G11 - ‘Item 5.2 Scored Zero’ Means Nothing to Your Board.
Boards don't act on control IDs and audit phrasing. They act on exposure: which business risk, on which systems, at what severity, owned by whom, treated by when. Translation isn't spin — it's the last mile of governance.
Where this gets hard
- Governance reports name controls and clauses; risk committees allocate attention by consequence and money.
- The same gap is trivial on a drafting tool and existential on a credit-decisioning system — flat reporting treats them identically.
- Critical gaps queue behind cosmetic ones, because nothing weighs severity by the systems each gap touches.
- ‘We're 73% compliant’ invites exactly one response: a nod. It contains no decision.
- Untranslated findings default downward — the most junior person in the room ends up owning residual risk nobody actually accepted.
Where to start
- Weight every gap by the highest-risk system it touches; the same finding should escalate differently at different tiers.
- Map gaps to the business-risk categories your register already uses: regulatory, financial, operational, reputational, strategic.
- End every assessment with one sentence a CFO can act on: risk, systems, severity, owner, deadline.
- Put severe items on the corporate risk register within days, with a named executive owner — not in an appendix.
- Report saves near-misses alongside gaps; prevented losses are the programme's business case.
The companion consulting document on our website includes the risk-overlay scoring model and a board-reporting one-pager template.
Part of RMAT's 12-part series on AI governance — Governing AI with Evidence. The companion consulting document — detailed checklists, a risk table, a maturity self-assessment and a 90-day action roadmap — is available on our website. #CEO #CIO #CTO #Risk #Governance #AI