Your Board Gets Plenty of Information. But Does It Get Assurance?

Why more reporting does not necessarily mean better governance.

Board packs have a habit of growing. Performance reports get longer. Dashboards acquire more measures. Finance reports become more detailed. Operational updates expand. Risk registers grow.

Before long, trustees or non-executive directors can receive hundreds of pages before a meeting.

That can feel like good governance.

The Board is receiving information. Management is reporting. Performance is being discussed. Risks are documented.

But there is a more important question: Does the Board actually have assurance?

Because information, performance reporting and assurance are related, but they are not the same thing. And confusing them can leave a Board simultaneously well-informed and poorly assured.

Information tells you what happened

Operational reporting matters.

It might tell a Board how many people are using a service, how many complaints have been received, which projects are progressing or what management has been working on.

There is nothing wrong with that. The problem comes when activity is mistaken for assurance. Ten staff attending safeguarding training tells the Board that training happened. It does not tell the Board whether people understood it, whether practice changed or whether safeguarding arrangements are effective.

A new policy being approved tells the Board a document exists. It doesn't tell the Board whether anyone follows it.

Resident meetings taking place tells the Board engagement happened. It doesn't tell the Board whether residents influenced anything.

Activity tells you what happened. Assurance helps you understand whether it worked. Performance tells you something different. Then we have performance reporting. Occupancy. Voids. Arrears. Complaints. Safeguarding. Staff turnover. Repairs. Financial performance. Customer satisfaction.

Boards need this information. It allows them to identify trends, exceptions and areas requiring attention.

But performance data still isn't the same as assurance. Imagine a dashboard showing: Complaints: GREEN

What does that actually tell the Board? Fewer complaints than last month? Fewer than target?

Responses within timescale? Good-quality investigations? Customers satisfied with the response?

Learning resulting in service improvement?

A green indicator can provide considerable comfort while answering a surprisingly narrow question.

So perhaps the Board needs to ask something different from:

"What does the number say?" It needs to ask: "What does this evidence allow us reasonably to conclude?"

Assurance starts with "How do we know?"

This is where the governance conversation changes. How do we know services are safe? How do we know customers or residents are receiving the service we say they receive? How do we know financial controls are working? How do we know risks are being managed? How do we know policies are followed? How do we know the culture described by senior leaders resembles the experience of employees and customers?

And one of my favourite governance questions: What evidence would tell us if what we believe isn't true?

That is a very different conversation from receiving an operational update. Management assurance matters. But it shouldn't be the only assurance. Boards should be able to rely substantially upon their executive teams. Governance would become impossible if trustees attempted independently to verify every management statement. But there is a difference between trusting management and designing the entire assurance system around management's view of the organisation.

If the only evidence the Board receives about service quality is a report written by the person responsible for that service, it has information. It may have very good information. But its assurance remains heavily dependent upon one source. Stronger assurance comes from triangulation.

Take complaints. Management might report that complaints are being managed well. What else could the Board see?

• Performance: Are complaints responded to within agreed timescales?

• Customer evidence: What do complainants say about their experience?

• Quality assurance: Do case reviews show consistently good investigations and responses?

• Learning: Are recurring causes being identified and services changing as a result?

• External evidence: Do regulatory findings, Ombudsman decisions, audits or independent reviews tell us anything different?

When those sources point in broadly the same direction, confidence becomes stronger. When they don't, the difference is often where the interesting governance conversation begins.

Your risk register provides a useful test

Take one of the biggest risks on your organisation's risk register. Then ask: What gives the Board confidence that this risk is actually being managed effectively?

A risk register might list controls such as: staff training; policies; supervision; audits; performance monitoring. Those may all be perfectly sensible controls. But the existence of a control isn't evidence that the control works.

The assurance questions are different:

• Did the training improve practice?

• Are policies actually followed?

• Does supervision identify poor practice?

• What did the audits find?

• What is the performance data telling us?

• What are customers or residents telling us?

• Have incidents or complaints exposed weaknesses?

This distinction matters.

