AI Governance, Risk & Red Teaming
Strategic · M11 · lesson 11 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Board AI Risk Dashboard - 12 KRIs/KPIs
📖
now learning

Board AI Risk Dashboard - 12 KRIs/KPIs

15 min

Q2 2026 Acme.Corp board AI subcommittee, 14:00, the half-hour slot before the audit-committee handover. The chair, former general counsel of a global bank, eleven months into the subcommittee assignment per the January 2026 charter amendment (lesson 072), opens with a sentence that lands like a memo: "I have thirty minutes every quarter. The full board gives me ten minutes of its hour. I do not want a twelve-deck briefing. I want a dashboard. One page. Twelve numbers. RAG-coded. Trended. Tied to appetite. By Q3 I want the dashboard, the commentary, and the appendix, three pages, and I want the CRO to defend any amber or red cell against the appetite from lesson 074, the heat-map from lesson 085, and the FAIR-quantified loss expectations from lesson 086. The audit committee's 10-K disclosure preparation will cite it. The ERM aggregation will pull from it. The dashboard is now the single-pane-of-glass artifact for AI risk. I expect twelve KRIs/KPIs, four categories, three metrics each, defined to a level a Big-Four auditor and an EU AI Office inspector can both read on the same page." The CRO has ninety days. This lesson is the playbook: the regulatory expectation forcing the dashboard; the four-category structure (Portfolio Risk, Compliance Posture, Operational Resilience, Vendor + Supply Chain); the twelve KRIs/KPIs each defined with formula, data source, threshold, cadence, owner; the one-page layout and three-page briefing format; six anti-patterns; the Acme Q2 2026 worked dashboard with two ambers and the board's asks; and the cross-walk that makes the dashboard the load-bearing artifact for EU AI Act Article 17, SR 11-7 aggregation, ISO 42001 Clause 9, AICPA AI TSC vendor evidence, and SEC Items 105/303/407 cybersecurity-and-AI disclosure. By the next board cycle, the dashboard fits one slide. The chair signs the minutes.

Why a Board AI Risk Dashboard Is the 2026 Single-Pane-of-Glass

The pre-2024 board AI report was either absent, sub-bulleted under cyber, or a quarterly slide deck, narrative-heavy, defensible only because no chair pressed it. That posture is gone in 2026. Seven developments converge on a single artifact, a one-page board AI risk dashboard with 12 KRIs/KPIs, that the audit committee, board AI subcommittee, risk committee, ERM function, and external assurance bodies all read from the same page.

  • Board AI subcommittee charters amended through 2024-2026. Approximately 35-50% of S&P 500 board charters were amended to include explicit AI-oversight language (Spencer Stuart Board Index 2025 + EY Center for Board Matters 2026 disclosures). The amendments name an audit committee, risk committee, or newly-formed AI committee as responsible organ and require periodic AI-portfolio reporting (lesson 072). The dashboard is the standard format: single page, defensible against challenge, shows trajectory, ties to appetite.
  • EU AI Act Article 17 (QMS) and Article 9 (continuous risk management). Article 17(1)(a)(b) requires a documented strategy for regulatory compliance and risk-management procedures; Article 9 requires a continuous, iterative process. The dashboard is the visible artifact, a Conformity Assessment Body in 2026 cross-references its KRI structure against the Annex IV TDF (Article 11) to test whether documented risks match operational evidence.
  • SR 11-7 / OCC 2011-12 / PRA SS1/23 aggregation principle applied to AI. Model risk requires board-informed aggregate position. As LLMs and agents enter the model-risk inventory (lesson 068), the dashboard is the portfolio-level view that satisfies the aggregation principle without forcing a model-by-model deep dive into the 45-90 minute risk-committee cycle.
  • SEC cybersecurity disclosure rule (effective 18 December 2023) extended to AI through 2025-2026 staff commentary. Item 1.05 Form 8-K for material incidents; Items 105 (risk factors), 303 (MD&A), and 407 (audit committee oversight) increasingly cite AI risks in proxy-and-10-K filings. Absent a defensible AI dashboard, the committee cannot attest under Item 407.
  • Dodd-Frank §165 enhanced prudential standards. Bank holding companies and designated nonbank financial companies must maintain board-level risk-committee oversight with explicit risk appetite. The dashboard calibrated to the AI risk appetite (lesson 074) is the standard form.
  • ISO/IEC 42001:2023 Clause 9 (performance evaluation) + Annex A.3 + A.9. Surveillance auditors in 2026 specifically request quantitative evidence of monitoring effectiveness. The dashboard with refresh cadence, RAG thresholds, appetite linkage, and signed sign-off block is the evidence stream that defuses Major Finding risk on Clause 9 objectives.
  • Audit committee + ERM integration mandates aggregation upward. Enterprise risk reporting in 2026 demands AI risk roll-up into the same top-of-house view that cyber, operational, financial, conduct, and strategic risks already feed. The dashboard's twelve KRIs are the input feed; the ERM scorecard is the consumer; the audit committee is the aggregator.

