rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/board-compliance-reporting-what-directors-need
Printed 28 August 2026
Board and committee compliance reporting: what a report to directors must contain
The standing components of a board compliance report: status, breaches, regulatory change, assurance results, escalation thresholds and the minute.
What the report is for
A board compliance report exists so that directors can demonstrate they informed themselves about the entity's compliance position and acted on what they were told. It is the primary evidence that oversight occurred.
That framing determines the content. The report is not a status update for the compliance function's benefit, and it is not an assurance that everything is fine. It is a record that specific matters were placed before the board on a specific date, in enough detail for a reasonable director to act.
Directors' duties supply the standard. The duty to exercise care and diligence under section 180 of the Corporations Act 2001, and the associated business judgment rule, are examined in directors' duties and the business judgment rule. The ASX Corporate Governance Council Principles set expectations for listed entities on risk oversight and reporting; for charities, ACNC Governance Standard 5 places duties on Responsible People that the board pack is used to evidence.
The nine standing components
A board compliance report that meets the test carries nine components. The order matters less than the completeness.
| # | Component | What it contains | Why directors need it |
|---|---|---|---|
| 1 | Position statement | A short, plain statement of the overall compliance position, including anything the board should know before reading further | Prevents burying material matters at page nine |
| 2 | Obligations status | New or amended obligations assessed since last report; open gaps with owners and target dates | Shows the obligations register is maintained |
| 3 | Lodgement and deadline status | Periodic obligations due in the period, completed on time, late, or missed | The most testable single indicator of program health |
| 4 | Incidents and breaches | Events logged, notifications made, clocks met or missed, events still open | Evidence the board was told, and when |
| 5 | Monitoring and assurance results | Tests completed against plan, exceptions, repeat findings | Distinguishes tested controls from assumed ones |
| 6 | Issues and remediation | Open issues by rating and ageing, overdue items named | Directs the board to where action is needed |
| 7 | Regulatory change | Instruments commenced, amended or announced; impact assessment; anything labelled proposed and not yet legislated | Forward view rather than rear-view mirror |
| 8 | Regulator interaction | Correspondence, notices, inspections, information requests, enforcement | Directors should never learn of a regulator contact from outside |
| 9 | Resourcing and capability | Whether the program has the people, budget and systems to do what the board approved | Removes the "we were never told" defence in both directions |
Component 9 is the one most often omitted and the one that most protects the compliance function. A board that has been told resourcing is inadequate has made a decision; a board that was never told has not.
A reporting calendar matched to the obligations
Not every component belongs in every pack. Set a calendar so that the depth rotates while the standing items appear each time.
| Item | Frequency | Notes |
|---|---|---|
| Position statement, incidents, lodgement status, open issues | Every meeting | The standing core |
| Monitoring results | Quarterly | Aligned to the monitoring plan cycle |
| Regulatory change assessment | Quarterly | Monthly intake, quarterly reporting |
| Obligations register review outcome | Quarterly, with an annual full refresh | Register version tabled at the annual refresh |
| Policy suite status | Semi-annual | Documents overdue for review, named |
| Independent assurance reports | As received | Tabled in full, not summarised away |
| Program plan and resourcing | Annual | Approved alongside the monitoring plan |
| Attestation or compliance certification | Annual | Where a regime or contract requires it |
Aligning the calendar to the compliance calendar and the national dates at /deadlines prevents the common failure where a lodgement deadline falls between board meetings and is never reported either side of it.
Writing for directors, not for the compliance team
Directors read many packs and have limited time. Four rules improve the record materially:
- Lead with the exception. Directors need to know what is wrong first. A report structured as achievements followed by issues invites the issues to be skimmed.
- Quantify consequence, not activity. "Fourteen controls tested" tells a director nothing. "Two of fourteen tests failed, both on the same manual reconciliation, exposure is a late lodgement penalty and a licence condition" tells them what to decide.
- Name the decision required. Every item should be marked as for noting, for discussion, or for decision. Items marked for decision should state the options.
- Avoid regime jargon without a translation. Section numbers and standard references belong in the detail, not in the summary line. Where a technical maximum penalty matters, cite it and stamp the date checked; the penalty estimator provides maximum ranges from the corpus.
Length discipline helps. Two pages of summary with appendices beats fifteen pages of undifferentiated narrative, because the summary is what ends up reflected in the minute.
Escalation: what goes to the board immediately
Some matters cannot wait for the next scheduled report. Define the thresholds in the compliance policy so that escalation is a rule rather than a judgement call made under pressure.
