Cyber incidents now test a board’s judgment as much as its technology. Directors may approve a security budget and still struggle to show who owns the risk, when the response plan was tested, or how decisions were recorded.
Regulators have raised the standard. SEC rules, NIS2, and DORA all bring board oversight closer to formal accountability. Successful cyber risk management gives directors a clear view of exposure, a defined role during an incident, and evidence that the organization acted on what it knew.
Key takeaways
- Executive compensation needs a clear link to long-term performance, risk controls, and board-approved outcomes.
- Independence alone does not make a board effective. Directors also need the skills to challenge management on technology, finance, sustainability, and sector risk.
- AI and cybersecurity now belong in the board’s regular oversight calendar, with clear ownership and a record of decisions.
- ESG reporting needs board-level responsibility, reliable source data, and evidence that published claims were reviewed.
- Succession planning should cover the CEO, senior leaders, committee chairs, and the skills the board will need next.
- A secure, searchable record of board materials, decisions, votes, and follow-up actions helps directors govern with better context.
Corporate governance issues boards need to address
A useful governance review connects each issue to three questions: who owns it, what evidence reaches the board, and which decisions need to be recorded?
| Issue | Board question | Evidence |
|---|---|---|
| Executive compensation | Does pay reflect long-term results and risk? | Policy, measures, minutes, rationale |
| Board independence and skills | Can directors challenge management? | Skills matrix, evaluations, succession plan |
| AI and cybersecurity | Who owns technology risk? | Risk reports, tests, decisions, action log |
| ESG and sustainability | Can disclosures be supported? | Controls, assurance, approved statements |
| Talent and succession | Who can step in? | Emergency plan, candidate reviews |
1. Executive compensation and internal controls
Pay remains a governance issue because it signals what the organization rewards. A package that values growth without accounting for conduct, resilience, customer outcomes, or control failures can encourage decisions that look good in one reporting cycle and create problems later.
The UK Corporate Governance Code 2024 has applied since 1 January 2025. Provision 29, which asks boards to declare the effectiveness of material internal controls, became applicable on 1 January 2026. The Financial Reporting Council’s guidance on the Code places remuneration alongside board leadership, succession, audit, risk, and internal control.
The remuneration committee needs evidence on performance measures, exceptional events, control failures, and any discretion applied to an award.
A defensible process includes:
- A policy approved by the appropriate committee.
- Financial and non-financial performance measures.
- A review of conduct, risk, compliance, and controls.
- A conflicts review and explanation for any discretion.
Board action: Keep the remuneration decision, supporting evidence, conflicts review, and final rationale together in the board record.
2. Independent directors, skills, and board capability
Independent directors still matter, but independence is only one part of board capability. Directors also need enough sector knowledge, financial judgment, technology awareness, international experience, and courage to question management when the facts are uncomfortable.
The 2025 Spencer Stuart U.S. Board Index reported that 80% of S&P 500 boards disclosed a skills matrix in their proxy statements, compared with 38% in 2020. The same research reported CEO succession as the second most important nominating and governance committee agenda item, cited by 60% of respondents. A board governance framework can help turn those priorities into a repeatable review rather than an annual paperwork exercise.
A useful skills matrix should do more than list director biographies. It should show where experience is concentrated, which capabilities are missing, and how the board’s needs may change after an acquisition, a new regulation, or a shift in the business model.
Boards should review:
- Independence, tenure, conflicts, and outside commitments.
- Experience in cyber risk, AI, data governance, and digital operations.
- Financial reporting, audit, compliance, and sustainability expertise.
- Committee capacity, director development, and chair succession.
The goal is a board that can ask better questions, not a matrix that only looks complete on paper.
3. AI, cybersecurity, and technology oversight
AI has moved from a specialist topic to a board responsibility. Directors need to understand where the organization uses AI, which decisions rely on it, what data it processes, and who is accountable when the system produces an unsafe or inaccurate result.
The EU AI Act adds a formal timetable to that responsibility. Prohibited practices began applying in February 2025. From 2 August 2026, the AI Office and Member State authorities are responsible for implementing, supervising, and enforcing the Act. Different AI systems have different application dates, so boards need an inventory that maps each use case to its obligations. The European Commission’s AI Act overview sets out the current implementation milestones.
Cyber risk belongs in the same discussion. SEC rules require US public companies to disclose material cybersecurity incidents on Form 8-K within 4 business days after a materiality determination and to describe board oversight annually. In the EU, DORA has applied to financial entities since 17 January 2025 and gives the management body responsibility for ICT risk and digital resilience.
Boards should expect concise reporting on:
- Material AI use cases, risk owners, data access, and human review.
- Critical technology providers, concentration risk, and resilience testing.
- Cyber incidents, near misses, remediation, and incident escalation.
- Decisions that require board approval, funding, or disclosure.