Why a dashboard rather than a slide deck. The board chair receives 80-300 pages of pre-read material per cycle. AI consumes typically 8-30 pages and 10-30 minutes of agenda. A 12-deck narrative is unreadable and unmemorable. A one-page dashboard with 12 KRIs, RAG-coded, trended over 4 quarters, with one-line annotations, is absorbable in 4-7 minutes, defensible under follow-up, and is the artifact the chair carries into the audit-committee handover and the ten-minute full-board slot.

What "12 KRIs/KPIs" means. A KRI is forward-looking (leading); a KPI is backward-looking (lagging). A defensible dashboard pairs both in every category. The Acme set: four categories × three metrics = twelve total, with each category carrying at least one leading and at least one lagging. Twelve is the cognitive ceiling for board absorption on one page; more than fifteen breaks readability (anti-pattern 1); fewer than nine sacrifices defensibility.

The defensibility test. Before any dashboard lands on the agenda, the AI Risk Office must pass a five-clause test. (1) Anchored thresholds, green/amber/red bands as specific numeric ranges tied to the board-approved AIRA (lesson 074). (2) Named source-of-truth per metric: inventory, FAIR ALE table, heat-map, finding-register, vendor DDQ tracker, Article 73 log, FRIA registry, ISO internal-audit plan. (3) 4-quarter trend sparkline, a point-in-time snapshot is half the artifact. (4) Tied to risk appetite, breach signals fire the lesson 074 runbook. (5) Quarterly refresh + monthly AIGC interim + emergency-refresh on substantial incident.

The Four-Category × Three-KRI Structure (Twelve Metrics Defined)

The twelve metrics distribute across four categories. Each category sits in one quadrant of the one-page dashboard. Each metric is fully specified: definition, formula, data source, RAG thresholds, refresh cadence, owner role, regulatory cross-walk, Article 99 worst-case penalty exposure linkage. The Acme set, defensible against challenge from board, audit committee, Big-Four auditor, ISO 42001 surveillance auditor, Conformity Assessment Body, EU AI Office inspector, SR 11-7 prudential examiner, is the following twelve.

Portfolio Risk Quadrant (KRI 1-4).

Answers: how big is the portfolio, how risky is its composition, what is aggregate financial exposure, how many appetite breaches are open.

  • KRI 1 - Inventory Size + Tier Mix. Definition: count of AI systems split by risk tier (Tier 1 Annex III high-risk; Tier 2 Article 50 limited-risk; Tier 3 minimal-risk; Tier 4 Article 5 prohibited, should be 0). Formula: per-tier counts; Tier-1 ratio vs AIRA ceiling. Source: AI model inventory (lesson 011/067). Thresholds: Tier 4 = 0 (any non-zero = crimson); Tier-1 ratio ≤25% (>25% amber; >35% red); inventory growth ≤30% YoY (>30% amber, capacity strain). Refresh: monthly. Owner: CAIO (lesson 005). Cross-walk: Articles 6 + 11; NIST Govern 1.1 + Map 1.1; ISO A.6. 99 worst-case: 99(1) €35M / 7% for Tier 4; 99(3) €15M / 3% otherwise.
  • KRI 2 - Aggregate ALE₉₅ € (FAIR-Quantified). Definition: 95th-percentile Annualized Loss Expectancy across the portfolio per the lesson 086 FAIR model, translates the lesson 085 heat-map into a single euro number. Formula: Σ (loss-event frequency × loss-magnitude distribution); Monte Carlo P95. Source: FAIR ALE table refreshed quarterly. Thresholds: ≤€25M green; €25-50M amber; >€50M red; >€75M crimson. Refresh: quarterly; emergency on Article 73 or substantial-modification. Owner: AI Risk Office head (2L). Cross-walk: Article 9(2)(a); NIST Measure 2.6; ISO Clause 6.1.2; SR 11-7 aggregation. 99(3) €15M / 3%.
  • KRI 3 - Heat-Map Red + Crimson Cell Count (with Arrows). Definition: count of plotted scenarios on the lesson 085 heat-map in red ∪ crimson cells + net 12-month movement arrows. Formula: count(red ∪ crimson); sub-count with deteriorating arrow. Source: lesson 085 heat-map. Thresholds: ≤1 green; 2 amber; 3 red; ≥4 crimson; deteriorating sub-count >1 = amber regardless. Refresh: quarterly. Owner: AI Risk Office head. Cross-walk: Articles 9 + 17; NIST Govern 5.1 + Map 5.1. 99(3) €15M / 3%.
  • KRI 4 - AIRA Breach Count This Quarter. Definition: count of AIRA KRI breaches per the lesson 074 runbook (red + amber distinct). Formula: count(breaches ≥ amber); sub-count of red with runbook activated. Source: AIRA breach register. Thresholds: 0-1 amber green; 2-3 amber or 1 red amber; ≥4 amber or ≥2 red red; any red unresolved >30d crimson. Refresh: monthly. Owner: AI Risk Office head. Cross-walk: AIRA (lesson 074); NIST Govern 1.3 + 1.4; ISO Clause 6.2. 99(3) €15M / 3% if regulatory.

