15 Reports
The op-ed you drafted in Chapter 7 travels light: it reaches a commuter or a council member and gets one decision out of them before the next tab loads. The testimony you prepared in Chapter 11 is a timed appearance before a county board, spoken once and entered into the record. The report is a third instrument: long, sourced, designed to be excerpted and cited years later in a brief you will never see. Some institutional reader (a legislative staffer, an agency’s policy advisor, a task force member, an advocacy research director) needs a document they can put in a folder and hand to their counsel. The op-ed is a knock on the door. Testimony is five minutes in the room. The report is the evidence you leave behind.
This is the genre chapter for the assurance module, and its artifact is Piece 3: a report section of about 2,000 words, addressed to a named Colorado state body, built on the disaggregated audit you constructed in Chapter 12 and tested in Chapter 13. The report is where assurance meets its public. An audit that no one with authority reads is a workpaper in a drawer. A report that cannot show its workpapers is audit-washing with footnotes.
15.1 A short political economy of the policy report
The modern policy report sits between academic research and advocacy, funded by foundation grants, occasional government contracts, and a small number of large philanthropic commitments to technology policy. The shops you will cite most (AI Now, Data & Society, EPIC, CDT, Brookings, New America, the Ada Lovelace Institute) calibrate that space differently: AI Now is argumentative, Data & Society explanatory, Brookings academic with a policy preamble. Read three before you write your own.
They share a structure: a short executive summary, findings organized by claim, methods folded in or in an appendix, recommendations aimed at a specific institutional actor, and references. Proportions differ, and they tell you where the authors think the argument lives. Each report also has a reader in mind who is not you. A report that reads as written for a general audience is almost always a worse report.
Non-US reports widen the range. Access Now’s #KeepItOn reporting builds a shared evidentiary record for UN human rights mechanisms and national litigants. Derechos Digitales in Santiago writes for regional advocacy and for proceedings in the Inter-American system. Paradigm Initiative in Lagos publishes Londa, country-by-country baselines on digital rights in Africa (Paradigm Initiative 2024). Less foundation money, more distributed authorship, tighter ties to litigation: the genre bends to the institutions it is trying to reach.
15.2 Reports that inform and reports that mobilize
Most authors never draw this distinction explicitly. An informing report surveys a field, names the actors, and leaves the reader better oriented. A mobilizing report builds to a demand: a rule the agency should write, a clause the procurement office should add, a disclosure the vendor should make. Both are legitimate and they are not interchangeable. A mobilizing report that reads as merely informing is ignored by those who could have acted; an informing report that reads as mobilizing is discounted by those who trusted it as a survey.
Read the recommendations to tell them apart. An informing report hedges (“policymakers should consider a range of approaches”). A mobilizing report is specific (“the agency should require, in its next solicitation, that the vendor deliver decision logs in CSV with a documented schema”). If your recommendations could be photocopied into a report on a different topic without changing meaning, you have written a report that will not cause anything to happen. That may be the right choice. Be sure it is a choice.
Piece 3 is a mobilizing section. It ends in recommendations to a body that can act.
15.3 The executive summary is the report
Most readers will read exactly three things: the title, the executive summary, and the recommendations. Some will glance at the figures. Almost none will read the methods. A legislative staffer during session triages dozens of documents a week, and the executive summary is where the triage happens.
So the executive summary is not a summary. It is the argument compressed to a page or so, with evidence pointers inline. It must stand alone: if a staffer forwards only the summary to their committee chair, the chair should be able to decide whether to ask for a briefing. The recommendations belong in it. If they are not in the executive summary, they are invisible.
Headings are the report’s second skeleton. A skimming reader reads headings and figure captions, and if those read as a coherent outline, the reader will trust the document enough to continue. “Findings” is a weak heading. “The model’s error rates differ most for groups the state serves least” is a strong one.
Test the three-layer skeleton before you send anything. Print the executive summary, the headings, and the figure captions, and hand them to someone who has not seen the report. If they can tell you what you found, what you want done, and who should do it, the skeleton works. If not, your argument lives where no one will read it. A second, more technical trap: if you type the audit’s numbers into the prose by hand, the report and the workpaper will drift apart the first time you rerun the audit. Read the numbers from the audit’s JSON output inside the report itself, so that a rerun updates both or neither.
15.4 Methods transparency as a credibility move
A report is not a peer-reviewed article. What it needs is methods transparency a skeptical reader can check in an afternoon: where the data came from and when, with which parameters; a link to the repository that produced each figure; a datasheet-style note for each dataset (Gebru et al. 2021); and a clear statement of what the analysis cannot support. The last item separates reports people cite from reports people weaponize.