Immediate escalation should be triggered by:
- Any event that starts a statutory notification clock — data breach assessment, work health and safety notifiable incident, cyber incident reporting under the critical infrastructure regime, reportable situations under the financial services regime.
- Any regulator contact that is not routine correspondence: a compulsory information notice, an inspection, an enforcement inquiry.
- Discovery that an obligation has been unmet over an extended period, regardless of individual materiality.
- A control failure affecting customer money, personal information, or safety.
- Loss of a licence condition, accreditation or certification, or a notice threatening one.
- Any matter the compliance function believes should go to the board — an unqualified right that should be written down.
Escalation should be recorded even where the board takes no action. The record that the board was informed on a given date is the artefact that matters; see incident and breach registers for how the underlying event record links to it.
Minutes, packs and the evidentiary value of the record
The pack and the minute do different jobs. The pack shows what the board was given; the minute shows what the board did with it.
A minute that supports the oversight record includes:
- The document tabled, by title and version.
- The substance of the discussion, particularly any questions asked and answers given. Questions asked are the strongest available evidence of engagement.
- Any decision, with the resolution wording and the date it takes effect.
- Actions arising, with owners and due dates.
- Where the board accepted a risk or deferred remediation, the reasons.
"The compliance report was noted" is a weak minute. It establishes that a document existed and nothing more.
Retention matters as much as content. Board packs and minutes should be retained for at least the period applying to the records they discuss — seven years is a common working baseline for corporate records, with longer periods for specific regimes. Version-controlled packs allow the board to establish what it knew and when, which is precisely the question asked when something goes wrong.
Weaknesses that recur in SMB board reporting
- Reporting activity instead of position. Counts of tasks completed, with no statement of whether obligations are being met.
- No regulatory change section, so the board only ever sees obligations after they have commenced.
- Verbal escalation. A material matter raised in conversation and never written down, leaving no record either that it was raised or that the board considered it.
- Assurance reports summarised rather than tabled, so directors never see the findings in the assessor's own words.
- No ageing on open issues. A list of twelve open issues means nothing without knowing that four have been open for over a year.
- Resourcing never reported, so a program known internally to be under-resourced is never a board decision.
- Same report every meeting. If the pack does not change, directors stop reading it, and the evidentiary value of tabling it falls away.
Frequently asked
How often should a board receive a compliance report?
At every scheduled board meeting, with a standing core of position statement, incidents and breaches, lodgement status and open issues. Deeper components — monitoring results, regulatory change assessment, register review outcomes, policy status — rotate on a quarterly or semi-annual cycle. Matters meeting the escalation thresholds go to the board immediately rather than waiting for the next meeting.
What should trigger immediate escalation to the board?
Any event starting a statutory notification clock, any non-routine regulator contact such as a compulsory notice or inspection, discovery of a long-running unmet obligation, a control failure affecting customer money, personal information or safety, and any threat to a licence, accreditation or certification. The compliance function should also hold an unqualified right to escalate anything it considers material, written into the policy.
Should the compliance report go to the board or to a committee?
It depends on structure. Where an audit and risk committee exists, detailed reporting usually goes there with a summary and escalated matters to the full board. In businesses without committees the full board receives the report directly. What matters is that the delegation is documented in the board or committee charter and that escalated matters reach the full board regardless.
What makes a board minute defensible on a compliance matter?
It records the document tabled by title and version, the substance of the discussion including questions asked, any decision with its resolution wording, actions with owners and due dates, and the reasons where the board accepted a risk or deferred remediation. A minute reading only that the report was noted establishes that a document existed and nothing more.
Should resourcing be reported to the board?
Yes, and it is the component most often left out. A board that has been told the program lacks the people, budget or systems to do what it approved has made an informed decision. A board that was never told has not, which weakens the position of both the directors and the compliance function if the program later fails.
Related
Related reading
Directors' duties under s 180 and the business judgment rule
How the business judgment rule protects directors under s 180 of the Corporations Act: who it covers, the four conditions, timing, and common pitfalls for AU boards.
ASX Corporate Governance Council Principles and Recommendations (4th Edition)
The 4th edition of the ASX Corporate Governance Principles took effect for financial years starting on or after 1 January 2020 with 8 Principles and 35 recommendations, disclosed under Listing Rule 4.10.3 on an 'if not, why not' basis.
Compliance monitoring and assurance plans: designing testing that proves the controls work
Building an annual compliance monitoring plan: design vs operating effectiveness, what to test and how often, sample sizes, and recording results.
Incident and breach registers: capturing, escalating and closing compliance events
Running one incident and breach register: the fields that matter, the statutory clocks that start on logging, escalation thresholds, closure and retention.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/board-compliance-reporting-what-directors-need