Compliance Posture Quadrant (KPI 5-7).

Answers: is documentation current, are fundamental-rights assessments closing, are we ready for surveillance audit.

  • KPI 5 - Annex IV TDF Currency Rate. Definition: % of Tier-1 systems whose Annex IV TDF refreshed ≤90d (or no current Article 25(1)(a) trigger). Formula: count(Tier-1 with TDF ≤90d OR no trigger) / count(Tier-1). Source: Annex IV TDF registry (lesson 027/035) + substantial-modification log (lesson 043). Thresholds: ≥95% green; 85-94% amber; <85% red; any system >180d stale + current trigger = crimson. Refresh: monthly. Owner: CAIO + CAF head (lesson 077). Cross-walk: Articles 11 + 18 + 25(1)(a) + Annex IV; NIST Govern 1.6; ISO Clause 7.5. 99(3) €15M / 3%.
  • KPI 6 - FRIA/IMV Closure Rate. Definition: % of scheduled FRIAs (Article 27) and IMVs (lesson 068) closed on schedule this quarter. Formula: count(closed on schedule) / count(scheduled). Source: FRIA registry + IMV calendar. Thresholds: ≥90% green; 75-89% amber; <75% red; any FRIA overdue >60d on Annex III §5/§6/§7 deployer = crimson. Refresh: monthly. Owner: AI Risk Office + DPO joint. Cross-walk: Article 27 + SR 11-7 IMV + Article 9; NIST Measure 1.1 + 2.1; ISO A.6.1.3. 99(3) €15M / 3%.
  • KPI 7 - ISO 42001 Surveillance Readiness Score. Definition: composite 0-100 score weighting internal-audit closure rate, management-review currency, corrective-action register, Clause 9 monitoring evidence, Annex A maturity (weights 25/15/20/25/15). Source: Internal Audit (3L) + AIMS records. Thresholds: ≥85 green; 70-84 amber; <70 red; any open Major Finding from prior surveillance = crimson regardless. Refresh: quarterly. Owner: AIMS owner + Internal Audit. Cross-walk: ISO/IEC 42001:2023 all Clauses + Annex A; NIST Govern 1.7; commercial contracts. Worst-case: certificate suspension €4-12M/yr commercial.

Operational Resilience Quadrant (KPI 8-10).

Answers: when AI fails, how fast does the organization detect, report, and remediate.

  • KPI 8 - Article 73 Incidents YTD + 15-Day Timeliness %. Definition: count of Article 73 serious incidents YTD + % reported to EU AI Office within 15-day statutory window (or 2-day for widespread infringement). Formula: count(YTD incidents); count(in window) / count(reports filed). Source: incident log + regulatory-correspondence binder. Thresholds: 0-1 with 100% green; 2-3 with ≥95% amber; ≥4 OR any late = red; any unreported post-window = crimson. Refresh: monthly (immediate on incident). Owner: AI Incident Response (1L) + AI Risk Office (2L). Cross-walk: Articles 73 + 72; NIST Manage 2.3 + 4.3; ISO A.9.3; SR 11-7; SOC 2 CC7. 99(3) €15M / 3%.
  • KPI 9 - Red-Team Findings Open >30d (Severity-Weighted). Definition: severity-weighted count of red-team findings open >30d using lesson 083 CVSS-AI rubric (Critical×4, High×2, Medium×1, Low×0.5). Formula: Σ(weight × count in band). Source: red-team finding register (lesson 084). Thresholds: ≤8 green; 8.1-15 amber; >15 red; any open Critical >30d = crimson regardless. Refresh: weekly to lead, monthly to AIGC, quarterly to board. Owner: AI Red Team head + CISO. Cross-walk: Articles 15 + 55 + 9; NIST Manage 2.1 + Measure 2.7; ISO A.6.2.6 + A.9; CAISI (Feb 17, 2026). 99(3) €15M / 3%.
  • KPI 10 - PMM Drift Signals Open vs Closed. Definition: count of Article 72 PMM drift signals (data/concept/fairness/performance) open vs closed this quarter. Formula: count(open); closed/total ratio; sub-count open >45d. Source: PMM monitoring plan + drift-signal log (lesson 080). Thresholds: open ≤3 with closure ≥80% green; open 4-6 OR closure 65-79% amber; open ≥7 OR closure <65% red; any open >45d on Tier-1 = crimson. Refresh: weekly to PMM owner, monthly to AIGC. Owner: PMM head (lesson 080). Cross-walk: Article 72 + Annex IV §9; NIST Manage 4.1; ISO A.9.1; SR 11-7. 99(3) €15M / 3%.

