A sponsored post by the Clew Research Team | Risk & Assurance
In most organisations, the board risk report is one of the most carefully prepared documents the risk function produces. It is also one of the least used. Not because boards do not care about risk, but because the reports they receive too often answer questions they are not asking.
Risk leaders invest considerable effort in their board packs. Registers are updated, heatmaps are refreshed, action logs are reconciled, and commentary is written and reviewed. The result is a document that demonstrates, with reasonable thoroughness, that risk management activity is taking place. What it does not always do is help directors understand the organisation’s actual risk position, how it has changed, where it is moving, and where the board’s own judgement or decision is required.
That gap is worth closing. Not as a cosmetic exercise in better presentation, but because the quality of governance that flows from a board risk report is directly shaped by what the report makes visible. Risk leaders who bridge that gap tend to find that their function becomes more embedded in strategic decision-making, that board conversations become sharper, and that accountability lands where it belongs rather than dissolving in the detail.
The shift required is not a methodological one. Risk functions that have invested in building solid registers, robust controls frameworks, and disciplined assurance programmes already hold the intelligence a board needs. The challenge is in the translation: converting operational rigour into strategic legibility.
Two Different Audiences, Two Different Jobs
The most important distinction in board risk reporting is one that is frequently overlooked in practice. A management risk report and a board risk report are different documents with different purposes, and trying to serve both audiences with the same pack is where most of the difficulty originates.
A management report is an operating document. It should be comprehensive, cover the full register, track actions in detail, and use operational language. Management needs that depth to run the risk programme effectively. A board report is a decision document. Its job is different: help directors understand the organisation’s strategic risk position, challenge it where necessary, and decide where their involvement is required.
Much of the content that migrates from management packs into board packs, the full register, the detailed action log, the methodology appendix, the control testing schedule, is not wrong. It is simply misplaced. Making it available on request rather than presenting it as the main event in the board pack is an act of editorial discipline that makes the report significantly easier to use. It also makes the risk function’s strategic contribution far more visible, which is no small thing for a function that is often undervalued at the executive level.
What the Board Is Actually Asking
Almost every question a board has about risk reduces to one of five. Getting clear on those five anchors is a practical way for any risk leader to audit their current report and identify where it is serving the board well and where it is not.
The first is objectives. Which strategic objectives are most at risk, and why? Risks should not sit in isolation. Each material risk needs to be connected to a named strategic objective and a stated performance consequence. A risk without an objective is a condition. Conditions can be noted. Risks connected to objectives, those that threaten something the organisation has committed to deliver, require a response. Structuring reporting this way also gives the risk function a natural language for engaging the executive team, because it speaks in the terms that the organisation is already measuring itself against.
The second is exposure. How much risk is the organisation carrying, and is it inside appetite? A static heatmap tells the board where things stand at a point in time. It does not tell them whether the position is stable, improving, or deteriorating. A risk that has been rated red for three consecutive quarters is a different conversation from an amber risk moving steadily towards red. Direction of travel matters as much as current position, and an appetite line on the chart gives the board a meaningful reference point for challenge.
The third is control confidence. How confident can the board be that the controls actually work? Grounding that confidence in evidence, whether from recent testing, independent assurance, or operational data, gives directors a stronger basis for their governance judgements than a self-assessed status. Where evidence is not yet available, saying so openly is the right approach. It surfaces a genuine gap, and demonstrating that kind of transparency is how risk functions build credibility with boards over time.
The fourth is change. What has moved since the last meeting, and what does the board now know that it did not know before? This is often the board’s primary question, and it is one that static reporting rarely answers directly. A clear delta view, showing what escalated, what improved, what new information emerged, and what actions closed or slipped, transforms the report from a periodic snapshot into a live read of the organisation’s risk position.
The fifth is action. What is management doing, and where must the board decide? The clearest improvement most board risk reports can make is in distinguishing between actions that management owns and is progressing, and decisions that require the board to make a call. Board-level items should carry a named owner, a committed date, and a specific question or direction sought. That clarity is not bureaucratic; it is the mechanism through which a board actually governs.
