In November 2025, during an Executive Committee meeting with a fintech client, a pivotal question was raised by a board member: “If a large enterprise evaluates us tomorrow for a buyout, can we prove we are trustworthy — not just secure?” This question highlighted a significant shift that many organizations are unprepared for. Security has evolved through three key phases: - Initially focused on defense - Then centered on compliance - Now, it is about digital trust as a growth function In regulated markets, trust influences: - Procurement speed - Sales cycle duration - Partnership approvals - Regulatory scrutiny management By 2026, the focus of boards will shift from asking CISOs, “Are we secure?” to “Can we prove trust — continuously, to anyone who matters?” This shift alters the landscape entirely. For CISOs, the role will expand from control ownership to trust orchestration. For CEOs, trust will transform into a revenue lever rather than merely a legal checkbox. In board and executive discussions, I utilize a three-stage lens: - Posture: What you claim to have (policies, controls, frameworks) - Proof: What you can demonstrate on demand (evidence, mappings, assurance) - Performance: What you can sustain over time (monitoring, metrics, outcomes) Most organizations find themselves stuck at the Posture stage; they may appear compliant on paper, but struggle when proof is requested. They often falter when continuous proof is necessary. The meeting concluded with a critical realization: “Security tools don’t create trust. Evidence, visibility, and consistency do.” Digital trust is no longer just an IT issue; it has become a board-level growth conversation, and it is approaching faster than many leaders anticipate. Follow for weekly insights on digital trust, security, and leadership. Comment “TRUST” if you would like to receive the Digital Trust Maturity Lens.
Board governance and digital trust in 2025
Explore top LinkedIn content from expert professionals.
-
-
The New Governance Issues: AI Execution & Digital Readiness In more and more boardrooms today, I’m seeing a shift: AI execution, data governance, and digital readiness are no longer viewed as “technology matters.” Today they are increasingly viewed as governance matters. And activists have noticed. In recent months, activists have begun to probe companies on the gap between their stated digital ambitions and their actual ability to deliver measurable AI-driven value. They’re scrutinizing everything from data architecture and model-risk controls to adoption rates and ROI. In some campaigns, the pressure point isn’t compensation, it’s audit and risk oversight. For Boards and executive teams, the message is clear: If AI is truly “core” to strategy, there must be clear ownership, clear metrics, and clear evidence of execution. What I’m advising leaders today: • Treat digital and data readiness as part of enterprise risk—and review it with the same rigor you apply to financial controls. • Define 12–24-month AI value roadmaps tied to accountable owners, budgets, and hurdle rates. • Track results using business KPIs, not vanity metrics. • Strengthen model-risk governance: inventory, testing, monitoring, and documentation. • Educate the Board, especially Audit and Risk committees, so oversight keeps pace with velocity. • Ensure disclosures match reality, activists are reading between the lines. This isn’t about building flashy innovation labs. It’s about alignment, accountability, and execution, exactly the areas where governance matters most. The companies that get this right won’t just avoid activist pressure, they will accelerate value creation. #CorporateGovernance #Boards #ExecutiveLeadership #AI #DataStrategy #RiskManagement #DigitalTransformation
-
Navigating the Intersection of Technology, Risk and Governance : 🔸 In the modern boardroom, the siloed approach of considering "IT issues," "compliance", "corporate strategy", "financial numbers" as distinct chapters is retreating. ✔️ As an advisor and Independent Director specializing in #TechReg , cyber and governance, I spend my time at the intersection of these three forces. In the automated, AI-driven world where #innovation needs to match steps with #trust, these forces are merged into a single, complex narrative, where the Boards need to view TechReg not as a hurdle, but intertwined onto the financial, risk and strategy discussion rooms (or committees) as gear-throttle-break that can take the business forward in the desired speed. 🔸 The "governance" piece is currently being tested by Generative AI. We are at crossroads where the pressure to adopt AI to stay relevant is clashing with the need for ethical guardrails and data integrity. ✔️ I advocate a "Governance by Design" framework, wherein oversight and controls are considered and incorporated at the inception of a project, rather than as a bolt-on after say, the software has been deployed. 