Vendor + Supply Chain Quadrant (KPI 11-12).

Answers: how concentrated is foundation-model supply chain, how current is third-party assurance. Vendor risk is the cascade trigger for the prior three quadrants.

  • KPI 11 - Vendor Concentration % (Top FM Provider). Definition: % of production AI systems (tier-weighted Tier 1×3, Tier 2×2, Tier 3×1) dependent on the single largest foundation-model provider. Formula: Σ(tier-weight × count on top provider) / Σ(tier-weight × total). Source: AI inventory provider field + vendor tracker. Thresholds: ≤45% green; 46-60% amber (diversification plan required); >60% red (board decision); >75% crimson. Refresh: quarterly. Owner: Procurement / Vendor Management + CAIO. Cross-walk: Articles 25 + 26; NIST Govern 6.1 + Manage 3.1; ISO A.10; SR 11-7; SOC 2 CC9; CAISI. Worst-case: single-supplier €5-30M + 25(1)(a) cascade.
  • KPI 12 - Vendor DDQ-Current Rate. Definition: % of Tier-A (FM providers) + Tier-B (critical tooling) vendors with current (≤12m) DDQ + ISO 42001 evidence + SOC 2 Type II with AI criteria + AI-specific evidence package. Formula: count(all 4 streams current) / count(Tier-A+B). Source: vendor evidence binder (lesson 049 + 050). Thresholds: ≥90% green; 75-89% amber; <75% red; any Tier-A with SOC 2 qualified or ISO 42001 lapse = crimson. Refresh: quarterly. Owner: Procurement / Vendor Management. Cross-walk: Articles 25 + 26; NIST Govern 6.1; ISO A.10; AICPA AI TSC + SOC 2 with AI; CAISI. 99(3) €15M / 3%.

Leading vs lagging balance. Leading (9): KRI 1 inventory growth, KRI 3 heat-map deteriorating arrows, KRI 4 amber-breach precursors, KPI 5 TDF currency, KPI 7 ISO readiness, KPI 9 open red-team findings, KPI 10 PMM drift, KPI 11 vendor concentration, KPI 12 DDQ currency. Lagging (3): KRI 2 ALE₉₅, KPI 6 FRIA/IMV closure, KPI 8 Article 73 count. The 9/3 ratio is the defensible balance, lagging-heavy becomes a post-mortem, not a steering tool (anti-pattern 2).

One-Page Dashboard Layout + Three-Page Quarterly Briefing

The dashboard is one page; the briefing pack wraps it in two supporting pages. Three pages total, designed to fit a thirty-minute slot with 10-12 minutes of pre-read and 18-20 minutes of agenda, so the chair can carry the pack verbatim into the audit-committee handover and the ten-minute full-board slot.

Page 1, the dashboard.

Landscape orientation, four quadrants arranged 2×2 - Portfolio Risk (top-left), Compliance Posture (top-right), Operational Resilience (bottom-left), Vendor + Supply Chain (bottom-right). Tiles per quadrant: 4/3/3/2. Each tile shows: KRI/KPI number + name (one line); current value (large numeral); RAG background (green/amber/red/crimson per anchored thresholds); 4-quarter trend sparkline; one-line explanatory annotation; arrow indicator (improving ↑ / stable → / deteriorating ↓); refresh timestamp; owner role. Legend strip across the bottom defines RAG bands + dashboard version + next scheduled refresh. The dashboard prints legibly on A4 landscape, projects legibly on 1080p, and reduces legibly to a quarter-page board-pack thumbnail. Twelve tiles fit comfortably; fifteen breaks readability.

Page 2, the commentary.

Four-section structure, 350-500 words. (a) Worst KPI: one paragraph: worst-RAG tile, value driving the rating, named mitigation owner, Q3 commitment, appetite linkage. (b) Best KPI, one paragraph: strongest tile and the operational discipline that produced it (so the board sees both risk and capability). (c) Emerging concern, one paragraph: a tile currently green/amber trending toward red with rationale. (d) Asks and decisions: bulleted 2-5 items the board AI subcommittee is asked to decide (sign-off, ratification, budget approval, escalation to full board). The commentary is the chair's Sunday-evening pre-read.

