Assettia

Data and AI a board can read

Assettia is the data and AI programme record: one place where an organisation keeps what its programme owns, what it has decided, and what it has proved.

Boards are now expected to oversee how their organisations use data and AI, and to be able to show that they did. Most boards receive that oversight as a deck: assembled by hand, current on the day it was written, and impossible to check. This page describes the alternative: a board report produced from the programme's own records, in which every figure can be opened and every decision has a name and a reason beside it.

What a board needs from a data and AI programme

Five things, and the record is built to answer each of them.

  1. 1

    What the programme owns. The data assets, the use cases, the risks, the people involved: a list that is kept, not recalled.

  2. 2

    What has been decided, by whom, and why. Which use cases were prioritised and which were deferred, with the reasoning written at the time.

  3. 3

    What has been proved. Where value has been measured, where a control has been attested, where a claim has evidence behind it.

  4. 4

    What is at risk. The AI risks the organisation carries, the controls in place, and who has signed to say so.

  5. 5

    What is missing. The registers that are still empty and the assessments not yet run, stated as such rather than hidden behind a zero.

The board report, produced from the record

The board report is not written in a word processor. It is generated from the same records the programme runs on, then reviewed and approved by a named person before it is filed with its version number.

Because it comes from the record, three things hold that do not hold for a deck. Every figure names the population it counted, and a director can open it to see the list. The reasons for decisions appear beside the decisions. And a register with nothing in it says so; an assessment not yet run is shown as not yet run.

When a figure changes between one report and the next, the report says so. Nothing is quietly restated.

What the record holds

Assettia

Data and AI Board Report

[Organisation]

[Period] · Prepared from the programme record

Every figure in this report traces to a record. Gaps are shown as gaps.

Questions a director can ask

The record is built so that these questions have answers, and the answers can be checked.

Which use cases are actually delivering value?
The value evidence linked to each use case, and the ones with none.
Why was this use case prioritised over that one?
The scoring against the same criteria, and the decision record with the person and the reason.
What are we exposed to?
The risk register: each risk, its controls, its regulatory reference points, and who attested to it.
Do we know what data we hold and who owns it?
The data asset register, including quality and rights, and which use cases depend on each asset.
What did we say last time, and what changed?
The previous report, filed with its version, and the differences stated.
What don't we know yet?
The empty registers and the assessments not yet run, listed as gaps.

What the board sees, and what it does not

The board sees facts derived from records by fixed rules. It does not see composed opinion presented as fact.

Where a model has helped, it has helped to draft: a summary, a suggested risk, a classification. Nothing a model produced becomes a record until a named person has reviewed and accepted it, and nothing on an executive surface is generated text presented as a finding. The board can rely on the report because the software makes it hard to do otherwise.

How the record works

How it fits the board's rhythm

The report is produced for each board meeting from the record as it stands. Between meetings, the decision log records what was decided and by whom, so the next report begins where the last one ended. Attestations on the risk register are signed by the people accountable for them and dated, so the audit and risk committee can see what was confirmed and when.

Nothing on this page requires the board to use software. The record is kept by the programme; the board reads what it produces.

For the audit and risk committee

The committee's view is the risk register and the attestation record: each AI risk, its controls, its regulatory reference points, and the named sign-off. Where a control has not been attested, the register says so. The committee can ask for the evidence behind any attestation, and the record holds it.

Questions people ask

Does the board need to log in to Assettia?

No. The programme team keeps the record. The board reads the report it produces, on paper or on screen, and can ask the team to open any figure to its population.

Who approves the board report before it is circulated?

A named person on the programme, usually the chief data officer, reviews and approves it. The approval and the version number are filed with the report.

Can the report contain a number that is not in the record?

No. Every figure in the report is computed from records by a fixed rule and names the population it counted. There is no field for typing a figure in.

What happens when a register is empty?

The report says the register is empty. It does not show zero, and it does not omit the section.

How is this different from the deck the board receives today?

The deck is assembled by hand and is correct on the day it was finished. The report is generated from live records, approved by a named person, filed with its version, and every figure in it can be opened and checked.

How can a board see a sample?

In a walkthrough, using a synthetic organisation, so nothing of the board's own organisation is entered until it decides it should be. Request a walkthrough

See how your board would read it.

A walkthrough takes forty minutes and uses a synthetic organisation. It includes a sample board report produced from that organisation's record.