The Board Was Told, and Still Could Not See It

In April, the Office of the Auditor General of Canada published a special examination of a federal Crown corporation and found a significant deficiency in workplace health and safety, including a hazard prevention program whose effectiveness had not been fully evaluated since 2010 - since 2018 for conservation officers. That alone is a serious finding. But the sentence that should trouble every board sits just after it: the board had been informed of the non-compliance through an internal audit, yet this information was not included in the annual health and safety report, limiting the board's ability to oversee these risks.
Read that carefully, because it describes a failure mode almost every governing body has experienced without naming it. The information existed. It had been generated internally, by the organization's own assurance function. It had even reached the board once. And it still did not arrive in the place where the board actually does its oversight work - the recurring report against which directors ask their questions, form their view, and create the record of having governed. Boards do not oversee an organization through everything they have ever been told. They oversee it through the small set of documents that arrive on a schedule. If something is not in those documents, then for governance purposes it is not in front of the board, however many times it was mentioned somewhere else.
Recent context
The finding is public. The Auditor General of Canada reported on 20 April 2026 on a special examination of the National Capital Commission, a federal Crown corporation. The examination found a significant deficiency related to workplace health and safety: the corporation had not complied with key federal requirements, including regularly evaluating and updating its hazard prevention program, whose effectiveness had not been fully evaluated since 2010 (2018 for conservation officers). Crucially, the audit noted that the board had been informed of the non-compliance through an internal audit, but that this information was not included in the annual health and safety report, limiting the board's ability to oversee these risks. Improvements were also identified in areas including asset maintenance, capital project management, board oversight, performance measurement and reporting, and risk identification.
The reporting chain is a records system, whether you designed it or not
Every board is served by a reporting chain: someone decides what goes into the quarterly package, what gets summarized, what is attached, what is escalated and what stays in the operational layer. In most organizations, nobody ever designed that chain. It accumulated. A template was written years ago by a person who has since moved on, and it has been filled in the same way ever since, which means it faithfully reports the risks that mattered in the year it was drafted. New findings from internal audit, regulatory correspondence, condition assessments and project exceptions all have to find their way into a structure that was never updated to expect them - and when they do not fit, they are mentioned once, verbally or in a separate memo, and then quietly leave the governance record. The result is a board that is simultaneously well-informed and unable to demonstrate oversight, which is the worst of both worlds: directors who knew, and a record that cannot show they were positioned to act. The fix is unglamorous and entirely within a board's control - treat the reporting package as a governed record with defined inputs, and require that anything raised through assurance channels is reconciled into it rather than allowed to disappear.
How XNM helps
XNM works with Crown corporations, provincial agencies and other public-sector boards on exactly this seam - the point where operational records become governance records. The practical work is to make the reporting chain explicit and traceable: defining what must flow into each recurring board report, connecting findings, assessments and project exceptions to the report they belong in, and keeping the trail of what was reported, when, and on what basis. Where it fits, XNM-Vision holds that record as a command centre, so a director can see not only the current package but the evidence behind it, and a corporate secretary can demonstrate that what assurance raised is what the board received. XNM brings the governance discipline alongside it - because the difference between knowing and being able to show you governed is, in an audit, the whole difference.
Practical takeaways
Ask what did not make it into the package. The most useful question a director can ask is not about the report's contents but about its exclusions - what was raised this quarter through any channel and did not appear here?
Define the inputs to each recurring report. If nobody has written down what must flow into the annual safety, risk or capital report, then its contents depend on the memory and judgment of whoever assembles it.
Reconcile assurance findings into governance reporting. An internal audit finding that is briefed once and never lands in a standing report has left the governance record - require an explicit reconciliation.
Date the last full evaluation of every program you rely on. Programs decay silently; a simple register of when each was last evaluated turns an invisible gap into a visible, actionable one.
Keep the evidence trail with the report. Being told is not the same as being able to show you were told - the record of what the board received, and when, is what an examiner will actually test.
FAQ
Our board is briefed thoroughly, including verbally. Isn't that oversight?
Briefing is how directors become informed; the reporting record is how the organization demonstrates they were positioned to govern. An examiner assessing board oversight works from documents - what was provided, when, and what it contained. A verbal briefing that never lands in a standing report leaves no trace that survives a change of directors, a change of management, or an audit three years later. Both matter, but only one of them is durable.
Isn't this just more reporting burden on management?
It is usually less, not more, because the burden in most organizations comes from assembling reports from scratch each cycle and then answering follow-up questions the package did not anticipate. Defining the inputs once and keeping the underlying record current converts recurring reporting into an extract. The effort moves from production to design, and design is a one-time cost.
The bottom line
The uncomfortable lesson in that special examination is not that a board was kept in the dark. It is that the board was told, and the governance record still could not show it. Directors are accountable for oversight they can evidence, and evidence lives in the reporting chain rather than in anyone's recollection of a meeting. Boards that want to avoid this finding should stop asking only what is in the package and start asking what should have been - and then make sure the answer is written down somewhere it cannot quietly fall out of.


