How should our board oversee technology without being technical?

Ask for a short set of facts in plain terms: critical systems, major projects, key vendors, security posture and recent incidents. Ask for each risk in business terms, with an owner and a date. Then decide whether the board needs more structure or an independent view.

Draft for Tamir's review. Not published.

Tamir Khason · Updated · Decision guides

What to ask for

Ask for the systems the business cannot run without, with age, owner and how long the business can run without each. Ask for the major projects with state, spend and risks, and the key vendors with dependence and exit terms.

Ask for the security posture and the last incidents in plain terms, and what changed after each. Near misses matter as well as outages. Repeated near misses on the same dependency are a pattern the board should see.

Turn findings into decisions

When internal audit and management disagree, ask both sides to state each finding's risk in business terms on one page. Get an independent view on the contested ones. Close each finding with a fix date or a recorded risk acceptance.

When a remediation plan stalls, rank the open findings by risk. Require the top ones fixed with named resources and dates, and bring the rest back as re-planned or accepted risk. Material decisions made in messages belong in the decision record.

Depending on your seat

If you're a new independent director, ask for those facts in your first months and meet the technology leader. Then ask two business leaders what technology blocks them.

If you chair the board, list the technology matters that reached it in the last two years. Decide whether a committee, a director with that background or an external adviser fits, and give it a mandate. If you're a minority investor, seek information rights tied to the technology assumptions behind your investment.

What to check before you decide

  • Ask for the critical systems list with age, owner and how long the business can run without each.
  • Ask for the major projects with state, spend and risks.
  • Ask for the key vendors with contract terms, dependence and exit.
  • Compare the incidents and near misses recorded in departments with what reaches the board.
  • Ask for each open audit finding's risk in business terms, ranked, with an owner and a date.
  • Close each finding with a fix date or a risk acceptance recorded by the board.
  • Write a mandate for any technology committee or role: what it reviews, approves and reports.

Questions people ask

Internal audit found IT control gaps, management calls them theoretical, how does the audit committee resolve it?

Ask for the risk in business terms for each finding: what could happen, how likely, and what it costs, from both sides on the same page. Then get an independent view on the contested ones and set a date for closure or formal acceptance of the risk. It depends on which findings touch critical systems and on whether the controls exist elsewhere in a different form.

State audit criticised our IT management and management disputes it, how does the committee decide what to accept and how to respond?

Sort the findings into accepted, partly accepted with reasons, and disputed with evidence, and respond with a plan only for what the body can deliver with dates and owners. Disputes need evidence. Arguments don't settle them. It depends on which findings are factual and which are judgement, and on what the body can commit to.

New independent director, how do I understand the company's technology risks in my first months?

Ask for five things: the systems the business cannot run without, the major projects and their state, the key vendors and dependencies, the security posture in plain terms, and the last incidents and what changed. Meet the people who run them, and then decide whether an independent view is needed. It depends on the company's dependence on technology and on what the briefing reveals.

Our IT control remediation stalled and management cites resources, what should the audit committee do?

Rank the open findings by risk and require the top ones fixed with named resources and dates, with the rest formally re-planned or accepted as risk by the board. A stalled plan with no ranking treats a critical gap like a paperwork gap. It depends on which findings touch critical systems and on what the company can actually resource.

Should our board have a technology committee or a technology director, and what would it do?

Decide by the company's dependence on technology and the volume of technology decisions: a committee makes sense when projects, security and vendor decisions need regular deep review; a director with the background helps the full board ask better questions. Either needs a mandate: what it reviews, what it approves, what it reports. It depends on the company's technology intensity and on the board's current capacity.

Should hospital boards receive technology near misses as well as outages?

Require reporting of decision-relevant near misses with clear significance and ownership. Oversight depends on credible escalation criteria, repeated causes, and whether existing controls prevented harm or merely avoided it by chance.

What evidence should support public technology decisions made through informal messages?

Reconstruct material decisions and their authority before relying on the current plan. Oversight depends on agreed scope, rationale, conditions, and requirements confirmed with procurement and legal owners.

What information rights do minority investors need for technology oversight?

Seek information rights tied to material investment assumptions and proportionate confidentiality protections. The terms depend on governance rights, business sensitivity, and enforceability assessed by transaction counsel.

How I can help with this decision

Ask or talk (Free)
I give my view on what your board should ask for first and how to read the answers without a technical background.
Review (Pay if it was worth it)
I write an independent assessment of the company's technology risks and the board's oversight arrangements. I recommend what to raise first, and a structure and mandate if one is needed.
Retain (When it makes sense)
I stay available to the board as an external adviser on technology matters that reach it, if that arrangement fits.