What a board's digital, AI and cybersecurity committee should do
Most boards know they must oversee technology risk. Fewer have decided who does it, how often, and against what standard. This is how I set it up for a first board.

When I design a board for a growth-stage company, the committee that oversees digital, AI and cybersecurity is often the last one the founders ask about. I put it near the front. At a mine site, a cyber incident can stop production, put people at risk and trigger a disclosure obligation on the same day.
Keep oversight and management separate
The committee oversees. Management owns the systems, the controls and the people who run them. Writing that line into the charter settles most arguments before they start, and it keeps directors out of day-to-day operations.
Route it through audit and risk
On a smaller board I have this committee report through the audit and risk committee. Cyber risk and financial controls then meet in one place, and the board hears one integrated account of risk. It also allows the committee to include members who would not meet the independence tests that apply to an audit committee.
Treat operational technology as a safety matter
In mining, the systems that run hoists, ventilation and processing plants are operational technology. A breach there is a safety, environmental and continuity event. I place the committee chair on the sustainability, HSE and technical committee as well as audit and risk, so site security is overseen by people who understand the site.
Give the board a standard it can test
A charter that says "oversee cybersecurity" gives directors nothing to measure. Adopting a recognized framework, such as the NIST Cybersecurity Framework or ISO 27001, does. The committee can then ask where the company stands against the framework, what the last penetration test found and what has been fixed since.
Put the right items on the agenda
The duties I write into the charter are these:
- The security framework and the company's progress against it.
- Penetration testing and remediation.
- The use of AI, model risk and human oversight of automated decisions.
- Privacy obligations in every jurisdiction where the company operates.
- Incident escalation and breach notification.
- Cyber risk carried by vendors and outsourced providers.
A material cyber incident should also be assessed promptly as potential material information for disclosure purposes. The committee meets at least quarterly and promptly after any material incident, and it reports to audit and risk after each meeting. A four-quarter work plan turns the charter into an agenda, so every topic gets its turn in the year.
When no director has the expertise
Early boards often lack a director with deep technology experience. An outside chair can fill the gap with firm limits in place. The committee is advisory and holds no delegated authority. The chair signs the board's conflict, confidentiality and conduct undertakings, any fees are disclosed, and the appointment ends automatically once a qualified director joins, the company lists, or two years pass.
The test I apply is simple. Every director should be able to name the company's most serious technology risks and say what is being done about each one. When they can, the committee is working.