AI Governance Institute
All governance templates →How do we report AI risk to the board and audit committee?

Implementation Kit

Board AI Risk Reporting Template and Worked Example

What you need to report AI risk to the board on a schedule: a report template, a dashboard, an escalation threshold register, and a fiscal-year calendar. The output is a quarterly report delivered on time with escalation thresholds that have been tested at least once.

Who this is for: The AI governance lead or chief risk officer who owns the board and audit committee reporting line for AI.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. Board AI risk report template

Document

The quarterly document. Same sections every time so directors can track movement quarter to quarter.

Template

Three to five pages. Same structure every quarter.

  • Executive summary: the three things the board should take away, and any decision requested
  • Risk inventory summary: count of AI systems by tier, change since last quarter, notable new or retired systems
  • Incident log: AI incidents this quarter by severity, status, and lessons applied
  • Regulatory tracker: obligations that changed or are approaching, with owner and readiness
  • Maturity scores: current governance maturity by domain, trend, and target
  • Watchlist: the risks not yet realised that the board should know are being watched
  • Decisions requested: anything needing a board or committee decision this cycle

Worked example

  • Executive summary: AI system count is stable at 47, with two High-tier additions in hiring and fraud. One Sev-2 incident, contained, no customer impact. The EU AI Act high-risk deadline moved to December 2027 under Regulation (EU) 2026/1744, which eases near-term pressure but does not change our plan. No decision requested this quarter.
  • Risk inventory summary: 47 systems: 3 High (up 2), 12 Limited, 32 Minimal. Retired one shadow tool found in the Q2 survey.
  • Incident log: 1 Sev-2 (support copilot surfaced another customer's order ID in a draft reply; caught pre-send by the review step; root cause fixed). 0 Sev-1.
  • Regulatory tracker: EU AI Act high-risk deadline now 2 December 2027; FRIA for the resume screener scheduled for October. Colorado SB205 readiness on track.
  • Maturity scores: Overall 2.6 of 4, up from 2.4. Weakest domain is monitoring at 2.1; target 3.0 by year end.
  • Watchlist: vendor concentration on one model provider; agent pilots in engineering not yet under the standard intake.
  • Decisions requested: none.

Acceptance criteria

  • The section structure is identical to the previous quarter's report, so trends are visible.
  • The executive summary states plainly whether a decision is requested, and if so, what.
  • Every incident in the log has a status and, if closed, the change that resulted.
  • Numbers reconcile with the inventory register and risk register as of a stated cut-off date.

2. Board AI risk dashboard

Spreadsheet

The one-screen metrics view. Current value, prior quarter, trend, the tolerance, and a status flag.

Template

MetricCurrentPrior quarterTrendToleranceStatus
AI systems in inventory (total / High-tier)//
High-tier systems with a signed risk assessment%%100%
Overdue control or assessment reviews0
AI incidents this quarter (Sev-1 / Sev-2)//
Mean time to contain an AI incident
Governance maturity (overall, 0-4)
Regulatory obligations approaching, not yet ready0
Vendor concentration (largest provider share of High-tier)%%

Worked example

MetricCurrentPrior quarterTrendToleranceStatus
AI systems (total / High)47 / 346 / 1upn/aOK
High-tier with signed assessment67% (2 of 3)100%down100%Breach: resume screener pending
Overdue reviews47improving0Watch
Incidents (Sev-1 / Sev-2)0 / 10 / 0upn/aWatch
Mean time to contain3hn/an/aunder 8hOK
Governance maturity2.62.4upreach 3.0 by year endOn track
Obligations approaching, not ready12improving0Watch: FRIA
Vendor concentration (High-tier)100%100%flatunder 70%Breach: single provider

Acceptance criteria

  • Every metric has a defined tolerance, and any breach is called out in the report's executive summary.
  • Values are as of the same cut-off date as the narrative report.
  • Trend is shown against the prior quarter, not just the current snapshot.

