Solutions · Reporting and dashboards

Five audiences. Five questions. One dashboard answers none of them

The board wants to know where the exposure is. The regulator wants a control in their own structure. The auditor wants evidence for a sample. The customer wants to know if you are safe to buy from. And the control owner just wants to know what is due this week.

Per audienceDifferent question, different view
Per frameworkIn that framework's own terms
ProducedNot assembled over three days
TraceableEvery number opens to its records
This page reflects how we see compliance reporting used in practice in the Kingdom. It is not an official reference. Submission formats and reporting obligations are set by the relevant authority — confirm what your regulator expects against their published requirements rather than against a general description.

The number everybody asks for

From the compliance programmes we build and run in Saudi Arabia: a single compliance percentage is the least defensible number in this category, and it is the first thing every executive asks for. Not because they are wrong to want a summary — because the summary they are offered hides exactly the information that would change their decision.

Consider what "78% compliant" actually communicates. It does not say which 22% is missing. It does not say whether the missing portion is administrative documentation or the entire access control set. It does not say whether the gap is being worked on or has been open for two years. And it does not say whether the 78% was assessed rigorously or self-declared by the people who own the controls.

An executive who acts on that number is acting on almost nothing. An executive who is told "our exposure is concentrated in three controls, two have named owners with dates, and one has been open since last year" can actually do something — and that sentence takes the same thirty seconds to read.

What a percentage hides
  • Which controls are missing, and whether they matter
  • How long each gap has been open
  • Whether anything is actually being done about it
  • Whether the assessment was rigorous or self-declared
  • Whether evidence behind the "compliant" portion is current
What a board can act on
  • Where exposure concentrates
  • Who owns the remediation, by name
  • What is overdue, and by how long
  • What has been accepted as risk, and by whom
  • What changed since the last time they looked

The right-hand column is longer to produce and shorter to act on. In our experience boards stop asking for the percentage once they have been given the alternative twice — because the alternative answers the question they were actually trying to ask.

Who is actually asking

Each of these needs a different view, and the effort of building one general dashboard is usually greater than building five specific ones.

The boardQuarterly
Are we exposed, and is someone dealing with it?

Concentration of exposure, ownership of remediation, what is overdue, what changed. Not a gauge. A board that receives a percentage asks a follow-up question the pack cannot answer.

The regulatorOn their cycle
Show me this control, in my structure

Their framework, their numbering, their scoring scheme, with evidence attached. A view converted into your internal scheme creates work for them and doubt about you.

The auditorDuring fieldwork
Evidence for these samples, please

Specific artefacts, for specific periods, traceable to the control they support. Speed here is the difference between a smooth audit and a finding about record-keeping.

The customerDuring vendor review
Are you safe to buy from?

Your certifications, your posture, answers to their questionnaire. Largely the same underlying records, presented for an external reader. Trust center →

The control ownerWeekly
What do I owe, and when?

The audience nobody designs for, and the one whose behaviour determines whether any of the others get a true answer. An IT manager owning fourteen controls needs a list, not a dashboard.

Note the last row. Reporting is usually built top-down for executives, and the person who actually produces the underlying reality gets nothing. If the control owner cannot see what is due, the board's view is a well-presented guess.

Produced, not assembled

The test is simple: how long does it take to produce the board pack, and who is blocked while it happens?

In most organisations a quarterly compliance report takes several days. Someone requests status from control owners, chases the non-responders, reconciles conflicting answers, builds slides, and circulates a draft for correction. By the time it reaches the board it describes a state that is a week old, and it consumed the compliance function's most experienced person for that week.

The deeper cost is not the time. It is that a report assembled this way cannot be produced more often than it is painful to produce — so the organisation learns about its position quarterly, and every decision between quarters is made blind.

The symptom

Reporting season

A recognisable period before each board meeting when the compliance team stops doing compliance and starts doing collation. The work does not improve the programme; it describes it.

The cause

State lives in people, not records

If the current status of a control is known only by the person who operates it, every report requires asking them. Collation is the tax you pay for not holding the state.

The consequence

Reports that are already old

A pack describing last week is fine for a trend and misleading for a decision. The board is frequently asked to approve something based on a position that has since changed.

The fix

Read the records you already keep

When control status, ownership, evidence validity and findings live in one place, the report is a view of that data rather than a document built from interviews.

The side effect

Reporting stops being an event

Once producing a view costs nothing, it is produced when someone needs it rather than when the calendar demands it — which is when it starts affecting decisions.

The honest limit

It only works if the data is maintained

A report generated from records is exactly as true as those records. This is not a reporting problem to solve with reporting tools — it is why ownership and evidence discipline matter.

A report is only as true as what is beneath it

Reporting sits at the top of a stack, and inherits every error in the layers below without displaying any of them.

LayerIf it is wrongWhat the report shows
Assets Systems missing from the register Full coverage of an incomplete estate
Risks Risks not linked to assets A list of worries with no way to prioritise
Controls Status self-declared, never verified Implemented, confidently
Evidence Artefacts expired or never reviewed A control that passed a year ago
Findings Closed on assertion rather than verification Resolved, until it reappears next cycle
Reporting All of the above, invisibly A clean dashboard nobody can trust

This is the argument against buying reporting as a standalone capability. A dashboard connected to poor records produces confident wrong answers faster than a spreadsheet does — which is worse, not better, because speed increases the number of decisions built on it.