🔸 Cybersecurity has graduated from the server room to the boardroom, thanks to the guidelines / mandates from key Indian regulators such as RBI, SEBI, IRDAI. However, the challenge I still see is the use of technical jargon, whereby conversations may get stuck. ✔️ I often play the role to 'translate' such tech terms into business and fiduciary 'English'; example "zero-trust architecture" and "endpoint detection" into automated controls built in to ensure that users need to prove their approved rights and authority to access systems, and, controls in the employees' systems to monitor, detect, intimate for any virus, malware etc. 🔸 Effective #cyber #governance involves asking not just questions such as 'are we secure'. ✔️ I help the Boards review detailed presentations, with impact analysis, financial numbers, risk rating et all, on say, how long can we survive a total systems outage, and steps-roles-procedures to recover from the same. ✔️ As an Independent Director, my goal is to ensure that the Board doesn't just "oversee" technology and financial ratios but truly understand how they should talk in sync and become a fundamental value driver in a digital first business. 🔸 With the world moving towards prescriptive technology regulation in the face of increasing number and category of threats, whether RBI, SEBI, IRDAI, DPDP Act and international rules such as DORA, EU AI Act et all, #compliance has moved from a back-office function into competitive advantage. ✔️ I help the Board to take a multi-directional lens to assess, say, how tech scalability and operational risk appetite fit into the 5-year business growth plan; to build the bridge between tech governance and financial balance sheet. #cyberboarddirector #cybersecurity #technology #riskmanagement #digitaltransformation
-
AI & the Boardroom: Asking the Right Questions 🤖⚡ Across several recent board engagements, one thing is clear: boards and executive teams still aren’t fully aligned on #AI. Too often, AI is seen as a tech issue — when it’s actually a business and governance issue that shapes strategy, culture, talent and risk. In a world where AI evolves daily, leadership isn’t about “knowing it all,” but about learning fast, asking better questions, and leading with clarity and curiosity. 🔍✨ That mindset powered an energising session with ~100 senior leaders at the Corporate Directors Programme 2025 for TERENGGANU INC— focused on helping boards move from understanding AI to creating value with AI. To support this, we emphasised our “show, not just tell” approach — sharing real-world AI transformations we’ve implemented with clients across the globe. These examples help boards see what good looks like, what’s possible, and how to scale responsibly. And we introduced our PwC AI Leadership Playbook, specially curated for boards and senior leaders to navigate uncertainty with confidence. Huge thanks to Clarence Chan, Sau Shiung Yap and Sundara Raj Ramamurthy for shaping this work. What Boards Should Do Next: 🚀 🌐 Cut through the noise 🎯 : Anchor AI discussions on real business outcomes, not hype. 🌐 Move from PoC to proof of value 📈 : Scale what works with measurable impact. 🌐 Set realistic expectations 🧭: AI success comes from governance, talent and iteration. 🌐 Champion responsible AI🛡️⚖️: Ensure transparency, trust and accountability are built in. 🌐 Reimagine services (especially public sector) 🏗️ : Go beyond efficiency to better citizen experience and stronger trust. 🌐 Empower the workforce 🧑🏫: Give your people the skills, tools and trust to adopt AI confidently and responsibly at scale. Huge thanks to Dato’ Burhanuddin Hilmi Mohamed and the TERENGGANU INC team for partnering with us as Knowledge Partner for #CDP2025. When governance and innovation align, real transformation follows. 🌍💼 Nurul Ain Abdul Latif Khoon Yean Soo Hoo Muhammad Fahmi Mohd Khalid (MY) #AILeadership #BoardGovernance #PwC #DigitalTransformation #AIinMalaysia #CorporateDirectorsProgramme #FutureOfLeadership #AIForGood #PublicSectorInnovation #LeadershipPlaybook
-
Is your Board ready for the most consequential phase of AI? 🚀 AI is no longer just a "tech topic" - it’s a fundamental shift in how value is created and how organizations are governed. I’ve been diving into the new AI Governance Principles for Boards developed by KPMG in collaboration with the INSEAD Corporate Governance Centre. These five principles offer a roadmap for directors to move from experimentation to enterprise-wide transformation with confidence. The 5 Pillars of AI Governance: 1️⃣ Strategy: Oversight of AI for long-term value, not just short-term gains. 2️⃣ Technology: Managing sovereignty, security, and vendor dependencies. 3️⃣ Workforce: Defining human-in-the-loop accountability and upskilling. 4️⃣ Trust: Ensuring AI is fair, inclusive, and environmentally responsible. 5️⃣ The Board itself: Updating governance structures to match the pace of AI. As Annet Aris (INSEAD) notes, trust isn't a constraint on AI - it’s the foundation that allows it to scale. The stakes are high. The decisions boards make today will determine which companies lead tomorrow. Read the full report to sharpen your boardroom judgment. Stephen Chase | Theodoros Evgeniou | Tanmay D. | Samantha Gloede Keane | Dhawal Jaggi #AIGovernance #CorporateGovernance #AIStrategy #Leadership #KPMG #INSEAD #DigitalTransformation #BoardOfDirectors
