Sample Deliverable

What a BoardSight report actually looks like

The redacted excerpt below is the deliverable an audit committee chair receives: a scored readiness picture across seven domains, the flagship second-line diagnostic, the material risks, and a named-and-dated remediation roadmap. No registration required.

Illustrative sample — not a real client. “Meridian Payments, Inc.” is a fictional company created to demonstrate the instrument. Every name, score, and finding is invented. No client data appears on this page.

Readiness Scorecard

Meridian Payments, Inc. — board-facing readout

2.3/4.0

BoardSight Composite — Exposed

2.2

Enterprise Governance & Director Oversight

Policy present; fluency and cadence thin.

Exposed
2.7

Risk Management & Model Integrity

Strongest area; operator discipline reasonable.

Adequate
2.1

Independent Assurance (Three Lines)Flagship

Flagship gap. Second-line collapse active.

Exposed
2.5

Disclosure, Incident Response & Regulatory

IR plan exists; disclosure controls do not scope AI.

Adequate
2.2

Third-Party & Vendor Cascade

Vendor AI inventory incomplete; EU AI Act mapping absent.

Exposed

Second-Line Collapse Flag: Active

The flag fires when the average of the four collapse-trigger items is below 2.5 and the gap between written policy and operating evidence exceeds 1.0. Meridian: average 1.8, policy-to-evidence spread 1.4. Translation for the AC chair — there is a second line on paper, but nothing independent is testing the AI against the risk appetite the board set. This flag is reported regardless of the overall score.

Top remediation priorities — named, owned, dated

1

Stand up a charter-level second-line AI risk function with an effective-challenge log.

Owner: Chief Risk Officer · Target: May 30

2

Reconcile the model inventory between engineering (first line) and risk (second line).

Owner: CRO + CDO · Target: May 15

3

Run a board-level AI failure-mode tabletop and capture the minute.

Owner: Audit Committee Chair · Target: Jun 30

Top five material AI risks

Each risk in the full report is backed by the underlying scored items, an evidence inventory, the standards it maps to, and the specific Caremark prong it implicates. Excerpt:

1. Second-line collapse — no independent validation on consequential models

A policy exists, but the operating evidence a monitoring system requires is absent. The core fiduciary-exposure driver.

2. EU AI Act Article 26 deployer obligations — unmapped exposure

EU payment-corridor operations create deployer-obligation exposure ahead of the applicable date; no provider/deployer mapping on file.

3. Disclosure controls do not scope AI events

Disclosure controls and procedures exclude AI; the Item 105 / 106 / 8-K chain is not aligned for a defensible material-incident readout.

4. Vendor AI inventory incomplete

Embedded AI features (fraud scoring, contact-center GenAI, help-desk tooling) sit outside the inventory; right-to-audit clauses in only a fraction of contracts.

5. Directors’ AI education stale

No full-board AI education session in over a year; one AI-fluent director; no standing independent advisor.

The full engagement adds the 8–12 page Audit Committee Annex — item-level scores across all seven domains and 64 items, the evidence inventory, a NACD / NIST AI RMF / ISO 42001 gap map, and a 90-day remediation roadmap. Methodology and the standards register are documented in our methodology.

See where your board actually stands

Request a Briefing
B
BoardSight

The AI Oversight Practice from Cognitive Corp.

Standards

NIST AI RMF 1.0ISO/IEC 42001:2023EU AI ActCOSO ERM

BoardSight provides independent, board-ready oversight evidence and advisory support. It does not provide legal opinions, regulatory certification, statutory audit assurance, or a guarantee that an AI system is safe or compliant.

© 2026 Cognitive Corp. All rights reserved.

BoardSight · AI Governance · Three Lines for AI