# Board AI Risk Reporting Template and Worked Example

What you need to report AI risk to the board on a schedule: a report template, a dashboard, an escalation threshold register, and a fiscal-year calendar. The output is a quarterly report delivered on time with escalation thresholds that have been tested at least once.

**Who this is for:** The AI governance lead or chief risk officer who owns the board and audit committee reporting line for AI.

Source playbook: https://aigovernance.com/playbook/board-ai-risk-reporting

---

## Board AI risk report template

_The quarterly document. Same sections every time so directors can track movement quarter to quarter._

### Template

> Three to five pages. Same structure every quarter.

- **Executive summary:** the three things the board should take away, and any decision requested
- **Risk inventory summary:** count of AI systems by tier, change since last quarter, notable new or retired systems
- **Incident log:** AI incidents this quarter by severity, status, and lessons applied
- **Regulatory tracker:** obligations that changed or are approaching, with owner and readiness
- **Maturity scores:** current governance maturity by domain, trend, and target
- **Watchlist:** the risks not yet realised that the board should know are being watched
- **Decisions requested:** anything needing a board or committee decision this cycle

### Worked example

- **Executive summary:** AI system count is stable at 47, with two High-tier additions in hiring and fraud. One Sev-2 incident, contained, no customer impact. The EU AI Act high-risk deadline moved to December 2027 under Regulation (EU) 2026/1744, which eases near-term pressure but does not change our plan. No decision requested this quarter.
- **Risk inventory summary:** 47 systems: 3 High (up 2), 12 Limited, 32 Minimal. Retired one shadow tool found in the Q2 survey.
- **Incident log:** 1 Sev-2 (support copilot surfaced another customer's order ID in a draft reply; caught pre-send by the review step; root cause fixed). 0 Sev-1.
- **Regulatory tracker:** EU AI Act high-risk deadline now 2 December 2027; FRIA for the resume screener scheduled for October. Colorado SB205 readiness on track.
- **Maturity scores:** Overall 2.6 of 4, up from 2.4. Weakest domain is monitoring at 2.1; target 3.0 by year end.
- **Watchlist:** vendor concentration on one model provider; agent pilots in engineering not yet under the standard intake.
- **Decisions requested:** none.

### Acceptance criteria

- The section structure is identical to the previous quarter's report, so trends are visible.
- The executive summary states plainly whether a decision is requested, and if so, what.
- Every incident in the log has a status and, if closed, the change that resulted.
- Numbers reconcile with the inventory register and risk register as of a stated cut-off date.

---

## Board AI risk dashboard

_The one-screen metrics view. Current value, prior quarter, trend, the tolerance, and a status flag._

### Template

| Metric | Current | Prior quarter | Trend | Tolerance | Status |
|---|---|---|---|---|---|
| AI systems in inventory (total / High-tier) | / | / | | | |
| High-tier systems with a signed risk assessment | % | % | | 100% | |
| Overdue control or assessment reviews | | | | 0 | |
| AI incidents this quarter (Sev-1 / Sev-2) | / | / | | | |
| Mean time to contain an AI incident | | | | | |
| Governance maturity (overall, 0-4) | | | | | |
| Regulatory obligations approaching, not yet ready | | | | 0 | |
| Vendor concentration (largest provider share of High-tier) | % | % | | | |

### Worked example

| Metric | Current | Prior quarter | Trend | Tolerance | Status |
|---|---|---|---|---|---|
| AI systems (total / High) | 47 / 3 | 46 / 1 | up | n/a | OK |
| High-tier with signed assessment | 67% (2 of 3) | 100% | down | 100% | Breach: resume screener pending |
| Overdue reviews | 4 | 7 | improving | 0 | Watch |
| Incidents (Sev-1 / Sev-2) | 0 / 1 | 0 / 0 | up | n/a | Watch |
| Mean time to contain | 3h | n/a | n/a | under 8h | OK |
| Governance maturity | 2.6 | 2.4 | up | reach 3.0 by year end | On track |
| Obligations approaching, not ready | 1 | 2 | improving | 0 | Watch: FRIA |
| Vendor concentration (High-tier) | 100% | 100% | flat | under 70% | Breach: single provider |

### Acceptance criteria

- Every metric has a defined tolerance, and any breach is called out in the report's executive summary.
- Values are as of the same cut-off date as the narrative report.
- Trend is shown against the prior quarter, not just the current snapshot.