Risk → Control → Evidence → Assurance

Without the evidence stage, a risk register can unintentionally create confidence based upon the existence of processes rather than their effectiveness.

Customer voice isn't an optional extra. It is evidence. This matters particularly in organisations delivering services directly to people. Customer or resident voice can sometimes sit separately from the serious governance business:

• A resident story at one meeting.

• A satisfaction report at another.

• An engagement update somewhere else.

I think that misses its potential value. Customer evidence is part of the assurance framework.

If management reports that a service is performing well but residents consistently describe a different experience, the Board has an assurance gap. If complaints reveal recurring problems invisible in the dashboard, the Board has an assurance gap.

Equally, if satisfaction is very high but the organisation only hears from a small and unusually engaged group of customers, the Board should understand that limitation too. So the question moves beyond: "Do we hear the customer voice?" to: "How does customer evidence influence the conclusions we reach about service quality?"

That is a much stronger governance question. More information can actually make assurance harder

This sounds counterintuitive.

Surely more information is better?

Not necessarily. Huge Board packs can create their own governance problem. Important issues become buried. Trustees spend limited preparation time reading operational detail. Meetings become dominated by explaining reports rather than discussing their implications. Questions focus on individual numbers rather than patterns. And strategic risks receive ten minutes because forty minutes disappeared discussing operational activity.

A Board can be surrounded by data and still lack the evidence it needs to govern confidently. The test shouldn't therefore be: "Have we given the Board everything?" It should be: "Have we given the Board what it needs to govern?"

Those are very different standards.

Assurance should be proportionate

None of this means every organisation needs an internal audit department, a complicated three-lines model or consultants independently reviewing everything. A small charity should not attempt to replicate the assurance architecture of a large housing association or listed company.

Assurance should reflect the organisation's size, complexity, regulatory environment and, most importantly, its risks. The objective isn't bureaucracy. It is appropriate confidence based on evidence.

And smaller organisations may need to think particularly carefully about this because their knowledge and controls can be concentrated among a relatively small number of people.

Five questions I would ask a Board

If I wanted to understand quickly whether a Board was receiving information or meaningful assurance, I would ask:

1. What are the five things that could most seriously prevent this organisation achieving its objectives?

2. What evidence gives you confidence those risks are being managed effectively?

3. Which of that evidence comes from somewhere other than the management team responsible for the activity?

4. Where has the evidence contradicted what you thought you knew about the organisation?

5. What has the Board changed, challenged or escalated because of the assurance it received?

The fifth question matters.

Because assurance that never influences governance risks becoming just another reporting exercise.

The aim isn't certainty

No Board can know everything happening inside an organisation. Nor should trustees attempt to manage it themselves. The purpose of assurance isn't to eliminate uncertainty.

It is to give the Board reasonable confidence that the organisation understands its significant risks, has appropriate controls and can identify when those controls are not working.

That requires more than reports. It requires a deliberate relationship between:

Risk → Controls → Evidence → Assurance → Board challenge → Action

So perhaps the question to ask at the next Board meeting isn't:

"Are we receiving enough information?" It is: "What are we confident about, why are we confident about it, and what evidence might prove us wrong?"

The answer may tell you considerably more about the quality of your governance.

Further reading and sources

Financial Reporting Council – UK Corporate Governance Code 2024

https://www.frc.org.uk/library/standards-codes-policy/corporate-governance/uk-corporate-governance-code/

National Housing Federation – Code of Governance 2020 https://prod.housing.org.uk/publications/code-of-governance-2020/

Regulator of Social Housing – regulatory standards and Sector Risk Profile https://www.gov.uk/government/collections/sector-risk-profiles

https://www.gov.uk/government/collections/regulatory-standards-for-landlords

Charity Governance Code 2025 https://www.charitygovernancecode.org/

Previous
Previous

Customer Voice Isn't a Survey: Are You Listening to Everyone, or Just the People Who Speak the Loudest?

Next
Next

Supported Housing Regulation is Coming: Are Smaller Providers Preparing or Just Waiting for the Regulations?