For boards and executive teams
Board-level compliance reporting: the four questions directors ask, and the one page that answers them
The four questions, and the metric that answers each
Exposure
“How exposed are we?”
Assurance
“Will the audit pass, and when?”
Third parties
“Which vendors could hurt us?”
Incidents
“What went wrong this quarter?”
Cadence and format
| Cadence | Audience | Content | Source in Certifyi |
|---|---|---|---|
| Monthly | Audit / risk committee chair | Control health, open findings, incidents, vendor reviews overdue | Reporting and audit trail module, scheduled report |
| Quarterly | Full board | Four-block report with exposure range and quarter-on-quarter change | Board report template, Monte Carlo output |
| Before an audit | Executive team | Readiness review, scope, evidence gaps, auditor timeline | Audit Management, Auditor Workspace |
| After a severe incident | Board chair, counsel | Timeline, containment, regulatory notifications, control change | Incident Management |
Making every number defensible
- Start from the record, not the deck. Generate the report from live control, risk, vendor and incident data. Hand-typed figures drift and cannot be audited.
- Keep the evidence hashed and versioned. Every file is hashed on arrival and never silently deleted, so a figure quoted in March still points to the same evidence in September.
- Let the auditor read the same page. When the audit firm works in the Auditor Workspace, the board report and the audit opinion are built from one trail.
- Log who saw what. Board packs carry sensitive figures. The audit trail records access, including sign-in attempts.
- Report the change, not just the state. Directors act on movement: exposure down 18 percent since the vendor consolidation, two controls red for the second quarter.
Regulatory expectations that make this non-negotiable
Europe
NIS 2 (EU)
Europe
DORA (EU financial sector)
United States
SEC cybersecurity rules (US)
Global
ISO 27001 and ISO 42001
Board reporting, answered
How often should the board see a compliance report?
A full four-block report each quarter, a one-line health summary each month to the audit or risk committee chair, and an ad hoc briefing after any severe incident or before a certification audit.
What is the single most useful metric for a board?
A loss-exposure range in currency with its trend. It converts control status into business language and lets directors weigh security spend against other risks.
Should the board see control-level detail?
No. Directors need coverage, health and movement. Control-level detail belongs in the committee pack and the audit record, one click away for anyone who asks.
How do we avoid the report being marketing?
Generate it from the compliance record and keep the evidence hashed. If a director can trace a figure to a file with a hash and a version history, the report is a record, not a claim.
Does Certifyi produce this report?
Yes. The Reporting and Audit Trail module builds board and management reports from live data, and the risk register supplies the Monte Carlo exposure figures. Auditors can generate their own reports in their workspace.