-
To CEOs & Boards of Indian Banks and Fintechs: DPDP Rules Are Live – Your immediate Action Clock Has Started.. November 14, 2025 – the Digital Personal Data Protection (DPDP) Rules, 2025 were notified. This isn’t another draft. Effective immediately- core obligations under India’s first comprehensive privacy law apply to every institution processing customer data. Board-Level Decisions Required: 1. Mandate DPO Appointment (India-based, Board-reporting) - Significant Data Fiduciaries (most digital banks, payment gateways, lending platforms) must have a named DPO by Nov 2026 - but start the search now - Board resolution needed: DPO to have direct escalation to Audit Committee; contact details public on website. 2. Approve ₹X Cr Privacy Budget for FY26 - Consent management platforms (₹2–5 Cr for mid-sized fintechs) - DPIA tooling + breach notification automation - Mandatory 72-hour DPB reporting capability (align with RBI’s 6-hour SOC rule) 3.Sign Off on Consent Overhaul - Kill legacy “implied” consents. - Mandate verifiable, granular, withdrawable consent at onboarding (app + branch). - Board to review sample notice in English + 3 regional languages. CEO’s Sprint: - Map all data flows (KYC → lending → marketing) - Confirm Significant Data Fiduciary (SDF) status - Add DPDP audit clauses to all vendor contracts Risk if you delay: - ₹250 Cr per breach (DPB) - ₹150 Cr for DPO non-compliance - RBI show-cause for misalignment with Digital Lending Guidelines Opportunity if you lead: - First-mover trust in a ₹100+ Tn digital economy - Consent-as-a-moat for customer retention #Views are personal #DPDPAct #BoardAgenda #FintechCEOs #BankingBoards #PrivacyByDesign
-
Five Questions Every Board Should Be Asking About AI Most boards are asking: What are we deploying? What is the ROI? Are we compliant? Important questions. But not the most important ones. The stronger boards are asking tougher questions: 1. Which decisions should never be delegated to AI? Just because AI can support a decision doesn’t mean it should make one. Some decisions require permanent human judgement. 2. Where could AI create systemic risk in our business? Risk doesn’t always sit in the model. It may sit in: Data quality Vendor dependencies Bias exposure Reputational amplification That changes the oversight challenge. 3. Who is accountable when AI goes wrong? Ownership is often dangerously unclear. Technology teams may build it. Business teams may use it. But who owns consequences? Boards should know. 4. Do we have governance that scales with adoption? Many organisations scale pilots faster than oversight. That gap becomes tomorrow’s risk event. 5. Are we governing for trust - or just compliance? Compliance protects downside. Trust creates long-term advantage. That distinction matters. My view: The AI governance conversation is moving from technology risk to board fiduciary responsibility. That is a major shift. Boards that understand it early will lead. Which of these questions do you think boards are asking too little today? #AIGovernance #BoardGovernance #ResponsibleAI #AILeadership #RiskManagement #DigitalTrust #CorporateGovernance
-
The article "Will AI Replace the Board-or Sharpen Its Strategic Edge?" in the Fall 2025 edition of NACD (National Association of Corporate Directors)'s Directorship magazine had me reflecting on my own experience of AI and boardrooms. We’re witnessing a quiet but profound shift in how boards operate on the journey from Awareness to Augmentation to Advisor. ▪️ Awareness is the first phase: ensuring management and directors understood AI’s potential and its risks. Many boards are still here: discussing policies, ethics, and disclosures, but awareness alone doesn’t drive enterprise or shareholder value. ▪️ Augmentation is where leading boards are today: using AI tools to enhance decision-making, surface insights faster, and improve governance workflows. Committee reports, investor sentiment, and risk dashboards should now be informed by intelligent systems that help directors see patterns in complexity. ▪️ Advisor is where long term value is created: where AI doesn’t just inform what we know, but advises how we decide. Boards would increasingly rely on AI to model outcomes, anticipate stakeholder responses, and assess leadership readiness in the effort to reshape the rhythm and dynamics of board dialogue itself. Some boardrooms are not broken, but all can get just a bit better along this journey. Every member of management and director will need digital fluency, not just digital literacy. The future boardroom isn’t replacing human judgment - it’s amplifying it. That is an exciting place to be. The boards that thrive will be those that combine wisdom, data, and humanity in equal measure. #BoardGovernance #AILeadership #CHRO #FutureOfWork #CorporateGovernance #BoardComposition #HumanCenteredAI