The Opening Page Sets Everything That Follows
Directors form their view of a board risk report on the first page. If that page is directional and decision-focused, the conversation that follows tends to match. If it reads as a compressed version of the full register, the board approaches everything else as a compliance exercise rather than a governance one.
A useful test: if a director reads only the opening page, can they tell, in sixty seconds, what matters most right now, what has changed since the last meeting, and where they are being asked to challenge or decide? If the answer to any of those questions is no, the page is not doing its job.
The opening page that works is not long. A clear position statement, a small number of decision-relevant indicators, and an explicit account of what the board is being asked to do: that is the architecture. Writing it first, before the rest of the pack is assembled, is a discipline worth developing. It forces the judgement call that the board needs to see, rather than deferring it to a narrative that spreads across many pages. Everything that follows the opening page is evidence in support of the position it states.
Making the Connection Visible
One of the most valuable things a board risk report can do is make the connection between strategic objectives and risk management activity traceable in a single document. Boards that can follow a material risk back to the objective it threatens, and forward through to the controls, assurance activity, and actions being applied, are boards that can govern with genuine confidence. Those that cannot are left to note the risk and move on.
This traceable link, sometimes described as a golden thread through the governance framework, is a functional governance tool rather than a presentational device. It enables board challenge that is grounded in evidence, and it demonstrates the integrity of the risk and assurance programme in a way that isolated reporting never can. Each material risk in the board pack should come with a named objective, a stated performance consequence, the controls being relied upon, the evidence base for confidence in those controls, and the current action on any identified gap. Applied consistently, that structure changes the nature of the board conversation.
What to Move, What to Keep
Improving the board risk report is as much about subtraction as addition. Most board packs have accumulated content over years, some added for good reasons that no longer apply, some carried forward because no one has reviewed whether it still belongs. Every page that competes for attention with the material the board actually needs makes the report harder to navigate.
Content that tends to work better in appendices or management packs than in the main board report includes the full risk register, detailed action logs, methodology notes, compliance calendars, training metrics, static heatmaps without a trend or appetite overlay, and long policy update summaries. Moving these into a clearly labelled appendix preserves full transparency while ensuring that the pages in front of the board are the ones that carry the strategic judgements they are there to make.
Starting With the Next Report
Improving the board risk report does not require a lengthy change programme. Risk leaders can make meaningful improvements within a single reporting cycle, starting with a conversation with the committee chair about what the board needs to be able to do after reading it. That conversation alone tends to surface useful clarity.
From there, mapping current content against the five anchors, rewriting the opening page, repositioning supporting material, and adding a clear delta view are changes that can be made incrementally. Testing a revised draft with one executive and one non-executive director before it reaches the full board is worth the time. Listening carefully to which pages generated discussion after each meeting, and which ones were not referenced, provides the feedback loop that makes each subsequent cycle better than the last.
The risk function holds some of the most consequential intelligence in any organisation. It understands where strategic objectives are under pressure, where controls are holding and where they are not, and where exposure is moving relative to what the board has approved. The board report is the primary channel through which that intelligence reaches the people responsible for governance. Investing in that channel is not a communications exercise. It is a governance one.
These ideas are explored in more depth in the related paper, Reporting Risk to the Board: What Directors Actually Need to See, which sets out the full five-anchor framework with detailed examples for risk leaders looking to apply it in practice.
The purpose of board risk reporting is not to prove that risk management activity is taking place. It is to help directors see the organisation’s position clearly enough to challenge it, govern it, and act before the signal is lost in the pack.
This article draws on practitioner research and framework development by the team at Clew, a risk and assurance platform working with organisations across multiple sectors to connect strategic objectives, risk, controls, assurance, and performance.
This website uses cookies to ensure you get the best experience on our website.
Read our Privacy Statement & Cookie Policy