Sample Deliverable
What a BoardSight report actually looks like
The redacted excerpt below is the deliverable an audit committee chair receives: a scored readiness picture across seven domains, the flagship second-line diagnostic, the material risks, and a named-and-dated remediation roadmap. No registration required.
Illustrative sample — not a real client. “Meridian Payments, Inc.” is a fictional company created to demonstrate the instrument. Every name, score, and finding is invented. No client data appears on this page.
Readiness Scorecard
Meridian Payments, Inc. — board-facing readout
2.3/4.0
BoardSight Composite — Exposed
Enterprise Governance & Director Oversight
Policy present; fluency and cadence thin.
Risk Management & Model Integrity
Strongest area; operator discipline reasonable.
Independent Assurance (Three Lines)Flagship
Flagship gap. Second-line collapse active.
Disclosure, Incident Response & Regulatory
IR plan exists; disclosure controls do not scope AI.
Third-Party & Vendor Cascade
Vendor AI inventory incomplete; EU AI Act mapping absent.
Second-Line Collapse Flag: Active
The flag fires when the average of the four collapse-trigger items is below 2.5 and the gap between written policy and operating evidence exceeds 1.0. Meridian: average 1.8, policy-to-evidence spread 1.4. Translation for the AC chair — there is a second line on paper, but nothing independent is testing the AI against the risk appetite the board set. This flag is reported regardless of the overall score.
Top remediation priorities — named, owned, dated
Stand up a charter-level second-line AI risk function with an effective-challenge log.
Owner: Chief Risk Officer · Target: May 30
Reconcile the model inventory between engineering (first line) and risk (second line).
Owner: CRO + CDO · Target: May 15
Run a board-level AI failure-mode tabletop and capture the minute.
Owner: Audit Committee Chair · Target: Jun 30
Top five material AI risks
Each risk in the full report is backed by the underlying scored items, an evidence inventory, the standards it maps to, and the specific Caremark prong it implicates. Excerpt:
1. Second-line collapse — no independent validation on consequential models
A policy exists, but the operating evidence a monitoring system requires is absent. The core fiduciary-exposure driver.
2. EU AI Act Article 26 deployer obligations — unmapped exposure
EU payment-corridor operations create deployer-obligation exposure ahead of the applicable date; no provider/deployer mapping on file.
3. Disclosure controls do not scope AI events
Disclosure controls and procedures exclude AI; the Item 105 / 106 / 8-K chain is not aligned for a defensible material-incident readout.
4. Vendor AI inventory incomplete
Embedded AI features (fraud scoring, contact-center GenAI, help-desk tooling) sit outside the inventory; right-to-audit clauses in only a fraction of contracts.
5. Directors’ AI education stale
No full-board AI education session in over a year; one AI-fluent director; no standing independent advisor.
The full engagement adds the 8–12 page Audit Committee Annex — item-level scores across all seven domains and 64 items, the evidence inventory, a NACD / NIST AI RMF / ISO 42001 gap map, and a 90-day remediation roadmap. Methodology and the standards register are documented in our methodology.