-
https://lnkd.in/eTbCzJtq This kinda struck a nerve...(referencing the article)...The Digital Duty of Care I know boards have long understood their duty of care in the physical world—financial oversight, safety, compliance, and culture. That responsibility now extends fully into the digital domain. Digital Duty of Care is a fiduciary obligation, not a technical consideration. The data in the article reinforces the scale of the issue. Boards increasingly identify AI and machine learning and cybersecurity and data privacy as top enterprise risks. These are not IT concerns. They are strategic risks with direct implications for valuation, trust, regulatory exposure, and long‑term resilience. From a governance perspective, these risks are no different from failures in financial controls or safety oversight. Despite this, board‑level capability and strategic focus in Cyber and AI remains insufficient. Again, from the article, fewer than one‑third of boards report having meaningful cybersecurity expertise. This gap exposes organizations to systemic risk and undermines effective oversight in an AI‑enabled operating environment. The role of the CISO has evolved from technical defender to business risk executive and strategic advisor. Organizations that expect systemic risk management must empower leaders capable of operating at the board and enterprise level. Boards serious about governance in the AI era must treat digital risk as a core strategic lens, not a periodic update. This includes strengthening board composition by adding directors with deep cybersecurity and digital risk expertise, ideally at the CISO or equivalent level, and prioritizing leaders who understand the integration of AI, cyber risk, and business strategy. Specifically: -- Appoint CISO-level directors (I know a good candidate) 😊 -- Prioritize leaders who understand AI, cyber, and business integration -- Treat digital risk as a core lens for strategy—not a quarterly update The bottom line is that Digital Duty of Care will define the next generation of responsible leadership. Boards must act proactively to strengthen oversight, capability, and accountability—before a digital failure forces the issue. The question is not whether boards should engage differently…It’s whether they do so before or after that failure forces the issue. And then it gets expensive, disruptive, and distracts from all the good things the business wanted to do prior to the cyber event. #CyberSecurity #CISO #BoardGovernance #AI #RiskManagement #DigitalTransformation #CyberRisk #Leadership
-
Boards aren’t ready for what AI just learned to do. These 7 shifts won’t wait for your Q4. 1️⃣ AI is making decisions without board approval. By late 2025, 25% of large firms will deploy AI agents. They approve invoices, adjust ops, and trigger actions. Most boards lack audit paths, oversight, or escalation. 2️⃣ AI talent is a governance failure in motion. Only 1% of firms report mature AI capability. 62% cite tech talent as their top digital risk. Few boards have any AI-literate oversight today. 3️⃣ Robots are serving customers before you're ready. Eldercare robots will hit $3.5B in revenue this year. Service robotics now scale health, retail, logistics. Boards still treat robotics like a 2030 problem. 4️⃣ Trust is collapsing, boards are not exempt. 71% of people trust firms less than a year ago. Gen Z trust in institutions is under 30%. Transparency is no longer optional. It’s survival. 5️⃣ AI is a new ESG liability, ready or not. One LLM can emit 300–500 metric tons of CO₂. Carbon audits now hit cloud and model operations. Boards must align AI with ESG, before regulators do. 6️⃣ Geo-tech risk is now board-level exposure. Chip bans disrupt 40% of key supply chains. Sovereign AI is reshaping vendors and procurement. Geopolitics must be a standing board agenda item. 7️⃣ AI-driven layoffs are no longer invisible. 76,000 tech layoffs have hit already in 2025. 41% of firms cite AI as the workforce cut driver. Backlash is no longer theory, it’s political risk. ➕ Bonus trendlines no board can ignore: Quantum may break core AI encryption assumptions. Deepfakes now sabotage brands, leaders, and markets. “Neutral AI” remains a legal and ethical dead zone. AI won’t take your board seat. But it’s changing how you deserve to keep it. Are we ready for the AI agents?