The Boardroom Is Becoming an Accountability Zone
Board accountability can no longer be reduced to approving strategy, receiving reports and recording decisions. Regulators increasingly expect organisations to show who owned important risks and how senior leaders exercised oversight. In the UK, the Senior Managers Regime requires clear Statements of Responsibilities for key decision-makers. Across EU financial services, the Digital Operational Resilience Act (DORA) makes management bodies ultimately responsible for ICT risk.
Meanwhile, AI, cyber threats, operational resilience, financial crime, sanctions and third-party dependencies are crowding the board agenda. More dashboards and committees do not automatically mean better governance. The emerging test is tougher: can directors demonstrate what they knew, what they challenged and what happened next?
Who Actually Owns the Decision?
Boards make decisions collectively, but collective responsibility can create an uncomfortable question when something fails: who actually owned the risk? UK financial regulation increasingly demands a clearer answer. Under the Senior Managers Regime, every Senior Management Function holder requires a Statement of Responsibilities setting out what they are accountable for. Recent 2026 reforms aim to streamline the regime while maintaining strong individual accountability.
The challenge intensifies when risks cross organisational boundaries. An AI deployment might simultaneously create technology, privacy, consumer, operational and reputational risks. Assigning it vaguely to “the board” invites accountability diffusion. EU regulation reinforces the direction of travel. DORA, for example, requires financial entities’ management bodies to define clear ICT roles while retaining ultimate responsibility for ICT risk.
Boards should therefore introduce dynamic accountability mapping, revisiting ownership as risks and projects evolve. Before approving a significant initiative, directors should ask: Who owns implementation? Who monitors unintended consequences? Who must escalate failure? A practical Board Accountability Map can connect every material risk with named ownership, challenge and escalation responsibilities.
Drowning in Data, Starved of Insight
A 300-page board pack may demonstrate administrative effort, but not effective oversight. The danger is dashboard theatre, with dozens of green indicators creating reassurance while deteriorating controls or interconnected risks remain buried. The Financial Conduct Authority (FCA) recently found that some firms presented extensive Consumer Duty data without adequately explaining what it revealed about customer outcomes.
Boards need decision-useful intelligence rather than governance noise. The Financial Reporting Council’s (FRC’s) current guidance says boards should oversee the nature, format and frequency of information they receive and ensure it supports effective decision-making.
One solution is exception-based reporting, highlighting material changes, emerging threats, deteriorating controls and unresolved questions. Every significant paper might include a short section headed “What should worry the board?” Directors should demand trends and forward indicators, not snapshots.
AI can help summarise papers and identify patterns, but hallucination, confidentiality and automation bias make human challenge essential. Boards should also periodically ask what information directors never use and what they repeatedly learn too late. Better accountability starts when reporting is redesigned around decisions, exceptions, trends and weak signals, not volume.
Governing What You Cannot Fully Understand
Boards increasingly govern risks that evolve faster than directors can master them. As organisations move from generative AI towards agentic systems capable of taking actions, the EU AI Act makes human oversight, monitoring and risk management increasingly important. Cyber accountability is equally explicit. DORA places ultimate responsibility for ICT risk on financial entities’ management bodies, while NIS2 (Network and Information Security Directive 2) requires management bodies to approve and oversee cybersecurity risk-management measures.
The same challenge extends to sanctions, financial crime and technology supply chains. Complex ownership structures can obscure sanctioned parties, while dependence on cloud, data and software providers creates third- and fourth-party vulnerabilities. A cyberattack coinciding with failure at a critical cloud provider could therefore become a board-level crisis within minutes.
“We relied on the experts” is no longer a convincing governance strategy. Directors need not become engineers, but they must understand enough to challenge assumptions. Reverse mentoring, specialist advisers, emerging-risk deep dives and realistic simulations can build that capability. The practical shift is from static risk registers towards continuous risk sensing and board-level scenario rehearsals that test decisions before reality does.
Building an Evidence Trail of Board Accountability
After a corporate failure, regulators may ask a deceptively simple question: what did the board actually do? Minutes stating that “AI risk was discussed” prove attendance, not effective oversight. The FCA has highlighted cases where board papers existed but minutes showed little evidence of meaningful challenge.
Boards therefore need decision traceability. For significant decisions, records should show the information directors received, assumptions questioned, alternatives considered, risks identified and actions requested. FRC guidance similarly recommends documenting the discussion leading to significant decisions, including issues raised and reasons for the decision.
Consider directors questioning whether an AI-powered customer decision system could produce unfair outcomes. A useful record would capture the concern, evidence requested, management’s response, agreed safeguards and subsequent testing. A Challenge-to-Action Register could then track commitments through to closure. Indeed, the FCA has praised firms using trackers for board requests.
This should not produce defensive, transcript-like minutes that inhibit debate. The aim is proportionate evidence connecting information → challenge → decision → action → outcome, demonstrating not merely that directors were present, but that governance happened.
Redesigning Governance for Faster Risk
Quarterly board rhythms look mismatched to risks that can mutate overnight. AI models evolve, cyber threats escalate and geopolitical shocks redraw supply chains before the next meeting. The question is not whether traditional boards disappear, but whether their operating model becomes more adaptive.
The FRC’s Corporate Governance Code guidance says boards should consider whether they possess the skills, knowledge and experience needed to assess risks effectively. Skills obsolescence becomes a governance risk itself. A board matrix built around yesterday’s expertise may need technology literacy, regulatory insight, resilience and data competence.
This does not automatically mean appointing more directors. Temporary specialist advisers, expert panels, technology committees and structured external challenge can inject expertise when required. Shadow boards and next-generation advisory groups can expose directors to perspectives missing from the boardroom.
Continuing education should follow emerging risks, not an annual governance calendar. Boards could also undergo periodic “stress tests”, confronting fast-moving cyber, AI or geopolitical scenarios and evaluating the quality of collective challenge. Board effectiveness should measure adaptability, not merely composition and process. Treat board design as a dynamic governance capability, not a fixed organisational chart.
Accountability Is Becoming Something Boards Must Prove
Board accountability is moving from assumption to evidence. Collective responsibility increasingly requires visible individual ownership, information overload must become decision-useful intelligence, and static oversight must give way to continuous risk sensing. Minutes alone are insufficient when stakeholders expect decision traceability and evidence that governance produced meaningful outcomes. The UK Corporate Governance Code reinforces this direction by requiring boards to monitor risk and internal controls and, from 2026, declare the effectiveness of material controls.
Directors cannot master every technical issue, nor should they. They must, however, know enough to question, challenge, escalate and demand evidence. Tomorrow’s defining question may therefore be: can we prove our governance structures delivered effective oversight when it mattered?
And what about you…?
- Does your board receive genuinely decision-useful information, or is effective oversight being undermined by increasingly large board packs and excessive data?
- Are your current board structure, skills and meeting practices sufficiently adaptable for tomorrow’s regulatory environment, or does your governance model need to evolve?


