Board Reporting / Swell AI Governance

The board does not need more AI telemetry. It needs assurance.

A board pack should tell directors whether management knows where material AI is being used, whether accountable owners and controls are in place, what changed, what remains unresolved and where a decision is required.

A quarterly board paper should not require a quarterly reconstruction of reality.

Where AI governance information sits in separate spreadsheets, vendor questionnaires, privacy reviews, emails and project notes, the board-report author must rebuild the story each cycle. That consumes time, creates inconsistent definitions and makes it difficult to explain later why management believed a use was controlled or approved.

01

Inventory changes

The known portfolio changes as new tools, embedded vendor features and employee uses are discovered.

02

Decisions are elsewhere

Approval rationale, conditions and exceptions may live in minutes, emails or workflow systems rather than the register.

03

Evidence ages

Supplier terms, privacy reviews, controls and testing evidence can become stale before the next board cycle.

04

Reports become snapshots

A polished deck may describe the position but still lack a traceable link to the governance record behind it.

A concise assurance view, backed by evidence.

The board should see material exceptions and direction of travel rather than prompt transcripts, model parameters or every control task.

Do we know the material AI uses across the organisation?
Is each material use owned and appropriately approved?
Which high-risk, unapproved or unknown uses require attention?
Are controls, conditions and overdue reviews being managed?
What incidents or material changes occurred?
What is management asking the board or committee to decide?

HarbourCare Services Ltd — quarterly AI governance assurance.

The example below uses the fictional scenario from the product strategy to show what a management-first report can look like. It is intentionally board-oriented: portfolio, risk, approval, exceptions, incidents, changes and decisions.

Fictional HarbourCare Services AI Governance Board Assurance report with risk distribution, approval status and portfolio visibility charts

Fictional example only. The visual is not a compliance certificate and does not represent a real customer.

Report what directors need for oversight — not every piece of operational detail.

01

Cover & assurance basis

Reporting period, issued version, accountable executive, scope and the limits of management's assurance.

02

Executive summary

Three to five messages, material events, direction of travel and decisions requested.

03

Portfolio overview

Active, proposed and retired uses; business-unit coverage; additions; attestation completeness.

04

Risk & approval

High-risk uses and approved, conditional, rejected, unapproved and unassessed status.

05

Exceptions

Unknown AI, overdue reviews, unresolved mandatory controls and expired conditions.

06

Incidents & changes

Material events, affected uses, response status and whether governance was reopened.

07

Management actions

Top actions, accountable owners, due dates and matters requiring committee attention.

08

Cost & value — where useful

Subscription cost, budget, expected/realised value and confidence in the measurement, without forcing weak data into the core assurance story.

09

Assurance statement

Management's evidence basis, limitations and next reporting date — never a blanket “compliant” badge.

The board pack should stay readable.

  • Prompt transcripts and raw technical logs unless they explain a material event.
  • Every control and action — show failed, overdue, exception-based or material items.
  • Unverified supplier claims presented as facts.
  • A single opaque risk score without context.
  • Personal information beyond what directors need for oversight.
  • A universal compliant/non-compliant badge.

The numbers need explanation.

The most useful board commentary explains why the portfolio changed rather than simply showing an increase.

“Management’s visibility of AI use improved this quarter. The register increased from 31 to 38 uses, primarily because the organisation-wide attestation identified four embedded vendor features and three staff productivity uses that had not previously been recorded. The increase does not represent seven new deployments.”

The board view is connected to the underlying case files.

The report is not intended to become a second source of truth. Portfolio measures and exception lists come from the same use-case records, controls, approvals, incidents, material changes and reviews that governance teams maintain during the quarter.

01

Maintain the register

Owners and governance leads keep the portfolio current throughout the reporting period.

02

Close attestations

Missing owners, overdue reviews and known information gaps are made visible before cutoff.

03

Validate exceptions

Governance leads confirm high-risk uses, incidents, expired conditions and open actions.

04

Draft commentary

Management adds context and requested decisions without changing the underlying facts.

05

Issue a snapshot

The final report is locked to its reporting period so later changes do not rewrite history.

Bring your current board question and the report you produce today.

A Swell demo can start with the reporting outcome and work backwards to the governance record needed to support it.