Most compliance functions report the same set of metrics to their board committees every quarter — number of breaches, training completion rates, policy attestations — regardless of whether those metrics actually help the committee make a decision. I'd argue most of them don't.
A metric is useful to a governance committee if it changes what the committee would do next. Training completion rates rarely meet this bar — a completion rate of 94% versus 97% doesn't usually change anything a committee would decide, yet it's reported with the same prominence as metrics that genuinely should change committee behaviour.
The compliance functions I've seen operate most effectively report a smaller set of metrics, chosen specifically because they're decision-relevant: which controls are showing early degradation signals, which regulatory changes require a resourcing decision this quarter, which risk exposures have moved meaningfully since the last report. Everything else moves to an appendix, available but not driving the conversation.
This requires compliance leadership to make an editorial judgment about what matters, which is a less comfortable position than reporting a comprehensive, defensible metrics pack that covers everything. But comprehensive reporting that doesn't drive decisions isn't actually serving its governance purpose — it's serving a documentation purpose, which is a different thing with a different audience.
If a compliance report couldn't plausibly change a single decision the committee makes this quarter, it's worth asking why it's being presented at all, and whether the function's time would be better spent on the smaller number of metrics that actually could.