Page 3, the appendix.

Fine-print follow-up reference. (a) Sign-off block (CRO + CAIO + AI Risk Office head + chair + meeting date + version); (b) data-source register per KRI; (c) regulatory cross-walk table (Article + NIST subcategory + ISO control + SR 11-7 + Article 99 band); (d) emergency-refresh trigger list; (e) threshold-revision history. The appendix is the artifact a Big-Four auditor, EU AI Office inspector, or 10-K disclosure reviewer pulls into evidence binders.

Cadence + emergency-refresh triggers.

Refreshed quarterly by the AI Risk Office (2L) with named inputs from CAIO (KRI 1), AI Red Team (KPI 9), PMM owner (KPI 10), Vendor Management (KPI 11 + 12), DPO + Internal Audit (KPI 6 + 7), AI Incident Response (KPI 8). Presented to the board AI subcommittee quarterly; to the AIGC (lesson 014) monthly; aggregated into the ERM scorecard for top-of-house reporting; cited in the audit committee's 10-K Items 105/303/407 preparation and proxy-statement governance section.

Emergency-refresh triggers (mandatory). (a) Article 73 serious incident; (b) AIRA red KRI breach unresolved >7d; (c) ISO 42001 surveillance Major Finding; (d) Tier-A vendor SOC 2 qualified opinion or ISO 42001 lapse; (e) Article 25(1)(a) substantial-modification on Tier-1 system without TDF refresh on schedule; (f) material litigation or regulator action; (g) chair explicit request. The emergency-refresh capability is the test of whether the dashboard is a steering tool or a calendar artifact.

Six Anti-Patterns That Kill Dashboards

  • 1 - Too many KPIs. 18, 24, or 36 metrics break board absorption; the cognitive ceiling for a non-AI-specialist director with multiple committee assignments is 12-15 across a 4-7 minute scan. Beyond 15, the dashboard becomes a risk-register printout and the chair tunes out. Fix: cap at 12 board-facing KRIs; push the remaining 60-150 register entries into AIGC monthly and the lesson 080/lesson 084 operational dashboards consumed by 1L/2L.
  • 2 - Lagging only, no leading indicators. Count-of-incidents / count-of-fines / count-of-findings is a post-mortem, not a steering tool. The chair asks "what will go wrong next quarter" and the lagging-only dashboard cannot answer. Fix: enforce roughly 70/30 leading-to-lagging ratio (9 leading / 3 lagging in the Acme set).
  • 3 - Static thresholds. A threshold set in Q1 2025 and never revisited drifts either too lax (always green; no signal) or too tight (always red; useless). Fix: revisit at each annual AIRA refresh (lesson 074); document the threshold-revision history in the appendix; major recalibration requires AIGC + board dual sign-off.
  • 4 - No AIRA tie-back. KRIs that float free of the board-approved appetite have no defensibility. The chair asks "above or below appetite" and the un-tied KRI cannot answer. Fix: every threshold cross-walked to AIRA in the appendix; breach signals fire the lesson 074 runbook; KRI 4 explicitly aggregates breach activity into a top tile.
  • 5 - Qualitative-only. "High vendor concentration; we should diversify" without a quantitative threshold and a specific percentage is a memo, not a dashboard tile. The Big-Four auditor and EU AI Office inspector cannot test qualitative claims against evidence. Fix: every tile carries a specific numeric value, a RAG threshold band, and a source-of-truth table.
  • 6 - Green-washing / threshold tuning. The 2L producer has a soft incentive to keep tiles green and avoid uncomfortable conversations. Threshold tuning ("lift amber from 25% to 30% because we expect Q3 inventory growth") is the failure mode. Fix: (a) threshold changes require AIGC + board dual sign-off; (b) Internal Audit (3L) reviews threshold-history annually to the audit committee; (c) producer's variable comp decoupled from green-tile count (per lesson 083 comp logic); (d) "threshold change log" reviewed every quarter.

Worked Example - Acme Q2 2026 Board AI Risk Dashboard

Acme.Corp Q2 2026: 17 production AI systems, board AI subcommittee chartered Jan 2026, AIRA refreshed Feb 2026 (lesson 074), heat-map and FAIR ALE refreshed May 2026 (lessons 085 + 086). The Q2 dashboard, populated in the four-quadrant layout, with anchored thresholds.

Portfolio Risk Quadrant.

