles from source counts to final denominator.

  • Unknown, stale, unreachable, and conflicting systems are visible.

  • Every exclusion has owner, reason, approval, and review/expiry point.

  • The percentage can be recalculated from recorded counts and formula.

  • The management summary includes denominator confidence and unknown-system count.

Reporting

  • Use this as the monthly evidence record attached to patch reporting or a change/review package.

  • Keep the one-paragraph management summary with the technical reconciliation.

  • Retain prior months so denominator drift and recurring unknown systems are visible.

Safety Notes

  • Do not improve the percentage by silently removing systems that lack evidence.

  • Do not treat inventory absence, stale scan data, or collection failure as compliance.

  • Document denominator and exclusion rules before comparing month-over-month percentages.

Keep Moving

Take the workflow further

Use the related Learn guide, practice the workflow in a Lab, or choose another Tool.