Files
Magnus Hedemarkandfactory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com> 888872cdfd fix(ai-governance): rephrase passages to clear the 8-word n-gram copyright gate
Reword reference and template sentences in ai-governance that shared
8-word contiguous runs with the mission research notes and source books,
so the VAL-IP-001 n-gram check reports zero overlaps.

Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
2026-08-14 21:00:09 -04:00

7.6 KiB

Board AI-Governance Report

Confidentiality: A completed report turns the noisy detail of day-to-day AI governance into a compact, decision-useful picture for directors, covering inventory and tiering, material risks and incidents, compliance exposure, third-party posture, governance operations, and progress against goals. Store it with the access controls appropriate to board-oversight and fiduciary information. This template implements the board-reporting discipline described in references/procurement-third-party-and-board-oversight.md, including the accountability chain that runs from named owners up through a council to a board committee. It is a working report, not legal advice; fiduciary and disclosure expectations should be confirmed with qualified counsel at use time.

When To Use

Use this report to structure the periodic AI-governance update to the board or its designated committee (audit, risk, or a dedicated technology or AI committee). Prepare it on a fixed cadence — commonly at least quarterly, with a standing agenda item — so AI risk is reviewed on a schedule rather than buried until an incident forces attention. Use it both for the recurring update and for a special briefing when a material AI incident or decision rises to the board's threshold. Management prepares, owns, and is accountable for the report's accuracy; the board's job is to ask questions and challenge the answers.

When Not To Use

Do not use this report as the working-level risk assessment of a single system (that is model-risk-assessment.md or third-party-due-diligence.md), and do not use it as the intake form for a new use case (that is use-case-intake-form.md). This is the top-side summary for directors; the depth behind each metric must already exist in the references, registries, and lifecycle artifacts it aggregates.

Report Identity

Field Entry
Report title <e.g. Board AI-Governance Update — Q3 2026>
Reporting period <start date — end date>
Prepared by / owner <name, role, and function accountable for accuracy>
Reviewed by <AI council / risk committee / audit>
Presented to <board / audit committee / risk committee / technology or AI committee>
Meeting date
Status <draft / final / for decision / for escalation>

Executive Summary

Give directors the three-to-five things they must know in one screen, with the metrics that back each claim.

  • State of the program: <one-paragraph overall assessment of safety, compliance, and governance posture>
  • Material changes this period: <new high-tier systems, exits, acquisitions, or policy changes>
  • Top risks and incidents:
  • Key decisions or approvals requested:
  • Bottom-line metric set: <the few trended numbers that summarize the period, per the reference's metric guidance>

Inventory And Tiering

Show how the AI portfolio is shifting, because directors need to know the scale and shape of what is being governed.

  • Total AI systems in inventory:
  • Count by risk tier: <low / medium / high — and the trend versus last period>
  • High-tier systems with a named owner: <count and percentage, and any gaps>
  • New systems added this period: <list or count, with tiers>
  • Systems retired or deprecated:
  • Coverage: <share of systems with completed risk assessments, model cards, or monitoring>

Material Risks And Incidents

Surface the highest-risk systems, their residual risk, and anything that needed prompt attention.

  • Highest-residual-risk systems:
  • Material incidents and near-misses this period: <list, severity, and status>
  • Incidents escalated to the board / committee:
  • Time to detect and to remediate: <mean or worst-case metrics, trended>
  • Risk-appetite exceptions:

Compliance And Regulatory Exposure

Cover open obligations, audit findings, and any enforcement or investigation activity.

  • Open compliance obligations:
  • Regulatory or enforcement activity: <investigations, notices, or filings relevant to AI>
  • Audit findings: <open versus closed, and the material items>
  • Policy and guidance status: <AI-specific policies in place, under review, or missing>
  • Regulatory horizon:

Third-Party And Supply-Chain Posture

Report the vendor surface, because much of the AI footprint arrives through procurement.

  • Material third-party AI engagements:
  • Vendors with current vs overdue diligence:
  • Critical-vendor concentration:
  • Supply-chain or model events: <data breaches, model changes, or end-of-support at a vendor>
  • Data flows without a documented lawful basis:

Governance Operations

Show the state of the control environment and decision machinery.

  • Policies and council decisions:
  • Approvals granted or denied:
  • Controls operating vs planned:
  • Exception and waiver register:
  • Director education:

Progress Against Goals

Connect the program to the objectives the board approved, and name the gaps.

  • Approved objectives:
  • Progress against each: <status per objective, with evidence>
  • Identified gaps and barriers: <knowledge, budget, regulatory uncertainty, or resource constraints>
  • Plans for the next period:
  • Maturity signal: <how the program is advancing, e.g. toward the framework-based maturity described in the references>

Decision And Escalation Requests

Give the board a clear, bounded set of asks so the meeting produces decisions rather than a briefing.

  • Decisions requested:
  • Escalation path for material incidents:
  • Next reporting date:
  • Recorded by / minuted by:

Completion

To complete this report: fill every labeled field, prepare the executive summary with the trended metric set that backs each claim, populate the inventory and tiering view from the registry, list material risks and incidents with severity and status, report compliance obligations and audit findings honestly, summarize the third-party and supply-chain posture including concentration, describe the state of governance operations, and chart progress against the board-approved goals. End with a bounded set of decisions or escalations for the board. Management must own and be accountable for the report's accuracy; the board reviews, asks questions, and challenges the answers. Rebuild the report on the fixed cadence you set and whenever a material incident or change warrants a special briefing.

Synthesized from references/procurement-third-party-and-board-oversight.md, which draws on The AI Product Manager's Handbook and Developing Cybersecurity Programs and Policies, together with research-org-board-governance.md (current to August 2026). Fillable artifact of the ai-governance skill; educational context, not legal advice.