  • KRI 1 - Inventory size + tier mix: 17 total (Tier 1: 4 / Tier 2: 6 / Tier 3: 7 / Tier 4: 0); Tier-1 ratio 23.5% (≤25% green); inventory growth 22% YoY (≤30% green). Tile: green. Trend: 14 → 15 → 16 → 17 (stable growth). Annotation: "Q3 procurement pipeline adds two Tier-3 systems; monitor for tier-creep."
  • KRI 2 - ALE₉₅ €: €22.4M (€25M ceiling; green). Tile: green. Trend: €19.1M → €20.6M → €21.8M → €22.4M (rising but within ceiling). Annotation: "Driven 38% by Scenario 7 Article 73 late-report tail; Scenario 7 mitigation operational test scheduled 30 June."
  • KRI 3 - Heat-map crimson + red cell count: 2 (Scenario 5 vendor lock-in; Scenario 7 Article 73 late-report). 1 deteriorating arrow (Scenario 5); 1 improving (Scenario 7). Tile: amber. Trend: 1 → 1 → 2 → 2. Annotation: "Both red cells have ratified mitigation; Q3 trajectory toward amber."
  • KRI 4 - AIRA breach count this quarter: 1 amber (KRI red-team-finding-open metric briefly crossed in March, resolved April); 0 red. Tile: green. Trend: 0 → 0 → 1 → 1. Annotation: "Single brief amber breach; closed within 21 days."

Compliance Posture Quadrant.

  • KPI 5 - Annex IV TDF currency: 96% (≥95% green; 12 of 12 Tier-1 + Tier-2 critical with TDF refresh ≤90d; 1 Tier-3 system with TDF 102d stale awaiting Q3 refresh slot). Tile: green. Trend: 92 → 94 → 95 → 96. Annotation: "Q3 refresh slot allocated 14 July; expect to maintain ≥95%."
  • KPI 6, FRIA/IMV closure rate: 93% (8 of 9 scheduled; 1 FRIA on hiring-AI deferred 7 days for vendor remediation completion, within 60-day buffer). Tile: green. Trend: 88 → 90 → 92 → 93. Annotation: "Hiring-AI FRIA closing 22 May; Q3 schedule firm."
  • KPI 7 - ISO 42001 surveillance readiness: 88 (≥85 green; year-2 surveillance scheduled October 2026; internal-audit pre-check completed April with 3 minor findings, all on schedule for remediation). Tile: green. Trend: 81 → 83 → 86 → 88. Annotation: "Stage-2 audit November 2025 passed cleanly; surveillance readiness on track."

Operational Resilience Quadrant.

  • KPI 8, Article 73 incidents YTD + 15-day timeliness: 1 incident YTD (22 April hiring-AI fairness-slice breach); reported on day 19 (late by 4 days due to trigger-categorization ambiguity between 1L and 2L, root cause identified in lesson 085 heat-map exercise). Tile: red. Trend: 0 → 0 → 0 → 1 (4-days-late). Annotation: "Trigger-categorization remediation playbook signed; operational test 30 June; 15-day timeliness 100% for any incident from 1 July."
  • KPI 9 - Red-team findings open >30d (severity-weighted): 12.4 (>8 amber threshold; <15 red threshold). 1 Critical (closed at day 27, no longer counted), 1 High open at day 41 (weight 2.0 × age penalty; ServiceAssist v1.0 prompt-injection finding awaiting vendor patch), 4 Medium open average 38d, 2 Low open >30d. Tile: amber. Trend: 8.1 → 9.7 → 11.2 → 12.4. Annotation: "Vendor patch ETA 12 June will close High finding and drop score below 8."
  • KPI 10 - PMM drift signals open vs closed: 3 open (1 fairness drift on hiring-AI in remediation, 1 performance drift on credit-scoring under investigation, 1 data drift on customer-service under monitoring); closure ratio 78% this quarter (7 closed of 10 total in quarter). Tile: green. Trend: 4 → 3 → 4 → 3 (stable). Annotation: "All three open <30d; closure ratio within green band."

Vendor + Supply Chain Quadrant.

  • KPI 11 - Vendor concentration %: 68% (>60% red threshold; >75% crimson; well above 45% green ceiling). Top provider supplies foundation model for 11 of 17 systems (3 Tier-1, 4 Tier-2, 4 Tier-3, weighted 68%). Tile: amber bordering red, appetite for vendor concentration is 60%; current is 68%; this is the first KPI driving the worst-KPI commentary section on page 2. Note: per Acme's appetite-band convention, 60-75% = amber; >75% = red. Trend: 64 → 65 → 67 → 68 (rising). Annotation: "Q3 multi-supplier diversification plan ratified by AIGC March; first contract Q3, second Q4; target 55% by Q1 2027."
  • KPI 12, Vendor DDQ-current rate: 87% (75-89% amber band; 13 of 15 Tier-A + Tier-B vendors with all four evidence streams current; 2 lagging, one SOC 2 Type II refresh delayed by vendor, one ISO 42001 evidence package overdue from Tier-B tooling provider). Tile: amber. Trend: 82 → 84 → 86 → 87. Annotation: "Both lagging vendors on track for July refresh; expect green Q3."