---

## Escalation threshold register

_The pre-agreed triggers that force something up to the committee or board between scheduled reports, with the clock and the owner._

### Template

| Trigger condition | Threshold | Notification window | Responsible party | Board notification path |
|---|---|---|---|---|
| AI incident severity | <Sev-1, or Sev-2 with regulatory or customer impact> | <e.g. 24h to committee chair> | <role> | <e.g. Audit Committee chair same day> |
| Risk exceeds appetite | <named metric past its tolerance> | <e.g. 5 business days> | <role> | <e.g. next committee, board if unresolved> |
| Regulatory change | <new binding obligation or moved deadline> | <e.g. 10 business days> | <role> | <e.g. committee, board summary next cycle> |
| Enforcement or inquiry | <regulator contact about our AI use> | <immediate> | <role> | <e.g. board chair and Audit Committee immediately> |
| Model or vendor failure | <High-tier system down or vendor material change> | <e.g. 48h> | <role> | <e.g. committee, board if customer impact> |

### Worked example

| Trigger | Threshold | Notification window | Responsible | Board path |
|---|---|---|---|---|
| AI incident severity | Any Sev-1; Sev-2 with customer or regulatory impact | Committee chair within 24h | AI Governance Lead | Audit Committee chair same day; full board at next meeting |
| Risk exceeds appetite | Any dashboard metric in "Breach" for two consecutive months | 5 business days | CRO | Committee next meeting; board if unresolved after one quarter |
| Regulatory change | New binding obligation, or a deadline move affecting a live plan | 10 business days | General Counsel | Committee, then board summary next cycle |
| Enforcement or inquiry | Any regulator contact about our AI use | Immediate | General Counsel | Board chair and Audit Committee chair immediately |
| Model or vendor failure | High-tier system unavailable over 4h, or vendor announces a breaking change | 48 hours | Vendor Risk Manager | Committee; board if customer impact |

### Acceptance criteria

- Every trigger has a specific threshold, not a subjective judgement call.
- Notification windows are in hours or business days and name who starts the clock.
- At least one escalation path has been tested in a tabletop in the last 12 months, with the result recorded.
- The register is referenced in the governance charter and the incident response plan.

---

## Reporting calendar

_Locks the delivery dates for the fiscal year so the report is never a scramble. Prepared-by and reviewed-by make the handoffs explicit._

### Template

| Period | Deliverable | Prepared by | Reviewed by | Delivery date | Forum |
|---|---|---|---|---|---|
| Q1 | Quarterly AI risk report | <role> | <role> | <YYYY-MM-DD> | <Audit Committee> |
| Q2 | Quarterly AI risk report | | | | |
| Q2 | Annual maturity deep-dive | | | | <Board> |
| Q3 | Quarterly AI risk report | | | | |
| Q4 | Quarterly AI risk report | | | | |
| Q4 | Next-year risk appetite review | | | | <Board> |

### Worked example

| Period | Deliverable | Prepared by | Reviewed by | Delivery date | Forum |
|---|---|---|---|---|---|
| Q1 | Quarterly AI risk report | AI Governance Lead | CRO | 2026-04-15 | Audit Committee |
| Q2 | Quarterly AI risk report | AI Governance Lead | CRO | 2026-07-15 | Audit Committee |
| Q2 | Annual maturity deep-dive | AI Governance Lead + Internal Audit | CRO, GC | 2026-07-15 | Board |
| Q3 | Quarterly AI risk report | AI Governance Lead | CRO | 2026-10-14 | Audit Committee |
| Q4 | Quarterly AI risk report | AI Governance Lead | CRO | 2027-01-14 | Audit Committee |
| Q4 | Next-year risk appetite review | CRO | Board Risk Committee | 2027-01-14 | Board |

### Acceptance criteria

- Delivery dates are set for the whole fiscal year and are on the committee's forward agenda.
- Each deliverable names a preparer and a separate reviewer.
- The calendar includes at least one annual deep-dive beyond the quarterly cycle.

---

## Governance controls this kit produces evidence for

- **HOC-007**: The report template, dashboard, and escalation register together are the board AI risk reporting and escalation-threshold mechanism.
- **BRD-006**: The dashboard tolerances and the "risk exceeds appetite" escalation trigger operationalise the documented risk appetite.
- **BRD-005**: The maturity-scores section of the report is a recurring, dated governance maturity assessment with a trend and a target.
- **BRD-004**: The report structure supplies the substance for ESG and investor disclosure on AI governance.
- **ALC-005**: The reporting calendar and the archived quarterly reports are the audit trail that reporting happened on schedule.
