Technology Governance Has Become a Board Responsibility — Not Just an IT Responsibility
- Steve Coles

- Aug 14
- 5 min read
Updated: 1 day ago
Technology has moved from supporting the business to becoming fundamental to how organisations compete, operate and remain resilient. Board governance needs to evolve accordingly.

For many years, Boards could reasonably treat technology as predominantly a management responsibility. Technology strategy was developed by the CIO, major investments came to the Board for approval, and cyber risk was generally addressed through periodic risk reporting.
That model is increasingly inadequate.
Technology now underpins almost every aspect of an organisation: customer experience, operational resilience, growth, regulatory compliance, productivity and increasingly the deployment of artificial intelligence. At the same time, cyber threats are becoming more sophisticated, technology supply chains more concentrated, and major transformation programmes continue to consume significant investment.
The issue for Boards is therefore no longer simply:
“Is management managing technology effectively?”
It is increasingly:
“Do we have the governance, information and capability to exercise effective oversight of technology?”
That is a fundamentally different question.
Technology governance does not mean managing technology
There is an important distinction.
Greater Board accountability for technology does not mean Directors should become
technologists, nor should the Board start making operational technology decisions.
Management remains responsible for technology strategy, architecture, cyber security,
delivery and operations.
The Board's role is governance.
That means being able to understand whether technology supports the organisation's strategy, whether material risks are being managed within appetite, whether major investments are delivering the expected outcomes and whether the organisation can remain resilient when technology fails.
The challenge is finding the right boundary between effective oversight and inappropriate intervention.
Boards that sit too far away from technology risk becoming dependent on management's interpretation of the issues. Boards that move too deeply into technology risk confusing governance with management.
Good technology governance sits between those two extremes.
The traditional Board technology conversation is changing
Historically, Board technology discussions often concentrated on projects, budgets, outages and cyber incidents.
Those issues remain important, but the agenda has broadened significantly.
Boards are now being asked to oversee questions such as:
Is our technology strategy genuinely aligned with business strategy?
Are we investing enough — or too much — in technology?
What technology risks could materially disrupt the organisation?
How resilient are our critical operations if key technology or suppliers fail?
Are our cyber controls actually effective?
How should we govern the adoption of AI?
Where are we dependent on ageing or unsupported technology?
Are major transformation programmes realistically deliverable?
Do management's technology metrics give the Board genuine insight or simply
reassurance?
These aren't questions that can be answered through a conventional CIO dashboard alone.
They require a governance framework that connects strategy, investment, risk, resilience and accountability.
The danger of the green dashboard
One of the more difficult challenges for Boards is determining whether they are receiving the right information.
Technology reporting can be extensive while still providing surprisingly little insight.
A Board pack may contain dozens of metrics showing project status, system availability,
cyber vulnerabilities, incidents and service performance.
Most may be green.
Yet significant technology risk can still exist beneath the surface.
The question Directors should ask isn't simply whether the indicators are green. It is whether the indicators measure the things that matter.
For example, knowing that 98% of critical vulnerabilities have been patched within the target timeframe may sound reassuring.
But what about the remaining 2%?
Are they sitting on critical internet-facing systems? Have they remained unresolved because the business has repeatedly declined the downtime required to patch them? Who has accepted that risk?
The aggregate metric can be green while the underlying risk is significant.
Effective governance therefore requires Boards to move beyond status reporting towards decision-useful insight.
Technology risk is increasingly business risk
Another important shift is the declining usefulness of treating technology risk as a separate category of risk.
A major cyber incident is not simply a technology event. It can become an operational,
financial, regulatory and reputational event within hours.
A failed transformation programme can affect growth, customer service, regulatory
commitments and shareholder returns.
An extended cloud or telecommunications outage can interrupt critical business services.
Poorly governed AI can create privacy, conduct, regulatory and reputational risks.
Technology risk increasingly manifests itself as enterprise risk.
That means technology governance needs to connect directly with the organisation's broader governance and risk frameworks rather than operating as a specialist discipline sitting underneath them.
The Board needs capability — but not necessarily more technologists
There is increasing debate about whether Boards need Directors with deep technology
expertise.
For some organisations, particularly those with significant technology dependency or
transformation agendas, that can be valuable.
But adding a technologist to the Board is not by itself a technology governance framework.
Every Director still has a role in governing material technology issues.
The objective should therefore be to create sufficient collective capability around the Board table to ask the right questions, understand the answers and recognise when further challenge is required.
That capability can come from several sources: Director education, appropriately experienced executives, Board technology committees and, where appropriate, independent external expertise.
The important point is that the Board should not be entirely dependent upon the people
responsible for delivering the technology agenda to determine whether that agenda is
appropriate.
Independent challenge matters.
Five questions Boards should consider
A useful starting point is for Directors to ask:
Do we have clear accountability for technology governance between the Board, its committees and management?
Does our technology reporting tell us what we need to know about material risk, performance, resilience and investment — or primarily what management finds easy to measure?
Can we independently challenge major technology investments before significant commitments are made?
Do we understand where technology could materially disrupt our critical business operations?
Does the Board have sufficient collective capability to govern technology confidently without drifting into management?
The answers will differ considerably between organisations.
There is no single governance model that is right for every Board.
The objective is confidence, not technical expertise
Technology will continue to become more important to Boards, not less.
AI will accelerate that trend. So will increasing cyber threats, regulatory expectations,
technology concentration and organisations' dependence on digital services.
The response should not be to turn Boards into technology committees or Directors into
technology specialists.
The objective is much simpler:
Boards need sufficient governance, information, capability and independent challenge to make confident decisions about technology.
When those elements are in place, technology stops being something the Board periodically receives reports about.
It becomes what it increasingly needs to be:
a core part of effective corporate governance.
Steve Coles
Board Technology Adviser | Non-Executive Director | Former Global Chief Technology
Officer
Steve advises Boards on technology governance, independent assurance, cyber, AI and operational resilience.
_edited.png)


Comments