Page 2 - Q2 2026 Acme commentary.

Worst KPI: KPI 11 - Vendor concentration at 68% versus 60% appetite ceiling. Driven by 2024-2025 foundation-model market consolidation and historical scale-economics decisions. CRO commits Q3-Q4 multi-supplier diversification plan: first contract signed June 30 (secondary provider for 2 Tier-3 use cases), second contract Q4 (primary provider for the hiring-AI Tier-1 use case migrating from incumbent), target concentration 55% by Q1 2027. Appetite linkage: AIRA KRI breach activated 14 March; lesson 074 breach-response runbook live with quarterly chair updates. Best KPI: KPI 5 - Annex IV TDF currency at 96%. Driven by the Centralized AI Function's (lesson 077) introduction of automated TDF version-control workflow in Q4 2025, replacing the prior manual quarterly refresh. The function reports under one hour of CAF time per refresh versus 8-12 hours pre-automation. Emerging concern: KPI 9 - Red-team findings open >30d at 12.4 weighted-points, within amber but trending toward red as ServiceAssist v1.0 vendor-patch ETA slips from initial 28 May to 12 June; if patch slips further or new Critical finding lands, KPI 9 crosses 15 into red. CRO authorizes interim mitigation (additional input validation layer) ratified by AIGC for deployment 1 June pending vendor patch. Asks and decisions for the board AI subcommittee this quarter: (1) Note KPI 11 amber/red boundary and ratify the Q3-Q4 vendor diversification plan; (2) approve €1.2M Q3 budget for the vendor diversification execution and the multi-supplier contract negotiation legal spend; (3) sign-off on the Article 73 trigger-categorization remediation operational test (30 June); (4) note the Q3 readiness on KPI 7 ISO 42001 surveillance (October cycle); (5) ratify the dashboard's threshold-revision history (no changes Q2; next scheduled review Q3 alongside annual AIRA refresh).

Board AI subcommittee actions taken.

Chair notes KPI 11 amber/red boundary; ratifies the diversification plan; approves the €1.2M budget; signs off on the operational test; thanks the CRO for the brevity of the briefing pack; instructs the audit committee handover to reference the dashboard verbatim in the 10-K disclosure draft; instructs the AI Governance Committee to use the dashboard as the standing artifact for monthly reviews; closes the agenda item at minute 24 of 30. The chair has six minutes back. The CRO has thirty-three minutes back versus the prior twelve-deck briefing format.

Cross-Walk + Penalty Exposure Reference

The dashboard is the load-bearing artifact at the intersection of EU AI Act, NIST AI RMF, ISO/IEC 42001, SR 11-7, AICPA AI Trust Services, SEC disclosure, and ERM aggregation. The cross-walk, reproduced in the appendix of every quarterly briefing, names the primary mapping per metric plus the Article 99 penalty band linked to its failure mode.

  • KRI 1 (inventory + tier mix): Articles 6, 11, 25(1)(a); NIST Govern 1.1 + Map 1.1; ISO A.6 + Clause 6.1.2; SR 11-7 inventory. 99(1) €35M / 7% if Tier 4 present; 99(3) €15M / 3% otherwise.
  • KRI 2 (ALE₉₅): Articles 9(2)(a) + 17; NIST Measure 2.6; ISO Clause 6.1.2; SR 11-7 aggregation. 99(3) €15M / 3%.
  • KRI 3 (heat-map red + crimson): Articles 9 + 17; NIST Govern 5.1 + Map 5.1; ISO Clause 6.1.2. 99(3) €15M / 3%.
  • KRI 4 (AIRA breach count): Article 17 + board appetite; NIST Govern 1.3 + 1.4; ISO Clause 6.2. 99(3) €15M / 3% if regulatory.
  • KPI 5 (Annex IV TDF currency): Articles 11 + 18 + 25(1)(a) + Annex IV; NIST Govern 1.6; ISO Clause 7.5. 99(3) €15M / 3%.
  • KPI 6 (FRIA/IMV closure): Article 27 + SR 11-7 IMV; NIST Measure 1.1 + 2.1; ISO A.6.1.3. 99(3) €15M / 3%.
  • KPI 7 (ISO 42001 readiness): ISO/IEC 42001:2023 all Clauses + Annex A; commercial contracts. Certificate suspension + €4-12M/yr commercial.
  • KPI 8 (Article 73 incidents + timeliness): Articles 73 + 72; NIST Manage 2.3 + 4.3; ISO A.9.3; SR 11-7 incident reporting; SOC 2 CC7. 99(3) €15M / 3%.
  • KPI 9 (red-team open >30d): Articles 15 + 55 + 9; NIST Manage 2.1 + Measure 2.7; ISO A.6.2.6 + A.9; CAISI. 99(3) €15M / 3%.
  • KPI 10 (PMM drift): Article 72 + Annex IV §9; NIST Manage 4.1; ISO A.9.1; SR 11-7 ongoing monitoring. 99(3) €15M / 3%.
  • KPI 11 (vendor concentration): Articles 25 + 26; NIST Govern 6.1 + Manage 3.1; ISO A.10; SR 11-7 vendor; SOC 2 CC9; CAISI supply-chain. Single-supplier €5-30M operational + 99(3) cascade.
  • KPI 12 (vendor DDQ-current): Articles 25 + 26; NIST Govern 6.1; ISO A.10; AICPA AI TSC + SOC 2 with AI. 99(3) €15M / 3% deployer cascade.

