Why compliance has moved into the boardroom
It has long been comfortable to view cybersecurity, data protection and AI as technical questions, something for the IT department to handle while the board attends to strategy and business. That division no longer holds. A series of new and tightened frameworks, from the AI Act to the rules on digital operational resilience and cybersecurity, have in common that they expressly place responsibility for governance and oversight at management and board level. Operational risk has become a board matter, whether the board wants it or not.
For boards in growth companies this is an uncomfortable change. Members are often chosen for their commercial or sector expertise, not for interpreting technical frameworks, and yet it is they who carry the responsibility if governance falls short. This article explains what the expanded responsibility means, where the personal exposure lies and how a board can take its responsibility seriously without getting lost in technical detail.
What the expanded board responsibility means
The shift is not about the board becoming technicians, but about it being able to govern and oversee risks it could previously delegate away.
From delegation to oversight
Previously a board could in practice delegate technical risks to a function and consider the matter settled. The new frameworks instead require active oversight: that the board understands the material risks, asks the right questions, ensures processes exist and follows up that they work. The responsibility cannot be delegated away, even if the execution can.
Operational risk as part of business risk
Operational risk, that is the risk of disruptions to the systems and processes the business rests on, has become an integrated part of the business risk the board has always had to manage. A cyberattack, a prolonged system outage or a misgoverned AI is no longer a technical mishap but a business event with legal and financial consequences that land on the board’s table.
Where the personal liability lies
What makes this development especially sharp is the link to personal liability. When frameworks place responsibility for governance and oversight at management and board level, it means that failures in that governance can have consequences not only for the company but for the individual members. It is not about a board being responsible for every technical fault, but about it being responsible for reasonable governance and oversight having been in place.
The decisive dividing line runs between a board that can show it understood the risks, asked the questions and ensured the processes, and one that gave the matter no attention. The first has taken its responsibility even if something still goes wrong. The second is exposed precisely because it has not. Documentation of the board’s work therefore becomes not a formality but a protection.
A practical example: the board that thought IT had it covered
Imagine a board in a growing company that never put cybersecurity or AI on its agenda, confident that the IT department and an external provider handle it. The minutes show strategy and budget, but not a word about operational risk.
When the company suffers a serious incident, say a data breach with leaked customer data, the question arises of what the board did to prevent and manage the risk. The answer is nothing visible: no risk review, no questions, no follow-up. The company faces not only the direct damage but also the question of whether the board failed in its oversight, with the personal exposure that can bring. A board that had regularly raised operational risk, asked questions and documented it would have stood on entirely different ground, even with the same incident.
Common mistakes companies make
The first mistake is to treat cybersecurity, data protection and AI as purely technical questions outside the board’s responsibility. The frameworks now say the opposite.
The second mistake is to assume that delegation equals freedom from responsibility. The execution can be delegated, but the oversight responsibility stays with the board, and it is the oversight on which it is tested.
The third mistake is not to document. A board that has actually handled the risks but not minuted it struggles to show that it took its responsibility once the question is asked.
Legal risks
The risk picture for the board is twofold. On one hand there is the company’s exposure: sanctions under the various frameworks, damages and the direct costs of an incident. On the other there is the personal dimension, where failures in governance and oversight can have consequences for individual members, depending on the circumstances and the framework in question.
Add to this the trust risk. An incident that reveals the board had no grip on operational risk damages the company’s reputation with customers, investors and partners, and ultimately its value. Taking operational risk seriously is therefore as much about protecting the company’s value as about avoiding sanctions.
Recommended actions
Start by putting operational risk, cybersecurity and AI on the board’s agenda as recurring items, not as one-off questions. Make sure the board gets an understandable picture of the material risks and of the processes that exist to manage them, without drowning in technical detail.
Ask the questions the oversight responsibility requires: what are our biggest operational risks, how are they managed, what happens in an incident and who is responsible? Make sure there is incident preparedness and that it is tested, and document the board’s work so that it can be shown the responsibility was taken. Bring in legal and technical expertise where the board’s own is not enough, and keep the work alive as both the risks and the frameworks evolve.
Frequently asked questions about the board’s responsibility in the AI era
Does the board have to understand the technology in detail?
No. The board must be able to govern and oversee, not act as technicians. It is about understanding the material risks, asking the right questions and ensuring processes exist, not about mastering the technology.
Can’t we just delegate these questions to IT or a provider?
The execution can be delegated, but the oversight responsibility stays with the board. The frameworks expressly place responsibility for governance at management and board level, and it cannot be delegated away.
What does personal liability mean in practice?
That failures in governance and oversight can have consequences not only for the company but for individual members, depending on the circumstances. A board that can show it took its responsibility stands considerably stronger.
How often should the board address operational risk?
As a recurring item rather than a one-off question. The risks and frameworks change, and a regular review both manages the risk and shows that the oversight responsibility is taken seriously.
Why is documentation so important?
Because it is the proof that the responsibility was taken. A board that handled the risks but did not document it struggles to show it when an incident or a review raises the question.
Summary
Operational risk, cybersecurity and AI have moved into the boardroom, driven by frameworks that expressly place responsibility for governance and oversight at management and board level. For boards in growth companies this means an expanded and partly personal responsibility, but not a requirement to become technicians. The board that puts the risks on the agenda, asks the right questions and documents its work takes its responsibility and protects both the company and itself, even on the day something still goes wrong.
Lawgent helps boards and management understand and manage their responsibility for operational risk, cybersecurity and AI, and build the governance and documentation the frameworks require. We combine experienced business-law advice with AI-driven efficiency, so you get an understandable and practical picture of your risks rather than a technical framework to interpret on your own. Want to know how well your governance holds up? Contact Lawgent for a review of the board’s responsibility and your operational risk.