You have already built most of this. The manifest from Chapter 12 answers “which data, which model, which recoding.” The thresholds file answers “judged against what, and on whose authority.” The changelog answers “what changed since last time.” The CI badge from Chapter 13 answers “does the code still do what the workpaper says.” The four-section audit memo, especially its list of assumptions, becomes your methods section almost verbatim. A methods section that links to all four is short and very hard to dismiss.
Oversight requires documentation that can travel, and reports are the documentation that travels. The specific claim of this chapter is that a report advances oversight only when it carries its own verification with it: a reader at a state agency, or the vendor’s lawyer, must be able to rerun the audit from the linked manifest and get the same table. A report that asserts findings without that path is the audit-washing this module has been arguing against, written by the other side. There is a second failure the genre is prone to: the “report and forget” cycle, in which a report is launched, covered, and shelved. Recommendations aimed at a named body, with an authority it already holds and a date by which it could act, are the defense. They give the reader a remedy to pursue, not just a finding to regret.
15.5 The translation gap
You already have findings. Writing the report is mostly translating them into terms an institutional reader can act on, and the translation has three moves first-time authors underestimate.
Name the actor. “Someone should regulate this” is a complaint. A recommendation names the body, the authority it holds, and the calendar it works on.
Name the remedy. An agency cannot act on “transparency.” It can act on a specific disclosure requirement, a records release, a procurement clause (Chapter 14), or a rule. Your recommendation should be close to copy-pasteable into a draft bill, rule, or contract.
Name the trade-off. Every institutional reader has a colleague whose job is to poke holes. Name the most plausible objection (cost, vendor pushback, privacy risk from collecting protected attributes, the small-cell problem in rural counties) and explain why the recommendation still stands.
15.6 Naming a Colorado state body
The report is not written for “policymakers” any more than the op-ed was written for “the public.” At the state level, three kinds of body recur, and each reads differently.
A legislative committee writes or amends statutes and oversees agencies. The Colorado General Assembly has committees of reference for each subject area and a Joint Technology Committee that oversees state information technology. A committee’s staff read for statutory hooks, fiscal implications, and whether your recommendation fits a bill they could carry next session.
A state agency writes rules, enforces statutes, and buys systems. Under SB 24-205, the Attorney General’s office holds enforcement authority over the Colorado AI Act; the Governor’s Office of Information Technology sets standards for state technology. Agency staff read for whether your evidence would survive a challenge and whether the recommended action is within their existing authority.
A task force or advisory body studies a question and reports to the legislature or the governor. Colorado has convened bodies on artificial intelligence and on related questions in recent sessions. Task force members read for options and evidence they can cite in their own report, and they often have the longest time budget.
Pick one body as the primary reader, confirm that it currently exists and has the authority your recommendation assumes, and write the executive summary to it. You cannot serve all three as the primary reader.
15.7 Quarto as a report stack
The technical apparatus is what you already know. A report is a Quarto project with its own _quarto.yml, a main report.qmd, a references.bib, and the audit repository as a dependency. Quarto renders the same source to HTML, PDF (for readers who print everything), and .docx (for the staffer who will run Track Changes on your recommendations).
report/
_quarto.yml
report.qmd
references.bib
audit/ # your audit-pipeline, as a git submodule or copy
manifest.yaml thresholds.yaml CHANGELOG.md
reports/2027-03-11-001.json
README.md
# _quarto.yml
project:
type: default
output-dir: _output
author:
- name: "Your Name"
affiliation: "INFO 4871/5871, University of Colorado Boulder"
format:
html: {toc: true, embed-resources: true}
pdf: {toc: true, number-sections: true}
docx: default
bibliography: references.bib
execute: {echo: false, warning: false}The first code cell in report.qmd loads the audit’s output, so every number in the prose comes from the workpaper:
#| label: setup
import json
audit = json.load(open("audit/reports/2027-03-11-001.json"))
find = {f["metric"]: f for f in audit["findings"]}
dpd = find["demographic_parity_difference"]
eod = find["equalized_odds_difference"]The executive summary then uses Quarto’s inline code instead of typed numbers:
# Disaggregated Error Rates in an Income Classifier Trained on Colorado ACS Data
::: {.callout-important title="Executive summary"}
Prepared for [named Colorado state body]. An audit of a model trained
on 2018 American Community Survey records for Colorado finds a
demographic parity difference of `{python} f"{dpd['value']:.2f}"`
(threshold level: `{python} dpd['level']`) and an equalized odds
difference of `{python} f"{eod['value']:.2f}"`
(`{python} eod['level']`). We recommend that [body] (1) ...,
(2) ..., and (3) ... before [date or session].
:::
## Error rates differ most for the groups the data describe least
{{< include sections/findings.qmd >}}
## Methods {#sec-methods}
Audit run `{python} audit['run_id']`; manifest, thresholds, changelog,
and CI-tested code at <https://github.com/yourname/acs-co-audit>.Render all three formats in one pass with quarto render report.qmd --to html,pdf,docx, and check that each shows the same numbers:
quarto render report.qmd --to html,pdf,docx
# => Output created: _output/report.html
# => Output created: _output/report.pdf
# => Output created: _output/report.docxBuild for .docx from day one. Retrofitting a Word-friendly layout the night before a deadline is a surprise you can schedule out of existence.
