What Should Risk Reporting to the Board Contain?
Four pages of risk, and nothing the board can act on.
The pack is thorough. The register is attached, the top ten are listed, the grid is colored, the mitigation status is updated. The board reads it, has no questions, and moves to the next item. That is not a board that is disengaged. It is a report that contains no decision.
Published
Key Takeaways
- Most risk reporting shows position and boards act on movement. The register, the top ten and the grid all describe a state, and a state that looks like last quarter's generates no decision even when something material has changed underneath it.
- Three kinds of risk need three formats. Preventable risks belong in exception reporting, strategy risks require discussion, and external risks require scenarios. Compressing all three into one status format is what makes packs simultaneously long and empty.
- On a capital program the contingency drawdown curve against plan is the strongest early signal available and it is almost never in the pack. It moves before the forecast does, because contingency is consumed before anyone concedes the estimate was wrong.
Research foundation
The three-category argument is Kaplan and Mikes (2012) in Harvard Business Review, extended in Mikes and Kaplan (2015) in the Journal of Applied Corporate Finance. The critique of grid-based reporting rests on Cox (2008) and Hubbard and Evans (2010). Escalation obligations draw on Marchand v. Barnhill (Del. 2019). Reporting content is anchored in GAO-20-195G. One limit is stated: no peer-reviewed study establishes an optimal board risk reporting format. The Four A's are the executive lens applied on top.
Ask a director what they learned from the last risk report and the answer is usually a version of the same thing: that the risks are being managed. That is a statement about the process, not about the program, and it is the only statement most risk packs are capable of producing.
The structural reason is that the pack was designed to demonstrate that risk management is occurring. It succeeds at that. A board does not need to be persuaded that risk management is occurring. It needs to know what changed and what it should do.
Why the standard pack fails
It reports level, not movement
A register is a state. A top ten list is a state. A colored grid is a state. Present the same state twice and the second presentation carries no information, which is why boards stop engaging with risk packs after about the third one.
What a governing body can act on is change: this moved, this is new, this closed, this is now worse than we told you last time. Everything else is context, and context belongs in an appendix that nobody has to read.
The grid does not measure what it appears to measure
There is a technical problem underneath the presentational one. Cox showed formally that risk matrices can assign a higher qualitative rating to a quantitatively smaller risk, and that under some configurations the resulting ratings correspond poorly to the underlying quantities. Hubbard and Evans established the more basic issue: the scores being plotted come from ordinal scales, and the arithmetic used to combine them into a position is not an operation those scales support.
So the position of a dot on the grid is not a measurement of exposure. It is a rendering of a judgment that has been through an invalid transformation. That does not make the underlying judgment worthless, and the narrower reading of what Cox actually proved is worth understanding before abandoning the format entirely. It does mean the grid should not be the thing a board looks at first.
One format is used for three different kinds of risk
This is the deepest of the three problems and the least noticed.
Kaplan and Mikes made the case that risks fall into three categories requiring different control processes. Preventable risks are internal, controllable, and carry no strategic benefit: fraud, safety breaches, process failures. These belong in rules-based, exception-only reporting, and a board should hear about them when something has gone wrong rather than monthly.
Strategy risks are taken deliberately in exchange for a return. They cannot be eliminated without eliminating the return, and reporting them as a status indicator destroys the only thing that makes them manageable, which is discussion of whether the return is still worth the exposure.
External risks are beyond the organization's influence entirely. They are addressed through stress testing and scenario work, not through mitigation plans, and a mitigation column against an external risk is theater.
Forcing a strategy risk into a compliance format converts a conversation the board needs into a green indicator. That single substitution explains most of what is wrong with most risk packs.
The five things that belong in the pack
What moved, and why
A short list of changes since the last report. New entries, closed entries, entries whose exposure changed materially, and one sentence of cause for each. This is the section a board will actually read and it should be first.
The current confidence level, and whether it changed
The budget and the schedule each sit at some probability of not being exceeded. State it. If it has moved since the last report, that is the most important sentence in the pack, because it means the same approved number now represents a different promise than the one the board approved.
A board that approved a budget at the 65th percentile and is now, without anyone saying so, holding a budget at the 45th, has had its risk appetite changed without a decision. That should be impossible to miss and in most reporting it is invisible.
Contingency drawdown against plan
This is the item most often absent and it is the strongest early signal a capital program produces.
Contingency should be consumed roughly in proportion to how much uncertainty has been resolved. Plot planned drawdown against actual and the divergence appears well before anyone concedes the estimate is wrong, because contingency is spent quietly by the people doing the work while the forecast is defended in meetings. A program that has consumed sixty percent of its contingency at thirty percent completion has already told you the answer, and it has told you in a single line on a chart that requires no interpretation.
A useful property of this measure is that it is difficult to present optimistically. Either the money is gone or it is not.