3. Escalation threshold register

Spreadsheet

The pre-agreed triggers that force something up to the committee or board between scheduled reports, with the clock and the owner.

Template

Trigger conditionThresholdNotification windowResponsible partyBoard notification path
AI incident severity<Sev-1, or Sev-2 with regulatory or customer impact><e.g. 24h to committee chair><role><e.g. Audit Committee chair same day>
Risk exceeds appetite<named metric past its tolerance><e.g. 5 business days><role><e.g. next committee, board if unresolved>
Regulatory change<new binding obligation or moved deadline><e.g. 10 business days><role><e.g. committee, board summary next cycle>
Enforcement or inquiry<regulator contact about our AI use><immediate><role><e.g. board chair and Audit Committee immediately>
Model or vendor failure<High-tier system down or vendor material change><e.g. 48h><role><e.g. committee, board if customer impact>

Worked example

TriggerThresholdNotification windowResponsibleBoard path
AI incident severityAny Sev-1; Sev-2 with customer or regulatory impactCommittee chair within 24hAI Governance LeadAudit Committee chair same day; full board at next meeting
Risk exceeds appetiteAny dashboard metric in "Breach" for two consecutive months5 business daysCROCommittee next meeting; board if unresolved after one quarter
Regulatory changeNew binding obligation, or a deadline move affecting a live plan10 business daysGeneral CounselCommittee, then board summary next cycle
Enforcement or inquiryAny regulator contact about our AI useImmediateGeneral CounselBoard chair and Audit Committee chair immediately
Model or vendor failureHigh-tier system unavailable over 4h, or vendor announces a breaking change48 hoursVendor Risk ManagerCommittee; board if customer impact

Acceptance criteria

  • Every trigger has a specific threshold, not a subjective judgement call.
  • Notification windows are in hours or business days and name who starts the clock.
  • At least one escalation path has been tested in a tabletop in the last 12 months, with the result recorded.
  • The register is referenced in the governance charter and the incident response plan.

4. Reporting calendar

Spreadsheet

Locks the delivery dates for the fiscal year so the report is never a scramble. Prepared-by and reviewed-by make the handoffs explicit.

Template

PeriodDeliverablePrepared byReviewed byDelivery dateForum
Q1Quarterly AI risk report<role><role><YYYY-MM-DD><Audit Committee>
Q2Quarterly AI risk report
Q2Annual maturity deep-dive<Board>
Q3Quarterly AI risk report
Q4Quarterly AI risk report
Q4Next-year risk appetite review<Board>

Worked example

PeriodDeliverablePrepared byReviewed byDelivery dateForum
Q1Quarterly AI risk reportAI Governance LeadCRO2026-04-15Audit Committee
Q2Quarterly AI risk reportAI Governance LeadCRO2026-07-15Audit Committee
Q2Annual maturity deep-diveAI Governance Lead + Internal AuditCRO, GC2026-07-15Board
Q3Quarterly AI risk reportAI Governance LeadCRO2026-10-14Audit Committee
Q4Quarterly AI risk reportAI Governance LeadCRO2027-01-14Audit Committee
Q4Next-year risk appetite reviewCROBoard Risk Committee2027-01-14Board

Acceptance criteria

  • Delivery dates are set for the whole fiscal year and are on the committee's forward agenda.
  • Each deliverable names a preparer and a separate reviewer.
  • The calendar includes at least one annual deep-dive beyond the quarterly cycle.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

HOC-007
HOC-007

The report template, dashboard, and escalation register together are the board AI risk reporting and escalation-threshold mechanism.

BRD-006
BRD-006

The dashboard tolerances and the "risk exceeds appetite" escalation trigger operationalise the documented risk appetite.

BRD-005
BRD-005

The maturity-scores section of the report is a recurring, dated governance maturity assessment with a trend and a target.

BRD-004
BRD-004

The report structure supplies the substance for ESG and investor disclosure on AI governance.

ALC-005
ALC-005

The reporting calendar and the archived quarterly reports are the audit trail that reporting happened on schedule.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →