Twenty years ago, being a good director meant understanding the business, reading and understanding the papers, attending meetings, challenging management and exercising judgement. None of that has changed.
What has changed is the environment in which that judgement must now be exercised.
Boards oversee more regulation, more technology, more data, more third-party dependencies and more cyber risk. They are expected to understand AI systems capable of making or influencing decisions, increasing expectations around operational resilience, more complex supply chains and businesses operating across multiple regulatory jurisdictions at once.
At the same time, directors remain part-time overseers, deliberately independent of the organisations they govern. That creates a governance paradox.
Directors are increasingly expected to know more, oversee more and, crucially, evidence more, while remaining structurally apart from the day-to-day management of the organisation.
Look closely at where governance standards, regulators and boards themselves are heading and a common theme begins to emerge.
The future of governance may not simply be more governance. It may be the ability to demonstrate that governance actually happened.
The global benchmark has already moved The G20/OECD Principles of Corporate Governance are probably the closest thing the world has to a common reference point for where governance expectations are heading.
Endorsed by G20 leaders in 2023, they are one of the Financial Stability Board's Key Standards for Sound Financial Systems and form the basis for the World Bank's assessments of national corporate governance frameworks.
That matters because the latest revision significantly widened the lens through which boards are expected to think about governance.
For the first time, the Principles contain a dedicated chapter on sustainability and resilience. Boards are expected to consider material sustainability risks through strategy, risk management, internal controls and disclosure. The Principles also explicitly bring digital security, data privacy, supply-chain disruption and geopolitical risk into the modern risk environment.
One detail deserves particular attention. The OECD notes that some boards have established committees specifically to advise on digital security risks and digital transformation.
Think about what that represents - Technology was once largely an operational matter. Cybersecurity became a risk matter. Digital transformation became a strategy matter. AI is rapidly becoming all three.
The boundary of what constitutes a board-level issue keeps expanding.
Specialist committees may advise. Experts may be brought in. Management may own implementation. But the responsibility of the board does not disappear simply because the subject becomes more technical.
That principle may become increasingly important as board agendas become more complex.
Internal controls stop being a description and start becoming evidence The UK's Provision 29 provides perhaps the clearest indication of where governance could be heading. For financial years beginning on or after 1 January 2026, boards reporting under the UK Corporate Governance Code must do more than describe their risk management and internal control framework. They must monitor it, review its effectiveness, explain how that monitoring and review took place, and make a declaration regarding the effectiveness of the company's material controls at the balance-sheet date.
Those controls are not confined to finance. They include financial, operational, reporting and compliance controls.
There is another change in the 2024 Code that received less attention but may be just as revealing. Companies are now encouraged to focus their governance reporting on board decisions and their outcomes, rather than simply describing policies and processes. That distinction matters.
For years, corporate governance reporting has been capable of telling shareholders that structures, committees, policies and processes exist. The direction is increasingly towards a harder question.
Did they actually work?
A policy is not evidence that a risk was controlled. A committee is not evidence that effective oversight took place. A board paper is not evidence that its contents were understood or challenged. And a governance framework is not evidence that governance was effective.
That is a subtle shift, but potentially a profound one.
Governance is moving from describing what exists towards demonstrating what happened.
Boards are starting to admit their own capability gaps There is another uncomfortable signal coming from directors themselves. PwC's 2025 Annual Corporate Directors Survey found that 55% of directors believed at least one of their fellow board members should be replaced. It was the highest figure in the survey's history and the first time it had crossed 50%.
The reasons are revealing. They include a lack of meaningful contribution, long tenure affecting performance and insufficient relevant expertise.
This is not necessarily evidence that boards are getting worse. It may instead be evidence that expectations are getting higher.
The range of issues a modern board is expected to understand has expanded rapidly. AI, cybersecurity, geopolitical risk, digital assets, operational resilience, sustainability, data, supply chains, financial crime, regulatory change and strategy itself increasingly compete for board attention.
The traditional model of a director bringing deep experience in one particular field remains valuable. Experience alone, however, is increasingly unlikely to cover the entire board agenda. That creates a different requirement.
Not omniscience, but access to reliable information, the ability to interrogate it and the confidence to challenge what sits outside a director's own expertise.
That may become one of the defining capabilities of the modern director.
Governance is becoming more continuous There is another structural change taking place. Traditional governance is periodic. Quarterly board meetings, annual reviews, periodic risk reports, scheduled control assessments and annual board evaluations have long provided its rhythm. Many of the risks boards oversee no longer operate on that timetable.
Cyber incidents happen in minutes. AI systems can process thousands of decisions before the next board meeting. Sanctions can change overnight. Geopolitical events can disrupt supply chains within hours. A significant cultural problem can develop long before it reaches a whistleblowing report.
The answer is not for boards to become management. That distinction remains fundamental.
What may need to change is the information supporting oversight. It may need to become more current, more connected and more capable of identifying where board attention is actually required. That creates an important distinction.
Governance cannot become continuous management. But the information supporting governance may increasingly need to become continuous.
AI changes the governance equation AI deserves particular attention because it presents boards with two challenges simultaneously. The first is obvious. Boards increasingly have to govern organisations that use AI. Where is it deployed? What decisions does it influence? What data does it use? What controls exist around it? Where does human oversight sit? Who remains accountable when an automated system gets something wrong?
But there is a second question. How should directors themselves use AI?
That question may prove just as important. The wrong answer is to outsource judgement to it. A director cannot delegate fiduciary responsibility to an algorithm. At the same time, refusing to use technology capable of helping interrogate increasingly complex information may eventually become equally difficult to justify. That creates an interesting governance boundary.
AI can identify, compare, cross-reference and summarise. It can challenge inconsistencies, surface regulatory obligations and recall what was said three meetings ago. It cannot assume responsibility for the conclusion.
AI may dramatically change how directors become informed. It does not change who is responsible for the judgement that follows.
Culture is becoming something boards can see earlier Culture has always presented boards with a problem. Everyone agrees it matters. Measuring it is considerably harder. Boards traditionally rely on employee surveys, management commentary, staff turnover and other indicators. By the time some of those measures move significantly, the underlying problem may already be well established.
Technology increasingly creates the possibility of identifying signals earlier. Anonymised sentiment, patterns in employee feedback, turnover, absence, customer complaints and conduct data can collectively provide a broader picture.
None of those measures can tell a board whether an organisation has a good culture. Nor should an algorithm attempt to make that judgement. But collectively they can provide evidence. Again, the principle is the same.
Technology provides the signal. The board provides the judgement.
The real information problem sits underneath all of it There is a structural problem beneath every one of these developments.
Information.
Consider what a director can now be expected to oversee: strategy, financial performance, internal controls, AI, cybersecurity, financial crime, operational resilience, culture, sustainability, regulatory change, third-party risk, geopolitics, data and increasingly emerging areas such as tokenisation and digital assets.
Now consider how the information required to oversee all of that often reaches the board.
A 400-page board pack delivered a few days before the meeting.
That model made sense when information was scarce. The modern problem is the opposite. There is too much of it.
The challenge is no longer simply obtaining information. It is identifying what matters, connecting one piece of information with another, recognising when something has changed, remembering what was promised three meetings ago, identifying where the evidence does not support the conclusion and knowing what question has not been answered.
A director can only exercise independent judgement over information they have genuinely had the opportunity to understand. That may be one of the most under-discussed constraints in modern governance.
Boards have never had more information. The challenge is making sure the right information leads to the right questions.
The board pack may no longer be enough This raises a more fundamental question about one of the most established features of modern governance.
The board pack.
It remains essential. But is a periodic collection of documents still sufficient as the primary information architecture supporting a modern director?
A board pack tells a director what management considers relevant for a particular meeting. Effective oversight increasingly requires something broader.
What was discussed previously? What action was promised? What changed? What regulatory obligation applies? What information conflicts with another paper? What has disappeared from the agenda? What risk is developing across several meetings rather than appearing clearly in one?
The board pack is a snapshot.
Governance increasingly requires a timeline.
That may ultimately be one of the biggest changes technology brings to the boardroom. Not replacing the pack. Connecting it.
The sharpest question boards will increasingly face It used to be enough for the relevant information to have been somewhere in the board pack. Increasingly, that will not answer the governance question. The harder question is:
What did the board actually do with it?
What was challenged? What evidence was requested? What alternatives were considered? What assumptions were tested? What action followed? Was that action completed? Did the issue return to the board?
And how was that oversight documented so that it exists somewhere beyond the memory of the people who happened to be sitting around the table?
This is where many of the developments now taking place in governance begin to converge.
Provision 29 requires boards to evidence their assessment of control effectiveness. The OECD increasingly embeds emerging and non-financial risks within board oversight. Directors themselves are demanding greater capability from fellow board members. Technology is making better information, connection and continuity possible.
The direction is increasingly clear.
Evidence of genuine engagement, not simply evidence that a process existed.
Better-informed judgement, not automated judgement Board portals solved an important problem. They digitised the board pack. PDFs replaced print. Email replaced post. Search replaced the filing cabinet.
But underneath the technology, the process a director actually goes through remained remarkably similar. Receive the information. Read it. Annotate it. Attend the meeting. Challenge. Decide. Then repeat the process at the next meeting.
The question worth asking now is whether the tools directors use are evolving as quickly as the responsibilities they carry. Artificial intelligence potentially changes that equation. Not by replacing directors. Not by making decisions for them. And certainly not by assuming responsibility.
It can, however, allow an individual director to interrogate hundreds of pages of information, identify inconsistencies, connect issues across successive meetings, cross-reference regulatory obligations, surface unresolved actions and independently test the information management has placed before them. That distinction is fundamental.
The future of governance is not automated judgement. It is better-informed human judgement, with better evidence behind it.
MyDirector-OS exists because of that gap.
BoardLens reviews board packs and other documents through the lens of the regulatory framework relevant to each appointment a director holds, helping identify risks, governance issues and matters requiring attention.
The Director's Assistant provides grounded, jurisdiction-aware answers against verified regulatory sources when a question needs to be explored independently.
Regulatory intelligence helps directors follow the frameworks relevant to the appointments they actually hold rather than attempting to monitor an entire regulatory landscape.
Continuity across meetings matters just as much, because effective governance is rarely contained within one document or one meeting.
An issue is raised. Management responds. An action is agreed. The next pack arrives. Three months pass.
Good governance requires the thread not to disappear.
None of these tools can decide what is material. They cannot determine whether evidence is adequate. They cannot decide whether management's explanation should be accepted. They cannot exercise a director's judgement.
Nor should they.
That responsibility remains exactly where it belongs - With the director.
The technology has a different purpose. It helps ensure that when judgement is required, the director arrives at it informed, prepared and capable of demonstrating how that judgement was reached.
Because that may ultimately be the biggest change coming to the boardroom.
The future of governance will not simply ask whether the board met, or whether the board received the information.
It will increasingly ask:
What did the board know?
What did it challenge?
What did it decide?
What happened next?
And what evidence exists to show that effective governance actually took place?
The future of governance is not automated oversight.
It is oversight that can show its working.