Reporting in Govrly

Views of records you already maintain, in the terms the person reading them uses.

Per framework

In that framework's own terms

An ECC view scored the way the NCA scores it, a SAMA CSF view in maturity levels, a custom framework in whatever scheme its author uses — not converted into a house scheme that the assessor would not recognise.

Traceable

Every number opens

A figure in a report leads to the controls behind it, and those lead to the evidence and the owners. A number you cannot open is a number you cannot defend when someone questions it.

Ownership

Named, throughout

Reports show who owns what is open, not only that something is open. "Three controls overdue" starts a conversation; "three controls overdue, owned by these two people" ends one.

Control owner view

What I owe, and when

The list for the person operating the control — what is assigned, what evidence is due, what is expiring. The view that keeps the others true.

Across entities

Where structure requires it

For groups, portfolios and ministry systems, coverage across entities while each keeps its own framework and scoring — comparable where comparison is meaningful and separate where it is not.

Change

What moved since last time

The question a board actually asks second. A view that shows only current state makes every meeting start from zero.

Building reporting people use

Start from the question, not from the chart. Almost every unused dashboard was built the other way round.

  1. Write down who asks, and what they askBoard, regulator, auditor, customer, control owner. Five audiences, five questions, in their words rather than yours. This takes an afternoon and prevents a year of unused dashboards.
  2. Start with the control owner viewCounterintuitive, and correct. If owners can see what is due, the underlying data becomes true — and every other report improves without anyone touching it.
  3. Build the regulator view nextIn their structure, their numbering, their scoring. This is the one with a deadline attached, and the one where a conversion error costs most.
  4. Make the board view answer the second questionNot "how compliant are we" but "where is the exposure and who owns it". Give them that twice and the percentage request usually stops.
  5. Make every number traceableIf a figure cannot be opened to the records behind it, it will be challenged once and distrusted afterwards. Traceability is what makes a report survive scrutiny.
  6. Show change, not only stateWhat moved since the last report is the most decision-relevant thing on the page, and the most commonly omitted.
  7. Delete the reports nobody opensEvery programme accumulates them. A dashboard nobody reads costs maintenance and implies coverage that is not being checked.
  8. Fix the records, not the chartWhen a report looks wrong, the problem is almost never the report. Reporting is a symptom layer — the fix belongs underneath it.
What this looks like in Govrly

Each framework reported in its own scoring scheme, every figure opening to the controls, evidence and owners behind it, and a working list for the control owners whose records keep all the other views true.

See it in a demo →

Reporting and dashboards — FAQs

Can we get a single compliance percentage?

You can, and we would advise against relying on it. A percentage does not say which portion is missing, whether it matters, how long it has been open, or whether the compliant portion was rigorously assessed. Where exposure concentrates and who owns the remediation answers the question an executive was actually trying to ask.

Why not one dashboard for everyone?

Because five audiences ask five different questions. The board wants exposure and ownership, the regulator wants their own structure and scoring, the auditor wants specific evidence, the customer wants posture, and the control owner wants a task list. A general dashboard is a compromise that serves none of them well and usually takes more effort than five specific views.

Can we report in our regulator's own scoring scheme?

Yes, and you should. An ECC view scored the way the NCA scores it, a SAMA CSF view in maturity levels, a custom framework in its author's scheme. Converting a regulator's scheme into an internal one creates work for them and doubt about you.

How long should producing a board report take?

It should be a view of records you already maintain rather than a document assembled from interviews. The deeper problem with multi-day collation is not the time — it is that a report which is painful to produce is only produced quarterly, so every decision in between is made without current information.

Our reports look fine but nobody trusts them. Why?

Usually because the numbers cannot be opened. A figure that leads to the controls, evidence and owners behind it survives scrutiny; one that cannot be traced is challenged once and distrusted afterwards. It is also worth checking whether the records underneath are maintained, because reporting inherits every error beneath it invisibly.

Which report should we build first?

The control owner view, which is counterintuitive and correct. If the people operating controls can see what is due, the underlying data becomes true — and every executive and regulatory view improves without anyone editing them.

Can we see across multiple entities?

Yes, where the structure requires it — groups, portfolios and ministry systems. Each entity keeps its own framework and scoring, and coverage is shown across them without averaging incompatible schemes into a number that cannot be defended.

Will a dashboard satisfy our regulator?

No report satisfies a regulator by itself. What a good view does is let you answer them in their own structure with evidence attached, quickly and consistently, rather than assembling that answer under time pressure each time they ask.

What is the most commonly missing element?

Change. Most reports show current state only, so every board meeting starts from zero and nobody can see whether the position improved. What moved since last time is usually the most decision-relevant thing on the page.

Our dashboard shows good numbers but we failed an assessment.

That is reporting inheriting errors from beneath it. Controls marked implemented but never verified, evidence that expired, findings closed on assertion — all of these display as green. The fix is not in the reporting layer, which is exactly why buying reporting as a standalone capability disappoints.

Stop assembling the board pack

See what a view of records you already maintain looks like, in each audience's own terms.