Implementation Kit
Board AI Risk Reporting Template and Worked Example
What you need to report AI risk to the board on a schedule: a report template, a dashboard, an escalation threshold register, and a fiscal-year calendar. The output is a quarterly report delivered on time with escalation thresholds that have been tested at least once.
Who this is for: The AI governance lead or chief risk officer who owns the board and audit committee reporting line for AI.
1. Board AI risk report template
DocumentThe quarterly document. Same sections every time so directors can track movement quarter to quarter.
Template
Three to five pages. Same structure every quarter.
- Executive summary: the three things the board should take away, and any decision requested
- Risk inventory summary: count of AI systems by tier, change since last quarter, notable new or retired systems
- Incident log: AI incidents this quarter by severity, status, and lessons applied
- Regulatory tracker: obligations that changed or are approaching, with owner and readiness
- Maturity scores: current governance maturity by domain, trend, and target
- Watchlist: the risks not yet realised that the board should know are being watched
- Decisions requested: anything needing a board or committee decision this cycle
Worked example
- Executive summary: AI system count is stable at 47, with two High-tier additions in hiring and fraud. One Sev-2 incident, contained, no customer impact. The EU AI Act high-risk deadline moved to December 2027 under Regulation (EU) 2026/1744, which eases near-term pressure but does not change our plan. No decision requested this quarter.
- Risk inventory summary: 47 systems: 3 High (up 2), 12 Limited, 32 Minimal. Retired one shadow tool found in the Q2 survey.
- Incident log: 1 Sev-2 (support copilot surfaced another customer's order ID in a draft reply; caught pre-send by the review step; root cause fixed). 0 Sev-1.
- Regulatory tracker: EU AI Act high-risk deadline now 2 December 2027; FRIA for the resume screener scheduled for October. Colorado SB205 readiness on track.
- Maturity scores: Overall 2.6 of 4, up from 2.4. Weakest domain is monitoring at 2.1; target 3.0 by year end.
- Watchlist: vendor concentration on one model provider; agent pilots in engineering not yet under the standard intake.
- Decisions requested: none.
Acceptance criteria
- ✓The section structure is identical to the previous quarter's report, so trends are visible.
- ✓The executive summary states plainly whether a decision is requested, and if so, what.
- ✓Every incident in the log has a status and, if closed, the change that resulted.
- ✓Numbers reconcile with the inventory register and risk register as of a stated cut-off date.
2. Board AI risk dashboard
SpreadsheetThe one-screen metrics view. Current value, prior quarter, trend, the tolerance, and a status flag.
Template
| Metric | Current | Prior quarter | Trend | Tolerance | Status |
|---|---|---|---|---|---|
| AI systems in inventory (total / High-tier) | / | / | |||
| High-tier systems with a signed risk assessment | % | % | 100% | ||
| Overdue control or assessment reviews | 0 | ||||
| AI incidents this quarter (Sev-1 / Sev-2) | / | / | |||
| Mean time to contain an AI incident | |||||
| Governance maturity (overall, 0-4) | |||||
| Regulatory obligations approaching, not yet ready | 0 | ||||
| Vendor concentration (largest provider share of High-tier) | % | % |
Worked example
| Metric | Current | Prior quarter | Trend | Tolerance | Status |
|---|---|---|---|---|---|
| AI systems (total / High) | 47 / 3 | 46 / 1 | up | n/a | OK |
| High-tier with signed assessment | 67% (2 of 3) | 100% | down | 100% | Breach: resume screener pending |
| Overdue reviews | 4 | 7 | improving | 0 | Watch |
| Incidents (Sev-1 / Sev-2) | 0 / 1 | 0 / 0 | up | n/a | Watch |
| Mean time to contain | 3h | n/a | n/a | under 8h | OK |
| Governance maturity | 2.6 | 2.4 | up | reach 3.0 by year end | On track |
| Obligations approaching, not ready | 1 | 2 | improving | 0 | Watch: FRIA |
| Vendor concentration (High-tier) | 100% | 100% | flat | under 70% | Breach: single provider |
Acceptance criteria
- ✓Every metric has a defined tolerance, and any breach is called out in the report's executive summary.
- ✓Values are as of the same cut-off date as the narrative report.
- ✓Trend is shown against the prior quarter, not just the current snapshot.
3. Escalation threshold register
SpreadsheetThe pre-agreed triggers that force something up to the committee or board between scheduled reports, with the clock and the owner.
Template
| Trigger condition | Threshold | Notification window | Responsible party | Board notification path |
|---|---|---|---|---|
| AI incident severity | <Sev-1, or Sev-2 with regulatory or customer impact> | <e.g. 24h to committee chair> | <role> | <e.g. Audit Committee chair same day> |
| Risk exceeds appetite | <named metric past its tolerance> | <e.g. 5 business days> | <role> | <e.g. next committee, board if unresolved> |
| Regulatory change | <new binding obligation or moved deadline> | <e.g. 10 business days> | <role> | <e.g. committee, board summary next cycle> |
| Enforcement or inquiry | <regulator contact about our AI use> | <immediate> | <role> | <e.g. board chair and Audit Committee immediately> |
| Model or vendor failure | <High-tier system down or vendor material change> | <e.g. 48h> | <role> | <e.g. committee, board if customer impact> |
Worked example
| Trigger | Threshold | Notification window | Responsible | Board path |
|---|---|---|---|---|
| AI incident severity | Any Sev-1; Sev-2 with customer or regulatory impact | Committee chair within 24h | AI Governance Lead | Audit Committee chair same day; full board at next meeting |
| Risk exceeds appetite | Any dashboard metric in "Breach" for two consecutive months | 5 business days | CRO | Committee next meeting; board if unresolved after one quarter |
| Regulatory change | New binding obligation, or a deadline move affecting a live plan | 10 business days | General Counsel | Committee, then board summary next cycle |
| Enforcement or inquiry | Any regulator contact about our AI use | Immediate | General Counsel | Board chair and Audit Committee chair immediately |
| Model or vendor failure | High-tier system unavailable over 4h, or vendor announces a breaking change | 48 hours | Vendor Risk Manager | Committee; board if customer impact |
Acceptance criteria
- ✓Every trigger has a specific threshold, not a subjective judgement call.
- ✓Notification windows are in hours or business days and name who starts the clock.
- ✓At least one escalation path has been tested in a tabletop in the last 12 months, with the result recorded.
- ✓The register is referenced in the governance charter and the incident response plan.
4. Reporting calendar
SpreadsheetLocks the delivery dates for the fiscal year so the report is never a scramble. Prepared-by and reviewed-by make the handoffs explicit.
Template
| Period | Deliverable | Prepared by | Reviewed by | Delivery date | Forum |
|---|---|---|---|---|---|
| Q1 | Quarterly AI risk report | <role> | <role> | <YYYY-MM-DD> | <Audit Committee> |
| Q2 | Quarterly AI risk report | ||||
| Q2 | Annual maturity deep-dive | <Board> | |||
| Q3 | Quarterly AI risk report | ||||
| Q4 | Quarterly AI risk report | ||||
| Q4 | Next-year risk appetite review | <Board> |
Worked example
| Period | Deliverable | Prepared by | Reviewed by | Delivery date | Forum |
|---|---|---|---|---|---|
| Q1 | Quarterly AI risk report | AI Governance Lead | CRO | 2026-04-15 | Audit Committee |
| Q2 | Quarterly AI risk report | AI Governance Lead | CRO | 2026-07-15 | Audit Committee |
| Q2 | Annual maturity deep-dive | AI Governance Lead + Internal Audit | CRO, GC | 2026-07-15 | Board |
| Q3 | Quarterly AI risk report | AI Governance Lead | CRO | 2026-10-14 | Audit Committee |
| Q4 | Quarterly AI risk report | AI Governance Lead | CRO | 2027-01-14 | Audit Committee |
| Q4 | Next-year risk appetite review | CRO | Board Risk Committee | 2027-01-14 | Board |
Acceptance criteria
- ✓Delivery dates are set for the whole fiscal year and are on the committee's forward agenda.
- ✓Each deliverable names a preparer and a separate reviewer.
- ✓The calendar includes at least one annual deep-dive beyond the quarterly cycle.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The report template, dashboard, and escalation register together are the board AI risk reporting and escalation-threshold mechanism.
The dashboard tolerances and the "risk exceeds appetite" escalation trigger operationalise the documented risk appetite.
The maturity-scores section of the report is a recurring, dated governance maturity assessment with a trend and a target.
The report structure supplies the substance for ESG and investor disclosure on AI governance.
The reporting calendar and the archived quarterly reports are the audit trail that reporting happened on schedule.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →