You can create a compliance report that looks for the line vty configs.
Config block begin: ^line vty
Config block end: ^!
RegEx is not present: transport input ssh
If the 'transport input ssh' is not there, it is assumed it is transport input all or transport input telnet, or blank. This would mean telnet would be authorized inbound. You can also alert if the following are not found:
ip ssh version 2
ip ssh source-interface
ip ssh time-out
Hope that helps. Let me know if you have more questions!