Writing  |  26 September 2026

What a board's digital, AI and cybersecurity committee should do

Most boards know they must oversee technology risk. Fewer have decided who does it, how often, and against what standard. This is how I set it up for a first board.

When I design a board for a growth-stage company, the committee that oversees digital, AI and cybersecurity is often the last one the founders ask about. I put it near the front. At a mine site, a cyber incident can stop production, put people at risk and trigger a disclosure obligation on the same day.

Keep oversight and management separate

The committee oversees. Management owns the systems, the controls and the people who run them. Writing that line into the charter settles most arguments before they start, and it keeps directors out of day-to-day operations.

Route it through audit and risk

On a smaller board I have this committee report through the audit and risk committee. Cyber risk and financial controls then meet in one place, and the board hears one integrated account of risk. It also allows the committee to include members who would not meet the independence tests that apply to an audit committee.

Treat operational technology as a safety matter

In mining, the systems that run hoists, ventilation and processing plants are operational technology. A breach there is a safety, environmental and continuity event. I place the committee chair on the sustainability, HSE and technical committee as well as audit and risk, so site security is overseen by people who understand the site.

Give the board a standard it can test

A charter that says "oversee cybersecurity" gives directors nothing to measure. Adopting a recognized framework, such as the NIST Cybersecurity Framework or ISO 27001, does. The committee can then ask where the company stands against the framework, what the last penetration test found and what has been fixed since.

Put the right items on the agenda

The duties I write into the charter are these:

A material cyber incident should also be assessed promptly as potential material information for disclosure purposes. The committee meets at least quarterly and promptly after any material incident, and it reports to audit and risk after each meeting. A four-quarter work plan turns the charter into an agenda, so every topic gets its turn in the year.

When no director has the expertise

Early boards often lack a director with deep technology experience. An outside chair can fill the gap with firm limits in place. The committee is advisory and holds no delegated authority. The chair signs the board's conflict, confidentiality and conduct undertakings, any fees are disclosed, and the appointment ends automatically once a qualified director joins, the company lists, or two years pass.

The test I apply is simple. Every director should be able to name the company's most serious technology risks and say what is being done about each one. When they can, the committee is working.

This article is general information drawn from governance work in Canada and Latin America. It is not legal, insurance or investment advice.

Paul Desjardins, Move Add Change

The future is yours. Let's build it.

If you are forming a board, preparing for public markets, adopting AI or entering a new market, I would like to hear about it. Send me a note here, or use the details below.

I meet on Teams, Zoom or Google Meet, or in person in Toronto.