15.8 Reports across the lineages
The report does not belong to data science. Within this module alone, it has two ancestors. The auditor’s report (Chapter 12) documents trust through procedure: what was examined, against what standard, by whom. The engineer’s incident review (Chapter 13) documents failure so that it is not repeated. Piece 3 borrows from both: the audit report’s discipline about scope and standards, and the incident review’s insistence on specific, assigned, dated changes. Say so in your methods. A report that knows its genre reads as adult.
15.9 Exercises
Exercise 15.1 (Structural analysis, US). Pick a recent AI Now Institute or Data & Society report. Map its structure: how many pages go to executive summary, findings, methods, recommendations, appendices? Is it informing or mobilizing? Who is the implied institutional reader, and what tells you? Write 400 words.
Exercise 15.2 (Structural analysis, non-US). Do the same for a recent report from Access Now, Derechos Digitales, or Paradigm Initiative. Note where it assumes a reader who is not a US government. End with one paragraph comparing it to your report from 15.1: which conventions differ, and what does that say about each report’s audience?
Exercise 15.3 (Executive summary and outline). Choose the Colorado state body your Piece 3 report will address. In 150 words, document that it currently exists, cite its source of authority, and name what it can actually do (amend a statute, write a rule, change a procurement standard, recommend). Then draft a one-page executive summary with recommendations inline and a section outline with one-sentence nut grafs. Exchange with a classmate and run the three-layer skeleton test from the Missing Manual callout.
Exercise 15.4 (Reproducible figure, laptop, real public data). Add a figure to report.qmd that plots per-group error rates from your audit’s JSON output, with the per-cell n labeled and suppressed cells noted in the caption. The caption must cite the audit run_id. Rerun the audit with a changed min_cell_size, re-render, and confirm that the figure and the inline numbers both update. Commit both renders.
Exercise 15.5 (Piece 3: Assurance / State / Report). Submit Piece 3, with all four parts:
- Technical artifact. A disaggregated audit with manifest, thresholds, changelog, and tests that run in continuous integration, as a reproducible repository a classmate can clone and run.
- Public text. A report section for a named Colorado state body: executive summary, methods, findings, recommendations (about 2,000 words).
- Installed-base note (about 300 words). Which pressure did you meet? Which installed-base elements did your artifact build, and which are still missing? Include provenance, license, and an AI-use disclosure.
- Graduate methods memo (INFO 5871 only; 750–1,000 words). Situate the piece in at least five scholarly sources and defend one methodological choice against the literature.
15.10 Looking ahead
Piece 3 asked whether a state can verify a system it depends on. Part V climbs the last rung of the ladder to the federal level and changes the pressure. Chapter 16 asks what happens when the record itself decays: datasets withdrawn, links rotted, archives left without a steward. Your audit depends on federal survey infrastructure that someone has to keep running; the folktables call that worked this term is a small act of trust in that continuity. The module that follows ends in a public comment (Chapter 20), a genre with the most formal route into federal decision-making of any in this book. If you choose Piece 3 for your final project, you might recast it in that genre, or deposit it with a DOI (Chapter 22).
15.11 Further Reading and Resources
- AI Now Institute, publications: https://ainowinstitute.org/publications. The mobilizing report in the US technology-policy ecosystem; read one cover to cover.
- Data & Society, library: https://datasociety.net/library/. A wide range of report types; notice how each is built for its implied reader.
- Access Now, #KeepItOn: https://www.accessnow.org/campaign/keepiton/. A non-US advocacy report integrated with UN human rights mechanisms.
- Derechos Digitales: https://www.derechosdigitales.org/. Latin American digital rights research written for regional advocacy and litigation.
- Paradigm Initiative, Londa: https://paradigmhq.org/londa. Distributed, country-by-country reporting; the opposite of the single-institute report.
- Colorado General Assembly: https://leg.colorado.gov/. Committee pages, bill histories, and interim committee schedules; start here to name your body.
- Quarto documentation on inline code and multi-format output: https://quarto.org/docs/computations/inline-code.html. The feature that keeps your prose and your audit in sync.
- Jonathan Gray and Liliana Bounegru, eds., The Data Journalism Handbook (2021) (Gray and Bounegru 2021). Chapters on long-form investigative projects whose conventions travel to reports.
- Timnit Gebru et al., “Datasheets for datasets” (Gebru et al. 2021). The provenance-note template for every dataset your report relies on.
- Pandoc manual, reference documents for
.docx: https://pandoc.org/MANUAL.html#option--reference-doc. Fixes most Word formatting surprises.