A board portal with controlled access, audit trails, and search connects the board pack, minutes, vote, and follow-up action.
4. ESG accountability and sustainability reporting
ESG has become a governance discipline because sustainability claims can affect capital allocation, reputation, regulatory exposure, and executive accountability. Boards need to know who owns each disclosure, how the underlying information was collected, and which controls support the final statement.
The reporting rules continue to change across jurisdictions, including the EU’s sustainability reporting framework. An audit committee, sustainability committee, or full board may oversee the work, but responsibility should be explicit and documented.
The board should ask:
- Which sustainability topics are material to the business?
- Who owns each data point and management assertion?
- What evidence supports public claims about climate, people, and supply chains?
- Which information receives internal review or external assurance?
Greenwashing risk often starts with weak internal records. If a claim cannot be traced to an owner, a source, a review, and an approval, the board has limited ability to defend it.
5. Talent, succession, and board renewal
Leadership continuity is a governance issue long before a vacancy appears. Boards need plans for the CEO, executive team, committee chairs, and the directors whose expertise will be difficult to replace.
A succession plan should name potential successors, identify development gaps, define the interim leader’s role, and set out how the board will communicate during a transition. It should cover an emergency departure and a loss of key technical expertise.
The board’s own renewal belongs in the same plan. New directors may need experience in AI, cybersecurity, sustainability, international operations, or a regulated market. Existing directors may need focused training before they can oversee those areas with confidence.
A practical annual review asks:
- Which leadership roles have a named successor?
- What would happen if the CEO or chair left tomorrow?
- Which board skills are missing or concentrated in one person?
- What development should happen before the next appointment?
Talent planning works best when the board revisits it after major business changes, not only during the annual evaluation cycle.
What is changing in 2026 and beyond
Board accountability is becoming easier to test
The UK Code’s internal control declaration, DORA’s management-body responsibility, and AI Act supervision all point in the same direction: boards need evidence of active oversight. A calendar entry saying “cyber update” is weak evidence. A record of questions, decisions, owners, and follow-up is stronger.
AI governance is becoming part of board composition
Technology expertise now affects recruitment, committee design, director education, and succession. Boards don’t need every director to be an AI specialist, but they do need enough collective knowledge to challenge assumptions and decide when management needs outside expertise.
ESG reporting is moving closer to internal control
Sustainability disclosures increasingly require consistent data, ownership, review, and assurance. Boards should give the reporting process the same discipline as financial and risk information.
How DiliTrust supports corporate governance
Good governance depends on the quality of the information directors receive and the record they leave behind. Email chains, shared folders, and disconnected spreadsheets make it difficult to confirm which version was approved or whether an action was completed.
DiliTrust’s Board Portal gives governance teams one controlled environment for agendas, board books, meeting materials, minutes, votes, and follow-up actions. Permissions help restrict sensitive information to the right people, while audit trails preserve the history of access and decisions.
Lini, DiliTrust’s AI engine, can help teams find information, summarize materials, and prepare meeting records inside the platform. The AI for Board Management approach keeps human review in the process.
The wider DiliTrust Suite connects board governance with contract, entity, matter, and data room workflows. That helps when a board decision depends on a contract obligation, entity filing, regulatory matter, or transaction record.
See how DiliTrust helps boards manage decisions, records, and follow-up actions: Explore the Board Portal
A board governance checklist
Use these questions in the next board or committee review:
- Are executive pay decisions linked to long-term performance, conduct, risk, and controls?
- Is the board’s independence assessment current and supported by a skills matrix?
- Does the board know where AI is used, who owns each use case, and which controls apply?
- Are cyber risk, ESG claims, and resilience testing reported with supporting evidence?
- Does the succession plan cover planned and emergency leadership changes?
- Are materials, decisions, votes, and actions stored together with a clear audit trail?
Conclusion
Corporate governance issues now meet at the board table. Pay, composition, technology, ESG, and succession each create different risks, but the board’s responsibility stays consistent: ask informed questions, make sound decisions, and keep a record that shows how oversight worked.
A secure governance process helps directors spend their time on judgment rather than document hunting. See how DiliTrust supports modern board governance.
Frequently asked questions
The main issues are executive compensation, board independence and skills, AI and cybersecurity, ESG accountability, and succession. Each needs a clear owner, evidence, decision process, and follow-up record.
Independent directors can challenge management without the same ties to executives or controlling shareholders. Effective boards also need the right skills, committee structure, time commitment, and evaluation process.
AI creates questions about accountability, data, safety, human review, and compliance. Boards should inventory material use cases, assign risk owners, receive regular reporting, and record decisions.
Corporate secretaries use board portals to distribute materials, manage meetings, record minutes, run votes, control access, and preserve an audit trail. DiliTrust’s Board Portal supports these workflows, with Lini assisting with search and meeting records.


