Board Pack

What is in the pack

The board pack page by page, from the executive view through the risk register to the methodology and reproducibility statements.

Currentengine 9.0.0Verified 2026-08-30

A dated PDF. Its length varies with the number of findings, because three of its sections paginate.

PageContents
CoverThe organisation, the date, and the assessment reference
Executive ViewThe overall position at board altitude: score, band, the governance pillars and their individual positions
Evidence LedgerWhich collectors ran, which did not, the scan scope, and the assessment notes
Financial and Operating PrioritiesBoard attention items, operating observations, cloud cost intelligence, and the board decision lens
Material RisksWhat leadership should look at first
Risk RegisterPriority findings and the control action for each. Paginates
90-Day Board Action MatrixWhat management should do next, banded by timeframe. Paginates
Complete Control IndexEvery failed control. Paginates
MethodologyHow every number in the pack was produced: thresholds, weights, rules
Scope and ReproducibilityWhat was covered, and what it would take to reproduce the result

Two pages that are unusual

The Evidence Ledger comes before the findings, not after. A reader deciding how much weight to place on a red band needs to know what the assessment could see before they read what it concluded.

The Methodology page prints the actual constants applied: the thresholds, the domain weights, the severity weights, the materiality rules and their identifiers. A reader can recompute the result.

The register is capped, disclosure is not

The narrative Risk Register carries a bounded number of rows, because it is a table a board reads. Disclosure is not bounded: the Complete Control Index carries every failed control at every severity, so the capped table plus the index always account for the full count.

The predecessor of this design capped the only place findings appeared at all, and left the large majority of failures invisible.