78 percent of European executive committees say they check their risk dashboard at least weekly, against 41 percent in 2021 (Gartner GRC Technology Survey, 2025, n=312). Maturity is rising. The problem: across 89 incident files handled by European authorities between January and December 2025, 61 percent occurred in organisations whose internal compliance score was above 80 percent at the time.
The dashboard did not fail because it was missing. It failed because it showed what teams wanted to see rather than what they needed to see. This article sets out the architectural error that makes most risk dashboards useless in a crisis, and actively misleading as a decision tool.
The age of false regulatory comfort
NIS2, DORA, GDPR, CSRD: the European regulatory corpus tripled in documentary surface between 2021 and 2025. For a mid-sized financial entity under DORA, that means 47 control requirements to document, 12 distinct annual reports, and mandatory operational resilience testing every three years. DORA has also required, since January 2025, a quarterly board report on operational resilience (Article 11). Reporting pressure is real and growing.
GRC platforms answered with what the market asked for: elegant interfaces, percentage scores, coloured pie charts. Those tools do not lie. They answer the wrong question. The question asked is "what is our compliance level today?" The useful question is "which control failures would expose us to a sanctionable incident within 90 days?"
The result of that framing: organisations buy dashboards that display an aggregate compliance score with no correlation to their actual risk exposure. It is the equivalent of a car dashboard reading "vehicle in good condition" by averaging oil consumption, tyre pressure and outside temperature, without separating what can wait for a service from what strands you within 48 hours.
The architectural error: lagging against leading indicators
Most risk dashboards are built on lagging indicators: compliance rate on a given date, number of validated controls, percentage of treated risks. Those metrics measure what happened, not what is about to.
For a GRC director, the useful question is not "what was our NIS2 score on 31 March?" but "how many critical controls have been overdue for remediation for more than 30 days?" The distinction matters: the first is a photograph, the second is a predictive signal.
Three leading indicators belong on an effective dashboard. Remediation speed: median time between identifying a control gap and closing it. An organisation at 75 percent closing gaps in 8 days is less exposed than one at 85 percent whose critical gaps have stayed open for 45. Risk concentration: an aggregate 80 percent can hide three critical controls sitting at 30 percent inside the DORA perimeter. Third-party exposure: 43 percent of DORA incidents in 2024 originated with a critical provider, not with the audited entity. A dashboard without integrated third-party monitoring covers at most 57 percent of the real risk surface.
The aggregation trap
Aggregation is the enemy of risk governance. When you compute a NIS2 compliance score of 82 percent, you merge 47 controls of different weight into one number. A "documented security policies" control counts as much as a "24-hour incident notification procedure" control, even though their regulatory impact is not remotely comparable.
A concrete case: a mid-sized financial services firm displayed a NIS2 score of 83 percent in January 2025. Post-incident analysis showed that the three controls covering critical incident notification, the 24-hour NIS2 obligation, had never been tested operationally. Aggregate score: 83 percent. Real risk: sanctionable non-compliance on the point regulators watch most closely.
The answer is not to drop aggregation. Boards need a readable summary. The answer is two layers: a summary indicator weighted by regulatory criticality, and a drill-down view on the five to ten most exposed controls. Those controls are what validates or invalidates the headline number.
What an effective dashboard shows
Four design principles separate a governance tool from a communication tool. Organisations applying them report on average 40 percent fewer "surprises" in regulatory audits, cases where the internal score did not match what inspection found (Gartner GRC Technology Survey, 2025).
One: weighting by regulatory criticality is not optional. Controls do not carry equal sanction risk. NIS2 and DORA notification obligations (24h/72h) must weigh structurally more than documentation obligations. A dashboard that treats all controls equally amplifies small wins and hides critical risk.
Two: movement matters more than position. Last month's score is less useful than the 90-day trajectory. A score of 74 percent rising three points a month with documented actions is less risky than a score of 85 percent flat for six months with no visible remediation. Stationary is a warning, not an assurance.
Three: third parties belong inside the score, not beside it. Monitoring critical suppliers is not a separate module. It is a dimension of the main DORA compliance score. A third-party risk register decoupled from the main dashboard creates two parallel truths that nobody reconciles before an audit.
Four: the audit trail must be visible at board level. DORA Article 11 requires traceability of remediation decisions. A dashboard without a timeline of decisions and their owners is not a governance tool. The difference shows the day a regulator asks who decided to defer a critical control by 30 days.
Assessing your own design
Before funding a rebuild, put three questions to your current dashboard. Does it show remediation speed, or only completion rate? Does it weight notification controls differently from documentation controls? Does it fold your critical providers' scores into your own risk perimeter? Two "no" answers out of three mean your dashboard is showing a partial reality.
Presidio is built on these four principles: weighting by regulatory criticality, remediation speed tracking, third-party monitoring folded into the main score, and a board-level audit trail aligned with DORA Article 11. See Presidio →
Conclusion
Risk dashboards are not at fault for the incidents they reveal. They are at fault for the ones they hide. Lagging indicators measure the past, not the future. Unweighted aggregation turns critical risks into reassuring averages. And third-party monitoring belongs in the main perimeter, not in an optional module.
Organisations that perform on compliance are not the ones with the highest scores. They are the ones that designed their dashboard to surface real risk rather than confirm existing convictions.
In your context: is your risk dashboard built to reassure you, or to protect you?