What has become irreversible
Boards act on options, and options close. A short statement of what can no longer be changed since the last meeting, and what will close before the next one, tells a governing body where its remaining leverage is. Almost nobody reports this and it is frequently the most decision-relevant page in the pack.
What the board is being asked to decide
With the risk consequence of each option. If the honest answer is that no decision is required, say so in a sentence and move on. A risk section with no decision in it should be short, and its shortness is informative rather than negligent.
Cadence and the trigger
A calendar cadence alone is not a reporting system, and this is where the governance exposure sits.
If the only route to the board is the scheduled report, then a material change discovered the week after a meeting waits for the next one. The Delaware oversight cases turned substantially on this: not that nobody knew, but that no obligation existed to tell the board between scheduled reports. The remedy is cheap and specific. Agree the triggers in advance, in writing, and treat crossing one as an obligation rather than a judgment call.
Workable triggers on a capital program: drawdown exceeding the planned curve by a stated margin, a bid outside the modelled range, float consumption past a threshold, a scope change above a value, and any event that moves the confidence level of the approved budget.
What to take out
- The full register. Attach it if governance requires; do not present it.
- Any risk that has not changed and requires no decision.
- Counts of mitigation activities. Activity is not exposure reduction, and reporting it invites the board to mistake motion for progress.
- Status indicators without a stated basis. A green light with no threshold behind it is an opinion formatted as a measurement.
One honest limitation before anyone rebuilds a template on this. No peer-reviewed study establishes an optimal board risk reporting format, and the annual practice surveys describe what organizations do rather than what works. The items above are defensible on the reasoning given and on field experience, and they should be treated as such rather than as validated design.
Evidence matrix
| Claim | Evidence tier | Source |
|---|---|---|
| Preventable, strategy and external risks require different control and reporting processes | Practitioner journal, peer edited | Kaplan & Mikes (2012), HBR 90(6) |
| Enterprise risk practice is contingent on context rather than uniform | Peer reviewed | Mikes & Kaplan (2015), JACF 27(1) |
| Matrices can rate a quantitatively smaller risk higher than a larger one | Peer reviewed | Cox (2008), Risk Analysis 28(2) |
| The scores plotted on a grid do not support the arithmetic used to place them | Peer reviewed | Hubbard & Evans (2010), IBM J. Res. Dev. 54(3) |
| Absence of an escalation obligation between scheduled reports is itself an oversight failure | Primary legal source | Marchand v. Barnhill, 212 A.3d 805 (Del. 2019) |
| An optimal board risk reporting format has been established | Not established | No peer-reviewed study located; surveys describe practice only |
| Drawdown against plan moves before the forecast does | Named field experience | Capital program practice, Mission Intelligence Systems |
What to do with this
Take the last risk pack and mark every sentence that could have changed a decision. On most packs the marked portion is under a tenth of the page count, and it is not the portion that took the longest to prepare.
Then rebuild it as one page in the five sections above, keep the register as an appendix, and add the drawdown chart. The preparation effort goes down. What the board can do with it goes up, and the first meeting where a director asks a question about the drawdown line is the moment the reporting starts working.
References
- Kaplan, Robert S., and Anette Mikes. “Managing Risks: A New Framework.” Harvard Business Review, vol. 90, no. 6, June 2012, pp. 48–60. Reprint R1206B. hbr.org. Preventable, strategy and external risk categories.
- Mikes, Anette, and Robert S. Kaplan. “When One Size Doesn't Fit All: Evolving Directions in the Research and Practice of Enterprise Risk Management.” Journal of Applied Corporate Finance, vol. 27, no. 1, 2015, pp. 37–40. doi.org/10.1111/jacf.12102.
- Cox, Louis Anthony, Jr. “What's Wrong with Risk Matrices?” Risk Analysis, vol. 28, no. 2, 2008, pp. 497–512. doi.org/10.1111/j.1539-6924.2008.01030.x.
- Hubbard, Douglas W., and Dylan Evans. “Problems with Scoring Methods and Ordinal Scales in Risk Assessment.” IBM Journal of Research and Development, vol. 54, no. 3, 2010, pp. 2:1–2:10. doi.org/10.1147/JRD.2010.2042914.
- Marchand v. Barnhill, 212 A.3d 805 (Del. 2019). law.justia.com. Absence of a board-level reporting and escalation process for a mission critical risk.
- NC State University Enterprise Risk Management Initiative and Protiviti. Executive Perspectives on Top Risks 2026. 14th annual survey, December 2025, n = 1,540. erm.ncsu.edu.
- U.S. Government Accountability Office. Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs. GAO-20-195G, March 2020. gao.gov/products/gao-20-195g. Contingency management and reporting.
- Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management: Integrating with Strategy and Performance. COSO, 2017. coso.org/guidance-erm.
- International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018, clause 6.6 on monitoring and review and clause 6.7 on recording and reporting. iso.org/standard/65694.html.
About the Author
Dan Flynn
Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build
Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.
His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.
