Exec Narrative Patterns
Different readers want different things. The same findings should not land the same way in a board deck, a CISO 1:1, and a regulator response.
Audience quick reference
| Audience |
Length budget |
Opening line wants |
Technical depth |
What they skip |
| Full board |
1 page max |
Strategic posture one-liner |
Low. No control IDs in body. |
Operational detail, acronyms, tables with >5 rows |
| Audit committee |
2 pages |
Risk-and-assurance posture |
Medium. Control families OK, not IDs. |
Strategy monologue, vendor names unless load-bearing |
| Risk committee |
2 pages |
Residual risk movement |
Medium-high. Framework names, risk scoring. |
Program branding, tool selection detail |
| CEO weekly |
Half page |
What changed, what's blocking, what's asked |
Low. Translate everything. |
Framework politics, tool comparisons |
| CISO weekly |
1 page |
What moved, what's blocked, what's next |
High. Control IDs, tool names, owner names fine. |
Over-explained context |
| Regulator / auditor |
As long as needed |
Precise scope + evidence |
Maximum. IDs, artifact paths, timestamps. |
Narrative softening |
Tone rules
Board and audit committee
- Past tense for what happened. Present tense for posture. Future tense only for asks.
- Numbers must be honest. Round where range matters more than precision. "Roughly 80%" beats "82.3%" if the instrument is noisy.
- Never start with control IDs. Start with impact.
- Name one person accountable per open item. Anonymous ownership reads as no ownership.
CEO weekly
- Assume 90 seconds of attention.
- Lead with the delta from last week. If nothing changed, say that.
- Asks come with the decision you want, not the full context. Attach the context.
CISO weekly
- Peer tone. You share context with the reader.
- Bullets, not paragraphs.
- Owner names and dates are load-bearing.
Regulator / auditor
- Precision. Timestamps, scope statements, evidence paths.
- Tone is neutral, not defensive. The facts do the work.
Format conventions
- Headline row: one sentence, no hedging. If the week was quiet, the headline says so.
- Tables beat prose for multi-framework status. Prose beats tables for narrative arcs.
- Appendix is where detail lives. Body stays clean.
- Dates are
YYYY-MM-DD. Periods are YYYY-Q# or YYYY-W##.
Length tests
If you cannot defend every sentence as "the audience needed this to make a decision," cut it.
If the document opens with context before the point, invert it.
If there are three open items and no ask, you are reporting, not communicating. Add the ask.
1---2name: exec-narrative-patterns3description: Audience-specific tone and format guidance for leadership communications. Use when drafting any /report:* output to tune length, framing, and technical depth to the reader (board, audit committee, CEO, weekly CISO, regulator).4---56# Exec Narrative Patterns78Different readers want different things. The same findings should not land the same way in a board deck, a CISO 1:1, and a regulator response.910## Audience quick reference1112| Audience | Length budget | Opening line wants | Technical depth | What they skip |13| --- | --- | --- | --- | --- |14| Full board | 1 page max | Strategic posture one-liner | Low. No control IDs in body. | Operational detail, acronyms, tables with >5 rows |15| Audit committee | 2 pages | Risk-and-assurance posture | Medium. Control families OK, not IDs. | Strategy monologue, vendor names unless load-bearing |16| Risk committee | 2 pages | Residual risk movement | Medium-high. Framework names, risk scoring. | Program branding, tool selection detail |17| CEO weekly | Half page | What changed, what's blocking, what's asked | Low. Translate everything. | Framework politics, tool comparisons |18| CISO weekly | 1 page | What moved, what's blocked, what's next | High. Control IDs, tool names, owner names fine. | Over-explained context |19| Regulator / auditor | As long as needed | Precise scope + evidence | Maximum. IDs, artifact paths, timestamps. | Narrative softening |2021## Tone rules2223**Board and audit committee**2425- Past tense for what happened. Present tense for posture. Future tense only for asks.26- Numbers must be honest. Round where range matters more than precision. "Roughly 80%" beats "82.3%" if the instrument is noisy.27- Never start with control IDs. Start with impact.28- Name one person accountable per open item. Anonymous ownership reads as no ownership.2930**CEO weekly**3132- Assume 90 seconds of attention.33- Lead with the delta from last week. If nothing changed, say that.34- Asks come with the decision you want, not the full context. Attach the context.3536**CISO weekly**3738- Peer tone. You share context with the reader.39- Bullets, not paragraphs.40- Owner names and dates are load-bearing.4142**Regulator / auditor**4344- Precision. Timestamps, scope statements, evidence paths.45- Tone is neutral, not defensive. The facts do the work.4647## Format conventions4849- Headline row: one sentence, no hedging. If the week was quiet, the headline says so.50- Tables beat prose for multi-framework status. Prose beats tables for narrative arcs.51- Appendix is where detail lives. Body stays clean.52- Dates are `YYYY-MM-DD`. Periods are `YYYY-Q#` or `YYYY-W##`.5354## Length tests5556If you cannot defend every sentence as "the audience needed this to make a decision," cut it.5758If the document opens with context before the point, invert it.5960If there are three open items and no ask, you are reporting, not communicating. Add the ask.