Reporting · Consulting · Consolidation
GRC reporting: giving the board an overview
A board of directors can only supervise what it sees. Yet in many organisations, it receives four separate reports — compliance, risk, internal control, audit — which it has to reconcile itself. The consolidation work is thus shifted onto those who have the least time and the least context.
The situation is common. Compliance presents its controls and findings. Risk management comments on its mapping. Internal control reports on its plan. Internal audit sets out its engagements and recommendations. Four documents, four formats, four scales of severity — and sometimes four different priorities for the same organisation.
Consolidate
A single view, powered by every function
Signal, no volume
What has changed and what calls for a decision
At a good pace
Some topics do not wait for the quarterly committee
The symptom: reports that don't talk to each other
None of them is at fault in isolation. It is their juxtaposition that is problematic: it leaves the board with the task of establishing a coherence that the roles have not produced. The result is predictable — meeting time consumed by reading rather than decision-making.
What a board really expects
An administrator has little time and does not have operational knowledge of the file. They need to know:
- Where do we stand on major risks — and what has changed since the last session?
- What's the matter — the significant weaknesses, along with their root causes and not just their symptoms?
- Who is handling what, by when — and which commitments have fallen behind?
- What do we need to decide on? — which decisions are a matter for the board, and not for management?
- Is the device reliable? — does the independent perspective of internal audit confirm what management is reporting?
The conditions for consolidation
Consolidating does not mean stapling existing reports together. Three prerequisites are necessary.
One common language firstly: without shared severity scales and taxonomy, aggregation adds non-comparable quantities. One unique reference next: each piece of data must have a designated source, otherwise the figures will diverge from one report to another. One reliable traceability finally: a dashboard whose figures cannot be justified loses its credibility at the very first doubt expressed in a meeting.
That is why consolidation cannot simply be improvised at the end of the process: it must be prepared right from the design stage of the scheme.
Structure the document
A tried and tested structure consists of four levels of reading:
- A summary page. The main points: evolution of major risks, key events, items calling for a decision. A busy director must be able to limit themselves to this.
- A consolidated view of the risks. Major risks, their evolution, and their level in relation to the defined risk appetite.
- Action tracking. Recommendations and action plans, with owners, deadlines and reported delays.
- Appendices by function. The detail that each function wishes to document, viewable without cluttering the summary.
An indicator of effectiveness: the proportion of meeting time devoted to discussion rather than presentation. If departments spend most of the meeting commenting on their documents, the reporting has not fulfilled its purpose.
Once this structure is defined, the tools can significantly reduce the manual part of the consolidation. By bringing together missions, checks, findings and actions in a shared environment, reporting can be fed from information already tracked in the course of activity rather than being reconstructed at each deadline.
The question of rhythm
The quarterly cycle structures most boards. It is suitable for overall monitoring, but not for everything. Certain events — a major incident, a significant breach, a sudden change in exposure — call for immediate information, without waiting for the next meeting.
It is therefore useful to define in advance the thresholds for feedback what facts justify informing the chair of the audit committee or the board without delay. This clarification avoids two symmetrical pitfalls — systematic escalation, which drowns out information, and prolonged silence on a serious matter, which exposes management to legitimate criticism.
Common pitfalls
- Confusing exhaustiveness with information: a bulky report is skim-read.
- Presenting activity indicators — the number of checks carried out — rather than result indicators.
- Ironing out the observations across successive proofreadings, to the point of erasing their significance.
- Omit history, which alone makes it possible to distinguish a trend from an isolated point.
- Dedicating several person-days to the manual production of a monthly document.
The ARCAD approach
ARCAD builds reporting formats tailored to the decisions expected by the board and the audit committee: executive summary, consolidated risk overview, action tracking, and documentary appendices. The firm also acts as an independent director and audit committee member—a position that gives precise insight into what a board member expects from a report.
Rethink the reporting addressed to your governing bodies.
ARCAD designs consolidated, legible formats tailored to the decisions expected.