Governance & GRC

What good board risk reporting looks like

Design principles for board risk reporting that focuses committees on decisions rather than description.

By Jonas Adam Mohamed Osman AbdelghafourPublished 5 November 2025Last reviewed 28 August 2026

Summary

Board risk reporting is the interface between the risk framework and the board's oversight duty. Too often it is designed from the data outward — everything that can be measured is reported — rather than from the decisions inward.

Start from the decisions

The design question is not "what data do we have?" but "what decisions is this committee expected to take?" Reporting that does not support a decision is briefing material at best and noise at worst.

The core components

Effective board risk packs share a common structure:

  • A concise dashboard of appetite metrics with clearly marked breaches
  • Forward-looking indicators, not only lagging outcomes
  • A short narrative on material changes since the last cycle
  • Open issues with ageing, ownership and expected closure
  • Emerging and horizon risks with a defined watch-list discipline

Discipline over volume

Packs grow because nothing is ever removed. An explicit sunset rule — every recurring item is reviewed annually for continued relevance — is a small governance change with a large effect on quality.

Consistency across committees

Terminology, thresholds and RAG conventions should be consistent between risk, audit and executive committees. Divergence forces the board to reconcile rather than decide.

Limitations

Reporting quality is bounded by data quality. Where lineage or timeliness is weak, the pack should acknowledge it and identify the remediation programme, rather than present spurious precision.

Related expertise

See Governance, Risk and Compliance and Corporate Governance.

Current compliance reading

About the author

Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance expert advising banks, insurers and regulated firms. See the professional profile, about and qualifications.

Frequently asked questions

What should risk leaders know about start from the decisions?

The design question is not "what data do we have?" but "what decisions is this committee expected to take?" Reporting that does not support a decision is briefing material at best and noise at worst.

What should risk leaders know about the core components?

Effective board risk packs share a common structure:

What should risk leaders know about discipline over volume?

Packs grow because nothing is ever removed. An explicit sunset rule — every recurring item is reviewed annually for continued relevance — is a small governance change with a large effect on quality.

What should risk leaders know about consistency across committees?

Terminology, thresholds and RAG conventions should be consistent between risk, audit and executive committees. Divergence forces the board to reconcile rather than decide.

What should risk leaders know about about the author?

Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance expert advising banks, insurers and regulated firms. See the [professional profile](/jonas-adam-mohamed-osman-abdelghafour), [about](/about) and [qualifications](/qualifications).