Aggregation upward. The twelve-KRI dashboard feeds the ERM scorecard alongside cyber, conduct, operational, financial, and strategic risk views. The audit committee uses the aggregated view for Item 105 risk-factor disclosure, Item 303 MD&A emerging-risk discussion, Item 407 oversight attestation, and the proxy-statement governance section. SEC 2025-2026 staff commentary cites the AI dashboard as a primary evidence stream for disclosed oversight. The CRO's annual letter to the audit committee includes the 4-quarter dashboard as Appendix B; External Audit risk-assessment workpapers reference it as the AI portion of the enterprise risk register.

Key Takeaways

  • The board AI subcommittee dashboard is the 2026 single-pane-of-glass. Twelve KRIs/KPIs in four categories (Portfolio Risk, Compliance Posture, Operational Resilience, Vendor + Supply Chain) on one page, with three-page briefing pack, designed to fit a thirty-minute board slot and roll up into the audit committee's 10-K disclosure preparation. Replaces twelve-deck narratives that cannot survive a regulator-grade defensibility test.
  • Each tile is fully specified. Definition, formula, data source, RAG thresholds tied to AIRA appetite, refresh cadence, owner role, regulatory cross-walk (EU AI Act + NIST AI RMF + ISO 42001 + SR 11-7 + AICPA AI TSC), and worst-case Article 99 penalty exposure. "Amber because consultant judgment" is rejected at the defensibility test.
  • 9 leading / 3 lagging is the defensible ratio. Forward-pointing indicators (inventory growth, heat-map trajectory, TDF currency, ISO readiness, red-team findings, PMM drift, vendor concentration, DDQ currency, AIRA breaches) outnumber backward-pointing (ALE, FRIA closure, Article 73 incidents). A lagging-only dashboard is a post-mortem, not a steering tool.
  • The dashboard ties to the AIRA, the heat-map, and the FAIR ALE. KRI 4 aggregates AIRA breach activity from lesson 074; KRI 3 derives from the lesson 085 heat-map; KRI 2 is the lesson 086 FAIR ALE₉₅ headline number. The three quantitative artifacts together form the defensibility stack.
  • Six anti-patterns kill dashboards. Too many KPIs (>15 breaks readability); lagging-only (no forward steering); static thresholds (calibration drift); no AIRA tie-back (no appetite link); qualitative-only (no evidence test); green-washing / threshold tuning (decoupling from reality). The fix in each case is structural: caps, ratios, sign-off requirements, Internal Audit threshold review, compensation decoupling.
  • Cadence is quarterly to board, monthly to AIGC, weekly to owners. Emergency-refresh triggers (Article 73 incident; AIRA red breach >7d; ISO 42001 Major Finding; Tier-A vendor SOC 2 qualification; substantial-modification on Tier-1; material regulator action; chair request) make the dashboard a steering tool rather than a calendar artifact.
  • Acme Q2 2026 worked example shows two ambers. Vendor concentration 68% above 60% appetite ceiling; red-team findings open >30d severity-weighted 12.4 above 8 appetite. Plan, budget, and operational test are board-AI-subcommittee ratified. The dashboard converts twelve numbers into five board decisions in twenty-four minutes.
  • Aggregation upward into ERM is the integration test. A standalone AI dashboard with no roll-up to top-of-house risk reporting fails the integration test. The dashboard feeds Item 105 / 303 / 407 disclosures, the proxy-statement governance section, the External Audit risk-assessment workpapers, and the SR 11-7-style aggregate model-risk position. The audit committee + ERM linkage is the artifact that demonstrates board-level oversight adequacy.