The board asks one question. You answer with forty.
The board asks where the company stands on risk. The answer may be split across an email from security, a finance spreadsheet, last quarter's compliance slide, and a Slack thread. The inputs can use different dates, owners, and definitions.
Someone then has to chase owners, reconcile the numbers, resolve contradictions, and build the deck. By the time it is sent, some of the underlying status may have changed.
Boards are being asked to oversee more, not less
Boards oversee a wider range of risks. Deloitte's Center for Board Effectiveness notes that the number and types of risks boards oversee are expanding and calls for directors to play a more active role in strategic risk oversight. Its examples include technology, regulation, customer preferences, investor activity, and geopolitical uncertainty.
Directors need current information on material changes, emerging risks, ownership, and response. A manually assembled quarterly deck can lag behind the conditions they are expected to oversee.
The information they get is not good enough
PwC found gaps in cyber reporting to boards. In its Pulse survey, 32% of directors said they were completely satisfied with the cybersecurity information they receive from management. PwC's Board Effectiveness survey advises executives to use clear language and frame insights with metrics the board understands.
More messages do not create a coherent view. Directors need a current summary and a way to inspect the detail behind each material line.
Give the board one live view, not one magic number
Give the board a live view it can interrogate. Show risks above appetite, overdue treatments, owner status, trends, material changes, and the evidence behind the current score.
Forty emails create more than a volume problem because none is authoritative. A live risk view lets leadership start with a summary and drill into the owner, control, evidence, and change history.
The reporting scramble is the actual problem
Reporting overhead takes time away from managing risk. Each hour the risk team spends chasing owners, merging spreadsheets, and formatting slides is an hour it cannot spend reducing exposure.
Manual assembly also introduces lag and error. By the time the inputs reach one deck, facts may have changed, owners may have moved on, and a control that was open on Monday can show green on Friday because nobody rechecked it. The board may review a stale picture after the team spent days preparing it.
One number means one source, not one summary
Do not manufacture the board number by hand. A hand-built summary still has forty emails underneath it. Use a single source of truth for material risks, owners, controls, and status updates, so the board sees the same number the team works from.
Sorena SSOT, our Single Source of Truth, keeps risks, owners, controls, and evidence in one governed place. When a status changes, the governed record changes with it. The board view and working view read from the same data, reducing reconciliation.
A live dashboard beats a stale deck
A live view stays current after the deck is sent. The board can read from the governed record instead of the version you finished formatting days earlier. There are fewer emails to chase because the inputs are already in one place, and less reconciliation because the numbers were not split apart first.
The view earns trust when it supports drill-down. A director can open a risk number and see the specific risk, its owner, the control, the evidence, and the last update. Each material line should trace to its source, giving the board a summary it can interrogate in the room and the full detail one click below.
Give the board the view, not the pile
Share one current view with the board. Forty emails are a poor way to provide an answer directors can trust and question. A single source of truth reduces assembly work and gives the board the same picture the team uses every day. See how Sorena Risk Management combines scattered status in one live view.
Frequently asked questions
Why isn't a quarterly board deck enough?+
A hand-built deck is still forty emails underneath, reconciled by hand and often stale by the time the board reads it. The work of chasing owners and merging inputs consumes the risk team's capacity and introduces lag and error. A live view from a single source of truth reduces the assembly step, so the number is more current and traceable.
Does the board need detail as well as a summary?+
It wants both, in the right order. Directors need a synthesized, current view up top, and the ability to drill into any line for the underlying risk, owner, control, and evidence. The failure of forty emails is that it delivers raw detail with no synthesis and asks the board to assemble the picture itself.
What makes the one number trustworthy?+
The view should read from the same governed records the team uses for day-to-day work. Each material number needs a timestamp and links to its risks, owners, controls, and evidence. That traceability reduces the chance that a slide shows a different status from the working record.
Sources
- Deloitte, Board's Expanding Role in Strategic Risk Oversighthttps://www.deloitte.com/us/en/services/audit-assurance/blogs/accounting-finance/board-risk-oversights.html?ref=sorena.io
- PwC, Corporate board director insights, Pulse Surveyhttps://www.pwc.com/us/en/library/pulse-survey/business-growth-through-recession-uncertainty/corporate-board-directors.html?ref=sorena.io
- PwC, Board Effectiveness: A Survey of the C-Suite (Harvard Law Forum on Corporate Governance)https://corpgov.law.harvard.edu/2025/06/23/board-effectiveness-a-survey-of-the-c-suite-4/?ref=sorena.io


