Risk reporting that gets leadership to act
At a recent webinar on risk reporting, product expert Lone Forland presented participants with the following statement:
"Based on identified control weaknesses in our third-party risk management, I recommend that we launch a structured supplier audit cycle to mitigate residual risk outside our risk appetite. This will, of course, require the allocation of budgetary resources."
Our CEO, Martin Jønck, laughed and replied wryly: "I've brought my credit card today, because I'm more than ready to mitigate risk and run the card through on every initiative you've prepared for us today."
Lone turned to the camera: "A conversation like that has never once taken place. Because what I just read out isn't how you talk to your leadership about risk management. In fact, it's not really how you talk to anyone about anything."
The point hit home: the sentence was technically correct — and completely incomprehensible to anyone outside the GRC function. That's what a lot of risk reporting sounds like the moment it leaves the GRC function.
Watch the full webinar recording here.
Leadership buy-in is not optional
It's tempting to treat leadership buy-in as something you hope to achieve — not something the frameworks actually require. But several of the frameworks NorthGRC's customers work with require it explicitly.
Article 20 of NIS2 requires the management body of essential and important entities to formally approve cybersecurity risk management measures. They must also actively oversee their implementation. That responsibility cannot be delegated away, and failing to comply can result in personal liability.
Article 5 of DORA goes even further for financial entities: the management body must define the organisation's risk appetite, approve the ICT risk management framework and bear overall responsibility for it. The accountability principle in the GDPR is built on the same logic for data protection.
ISO 27001:2022 clarified the same point in clause 5.3 on organisational roles and responsibilities — but the principle itself isn't new. The standard has made clear since 2013 that top management retains overall responsibility for information security, even when the day-to-day work is delegated to specialists.
The pattern repeats across the frameworks: risk management can no longer sit solely with "the most capable person in IT." It has to be reported to, and owned by, leadership — which assumes that leadership actually understands what they're being shown.
Agree on scope before you present
The most common mistake happens long before anyone opens a presentation: skipping the conversation about what actually matters to the business.
Martin Jønck's advice is to find a sponsor first: someone who already knows the organisation's goals and strategic priorities, and with whom you can have an initial conversation about what's genuinely critical to the business. Depending on the size of the company, that might be the CEO themselves; in a larger organisation it's typically a CFO, a sales director or an HR partner. What matters is understanding of the goals, not title or seniority.
That conversation narrows the scope quite naturally. Left to their own devices, risk managers tend to assess everything — every supplier, every system, every process — because everything feels a little bit critical. Once the organisation's real goals are clear, it typically narrows down to three or four genuinely critical areas. An ERP outage a haulage company can live with for a day might be unacceptable within a few hours for a B2B SaaS business — how much downtime you can tolerate depends entirely on what the business actually needs to keep running.
Getting this clarity early does two things. It gives you a clear defence for any risk finding down the line — "you said this was what mattered, so that's what I measured" — and it saves you weeks spent assessing something no one with decision-making authority considered critical in the first place
What risk appetite actually means
Once scope is in place, the next conversation is risk appetite — and it's harder than it sounds, because the immediate reaction is always "zero risk."
Jønck compares it to home contents insurance: no one actually insures against every conceivable loss, because the premium for zero exposure doesn't exist within any realistic budget. Instead, you set an excess you can bear yourself and insure everything above it. Risk appetite works the same way — it's the threshold above which the organisation wants formal oversight, not below.
In practice, that threshold often ends up as a red-amber-green risk matrix — the most common way of visualising risk levels in a report. The pitfall is trying to express the threshold through colour alone. Everyone in the room reads the scale differently, and the moment it goes up on screen, someone will always ask what separates amber from red — a conversation that eats into the time set aside for decisions. A clearer approach ties the colour to a concrete measure: impact above a stated amount, downtime beyond a stated number of hours, recovery time beyond a stated threshold. Colour can still support the picture — it just shouldn't carry the whole argument on its own.
Quit the compliance language
Even with scope and risk appetite in place, the report itself can still lose the room — usually because of language no one outside the GRC function speaks day to day.
Lone Forland's advice is clear: the technical method — confidentiality, integrity, availability, residual risk, likelihood-impact matrices — belongs in the assessment work itself, not in the report to leadership. It helps you analyse the risk. It doesn't help anyone make a decision.
The problem isn't unique to GRC — every specialist function does the same thing. Forland's practical test: read through each sentence and ask yourself whether a twelve-year-old could follow it. If not, rewrite it — or, as she suggested, run it through an AI assistant first and ask for a version everyone in the business would understand.
Ready to see it in action?
Watch the webinar recording for the full walkthrough of scope, risk appetite and presentation technique from Lone Forland and Martin Jønck.
Say less — say what matters
The last element is what actually makes it into the presentation itself — and the urge to include everything is usually what trips you up.
Most risk managers get a narrow window with leadership — five, ten, maybe seven minutes in a meeting that also covers sales, IT and half a dozen other topics. Trying to cover the entire risk landscape in that time means the few decisions that actually require a yes or no get drowned out by everything else.
The solution: choose the one, two, or at most three findings that genuinely require budget or a decision, and roll the rest into a single line — "everything else is green and amber, no action needed" — ready to be expanded on if someone asks, but not included in what you show.
The same logic applies to what you show on screen. If it's packed with every single risk, every colour and every caveat, it forces the audience to read instead of listen. Move the supporting detail to a handout or speaking notes instead, and use what you show for nothing but the three topics, at most, that require a decision today.
Getting started: Your next report, step by step
- Find a sponsor who knows the organisation's real strategic priorities — you need someone to hold scope up against, not necessarily the CEO themselves.
- Agree on scope and risk appetite in plain business language — an amount, a number of hours, a recovery time — before you carry out the assessment, not afterwards.
- Translate the language. If a term wouldn't survive the twelve-year-old test, rewrite it — or run it through an AI assistant first.
- Limit the presentation to your one to three most important findings. Anything already green or amber gets one summary line — not space in what you show.
- Practise the delivery. It's the least exciting advice in the toolbox — and still the one that works.
Getting scope and language right is only half the job — the other half is having the data ready to back it up the moment someone in the room asks a follow-up question. This is where a joined-up risk picture really pays off: when every asset, every supplier and every finding is already linked to the same risk landscape, next month's report stops being a scramble, and "why does this matter to us" no longer means a separate trawl through last year's spreadsheets.
See leadership-ready reporting
See how NorthGRC converts risk data into actionable executive reports—without the hassle of manual spreadsheet consolidation.
Read more about how a unified risk landscape links assets, suppliers and findings in one overview.
Continue your journey with NorthGRC:
