Home Insights & AdviceYour board pack looks polished. Can anyone defend the numbers in it?

Your board pack looks polished. Can anyone defend the numbers in it?

by Sarah Dunsby
3rd Aug 26 11:22 am

There is a particular moment I would ask every director to imagine, because sooner or later it happens for real. A number in the board pack gets challenged. Not casually, properly challenged, by an investor, an auditor, a lender or simply a sharp non-exec. Where did this margin figure come from? Who approved the way it is calculated? Why does it not match the version we saw in March?

And the room does not know.

Nobody is lying. The dashboard is polished, the charts are clear, the pack looks like the output of a business in control of its information. But polish and control are not the same thing. Trusted numbers are not a reporting feature. They are a governance outcome, and the accountability for them sits in the boardroom, not in the IT department.

The test is not accuracy. It is defensibility.

Here’s the thing… most of the time the figures in a challenged board pack are not even wrong. Each one is doing exactly what it was built to do. The problem is that nobody can stand behind them, because the basic questions were never settled.

A director does not need to understand the technology underneath the reporting. But for the handful of numbers the business is run on, revenue, margin, headcount cost, forecast, someone at the table should be able to answer questions this simple. Who owns this measure? Which system does it come from? Who is allowed to change how it is calculated? And when two reports disagree, which one is official?

These are not technical questions. They are ownership questions, and in my experience of working with organisations of all sizes, they are the ones that go unanswered the longest. UK boards have largely accepted that technology risk is a board matter now, cyber gets a slot on the agenda in most well-run firms. The data those firms make decisions with deserves the same treatment, and mostly it does not get it.

Growth spreads the risk quietly

While a business is small, informal control just about works. Reports come from people you know, and when a figure looks odd you ask the person who built it.

Growth breaks that without announcing it. More staff build reports. Acquisitions bring systems that count things differently. A dashboard shared with one manager gets shared onwards, a contractor keeps workspace access after the contract ends, someone changes roles and takes their old permissions with them. None of these is a crisis on its own. Together they mean the business no longer knows who can see salaries, margins, customer values and forecasts, or which of the five versions of the revenue measure the latest pack was built on.

The uncomfortable part for a board is that this risk does not appear anywhere until it appears everywhere. It sits silently in the estate for years, then surfaces at the worst possible moment, during diligence, an audit, a lending conversation or a dispute, when the cost of not being able to defend a number is at its highest.

Agree what the words mean, then protect them

The fix starts somewhere unglamorous. Before dashboards, before platforms, the business has to agree what its own words mean. When is a customer active? Which date drives monthly revenue? Do refunds reduce this month’s sales or the original month’s? Every business assumes these are settled. Ask two departments and find out.

Those agreed definitions then need a home, one governed place that reports draw from, rather than living in the heads of whoever built each file. And the small set of measures that carry real risk, the board pack, the financial figures, payroll, forecasts, need what any important asset needs. A named owner. A known source. Controlled access that follows job roles rather than accumulated requests. A record of when the definition changed and who approved it.

Note what is not on that list. Not a committee for every dashboard, not a policy document nobody reads, not locking the whole estate down. Govern the content that carries risk, and leave people room to work.

Start with an internal stock-take

None of this requires a programme or a budget line to begin. It requires a directive from the board, and a page of paper.

Ask your own team to produce a simple inventory. Which measures does the board pack depend on? For each one, who owns it, which system does it come from, and who can change the calculation? Where do duplicate versions exist, and which report is treated as official? Where has access spread beyond what anyone would design today? This is the same ground that formal Power BI governance services cover in depth, but the first pass needs nothing more than the board asking for it, and the gaps it exposes are usually obvious the moment they are written down.

Then keep the output boardroom-sized. A short, plain overview of reporting risk, unowned reports feeding decisions, sensitive data with unclear access, conflicting versions of key measures, and a sensible order for fixing them. If the exercise produces pages of technical findings and no view a director can act on, it was scoped for the wrong audience. The point is not documentation. It is that the next time a number is challenged, someone at the table already knows the answer.

AI makes the same weakness more expensive

There is a newer reason boards are waking up to this. Most are now asking how AI can improve forecasting and reporting, and the honest answer is that AI inherits whatever the business already has. An AI assistant cannot safely guess what active customer means, and given two plausible-looking margin measures it will pick one and answer confidently. The UK regulator has been clear that organisations need to assess the accuracy of AI outputs they rely on, and that assessment is impossible if nobody can say which underlying definitions are correct in the first place. Ungoverned data with AI on top is not modernisation. It is the same weakness, delivered faster and with more conviction.

Never find out in the meeting

Boards make hard calls on hiring, investment, cost and growth, and those calls are only as strong as the information in front of them. Weak data governance becomes a boardroom risk at the precise moment a leader cannot explain where an important figure came from or who controls it, and by then the damage is reputational as well as operational.

The remedy is not more reporting. It is ownership, agreed definitions, sensible access and regular review, applied to the numbers that matter most. A business should never discover its data rules in the meeting where its numbers are being challenged. The better version of that meeting is available, and it is built long before anyone walks into the room.

Leave a Comment

CLOSE AD

Sign up to our daily news alerts

[ms-form id=1]