For boards and executive teams

Board-level compliance reporting: the four questions directors ask, and the one page that answers them

Boards do not want a tour of a compliance dashboard. They want to know how exposed the company is in money, whether the audit will pass and when, which third parties could hurt the business, and what went wrong this quarter. This guide shows what to report, how often, and how to make every number defensible.
In one paragraph: a board compliance report has four blocks. Exposure: the loss range in currency from quantified risk modelling, with the top drivers. Assurance: framework and control status with audit dates and open findings. Third parties: critical vendors assessed and overdue. Incidents: what happened, how fast it was contained and which control changed as a result. Each figure should trace to a record and to hashed evidence, so a director can ask “show me” and get an answer in the same meeting.
The four blocks of a board compliance reportExposure$1.8M / $4.6MP50 / P90, sampleLoss range in currency fromMonte Carlo modelling, topfive drivers, change sincelast quarter.Assurance94%controls passing, sampleFramework status, controlhealth, audit dates, findingsopen and closed.Third parties92%assessed, sampleCritical vendors assessed,overdue reviews, concentrationrisk, contract dependencies.Incidents3 open90 days, sampleOpen incidents by severity,time to contain, lessons thatchanged a control.TraceabilityEvery figure links to the record it came from: control, risk, vendor or incident, then to the hashed evidence file and its version history.Board question → metric → record → evidence → hash. No slide is hand-typed.

The four questions, and the metric that answers each

Directors ask the same things in every industry. The trick is answering in their units, not in compliance vocabulary.

Exposure

“How exposed are we?”

Report a loss range, not a heat map. Monte Carlo modelling over your risk register gives a P50 and P90 loss figure in currency for a 12-month horizon, plus the five risks that drive most of it. Track the change quarter on quarter.

Assurance

“Will the audit pass, and when?”

Show framework coverage and control health as of today, the audit calendar, and findings open versus closed. If a Type II observation window is running, show the day count.

Third parties

“Which vendors could hurt us?”

Percentage of critical suppliers with a current assessment, overdue reviews, and where a single vendor holds customer data. Tie each critical vendor to the controls that depend on it.

Incidents

“What went wrong this quarter?”

Incidents by severity, time to detect and contain, and the control that changed because of each one. A board learns more from one fixed root cause than from a zero-incident claim.

Cadence and format

A page a quarter, a line a month, a call when it matters.
CadenceAudienceContentSource in Certifyi
MonthlyAudit / risk committee chairControl health, open findings, incidents, vendor reviews overdueReporting and audit trail module, scheduled report
QuarterlyFull boardFour-block report with exposure range and quarter-on-quarter changeBoard report template, Monte Carlo output
Before an auditExecutive teamReadiness review, scope, evidence gaps, auditor timelineAudit Management, Auditor Workspace
After a severe incidentBoard chair, counselTimeline, containment, regulatory notifications, control changeIncident Management

Making every number defensible

The difference between a slide and a report is whether a director can pull the thread.
  1. Start from the record, not the deck. Generate the report from live control, risk, vendor and incident data. Hand-typed figures drift and cannot be audited.
  2. Keep the evidence hashed and versioned. Every file is hashed on arrival and never silently deleted, so a figure quoted in March still points to the same evidence in September.
  3. Let the auditor read the same page. When the audit firm works in the Auditor Workspace, the board report and the audit opinion are built from one trail.
  4. Log who saw what. Board packs carry sensitive figures. The audit trail records access, including sign-in attempts.
  5. Report the change, not just the state. Directors act on movement: exposure down 18 percent since the vendor consolidation, two controls red for the second quarter.

Regulatory expectations that make this non-negotiable

Board accountability for cyber risk is now written into rules in several jurisdictions.

Europe

NIS 2 (EU)

Management bodies must approve cybersecurity risk-management measures and oversee their implementation, and can be held liable. Training for management is expected.

Europe

DORA (EU financial sector)

The management body bears ultimate responsibility for ICT risk, approves the ICT risk framework and reviews it at least yearly.

United States

SEC cybersecurity rules (US)

Registrants describe the board’s oversight of cybersecurity risk and management’s role in assessing and managing it in annual filings.

Global

ISO 27001 and ISO 42001

Top management must demonstrate leadership and commitment, review the management system at planned intervals and act on the results.

Board reporting, answered

A full four-block report each quarter, a one-line health summary each month to the audit or risk committee chair, and an ad hoc briefing after any severe incident or before a certification audit.

A loss-exposure range in currency with its trend. It converts control status into business language and lets directors weigh security spend against other risks.

No. Directors need coverage, health and movement. Control-level detail belongs in the committee pack and the audit record, one click away for anyone who asks.

Generate it from the compliance record and keep the evidence hashed. If a director can trace a figure to a file with a hash and a version history, the report is a record, not a claim.

Yes. The Reporting and Audit Trail module builds board and management reports from live data, and the risk register supplies the Monte Carlo exposure figures. Auditors can generate their own reports in their workspace.

See a board report built from your own record

Twenty minutes with a compliance lead. Bring your last board pack and we will show what changes.
Scroll to Top