Compliance glossary
Definition

Board / QI Reporting

The annual written report the Qualified Individual must deliver to firm leadership on the status of the information security program.

What it means.

Board reporting (or QI reporting) is the annual written report that the Qualified Individual must deliver to the firm's board of directors, equivalent governing body, or senior officer in charge, summarizing the overall status of the information security program (16 CFR 314.4(i)). The report covers the current state of the program, risk assessment results, incidents during the year, testing and monitoring outcomes, identified gaps, and recommendations for the coming year. Firms with fewer than 5,000 consumer records are exempt from the written report requirement but still benefit from the discipline.

Why it matters for CPA firms.

The board report is the FTC's mechanism for forcing senior accountability. A program nobody reviews tends to atrophy. Producing the report annually surfaces gaps before regulators or insurers do. For small firms with no formal board, the report goes to the managing partner or owner and gets stored alongside the WISP as evidence of governance.

Relevant regulations.

  • 16 CFR 314.4(i)

How Kompflow helps.

The QI Dashboard (Premium) module handles this for your firm, personalized to your software, team size, and state requirements.

See plans and pricing

Related terms.

Ready when you are

Pick where to start.

Buy the WISP yourself if you need the document.
Talk to us if you want the platform.

30-day money-back on Kompflow WISPCancel anytimeNo setup fees on any tier

We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy