Reporting to the Board Without Overclaiming
What an executive audience needs, what will not survive a question, and the position to take on the thing they will ask.
Governance · Procedure
This subject arrives at board level with urgency attached and a great deal of circulating material. The reporting that holds up is narrower than what is expected.
The recommendations in “Reporting to the Board Without Overclaiming” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating the practical overview can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.
For an independent benchmark, compare the local approach with NIST AI RMF Playbook; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
What they need
What is actually in use here, counted.
What the real exposure is, described concretely.
What has been done, and what remains.
What decision you need from them, if any.
One page.
What will not survive a question
Industry percentages about shadow AI adoption, which the sizing note explains are unsourceable.
Claims that use has been eliminated.
A risk rating with no method behind it.
And any productivity figure from a vendor, which is the one most likely to be in the pack and the one an informed director will question.
The question they will ask
"Are we exposed?"
The honest answer is a description rather than a yes or no: these tools are in use, this is what we found going to them, these controls are in place, this is what we accept.
An unqualified reassurance is the answer most likely to be wrong in public later.
Framing it as capability, not only risk
Boards increasingly ask why the organisation is not using these tools more, as well as whether it is exposed.
A report that is only about risk invites the second question unanswered.
Say what is being enabled and what it is for, which also makes the restrictive parts more credible.
The accepted risks
State what you are not controlling and why: personal devices, embedded features in approved tools, use you cannot see.
This is uncomfortable and it is the part that protects you, because an incident in a documented accepted-risk area is a different conversation from a surprise.
Cadence
Once on establishing the programme, then annually or on material change.
More frequently is a sign the subject has become a standing anxiety rather than a managed area.
What to ask them for
A decision on budget for approved tooling, if that is the constraint.
A sponsor, if ownership is contested.
And a position on risk appetite for the categories you cannot fully control, which is genuinely their decision rather than yours.
What to check
Does your board material contain a figure you cannot source?
Is the accepted-risk list in it?
Does it say what is being enabled, or only what is restricted?
And is there a clear ask, or only an update?
The point
The honest answer to whether you are exposed is a description rather than a yes or no.
Unqualified reassurance is what turns out wrong in public.
Underlying all of this
Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.
The recurring pattern
The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.