Site icon Roundbox Consulting

How to choose an IT expert for Your Not for Profit Board

Crossing board boundaries in IT governance

Executive Takeaway: Many boards mistakenly appoint “the IT person,” a vendor, or rely on a single tech-savvy director, which can lead to governance risks and blurred roles between management and oversight.

 

I really, really wish that Not for Profits would stop recruiting technology experts onto their boards just because they work in IT.

Over the last few years, cybersecurity, AI, privacy and digital transformation have become board-level issues, rather than back-office concerns.

The problem is that many boards are responding with terrible recruitment processes for more technical board directors. By that, I mean they choose this director because they are…

A few weeks later, that person is sitting on the board or a committee because they’re now considered “the technology expert.”

Risk mitigated, right?

Not from my experience.

 

Why boards keep making this mistake

To be fair, I understand how it happens.

Few directors have a background in technology. They built their careers in finance, operations, legal, or other disciplines. Then suddenly they’re being told they need to understand technical risks.

That can feel overwhelming.

Faced with those concerns, many boards conclude they need “an IT person”.

The problem is that they often focus on technical expertise alone when they should be also focusing on governance capability.

When a board recruits solely for IT knowledge, I’ve often seen some of the worst governance behaviours because they don’t understand their board responsibilities.

The board asks them to help with cybersecurity risks. Instead, they start questioning operational decisions.

The board asks them to provide strategic advice.  Instead, they start debating software products.

The board asks them to help recognise technology project risk. Instead, they start acting like an unofficial IT project manager.

None of this usually comes from bad intentions. It’s because they’ve spent their entire career solving operational problems.

But the role of a director is fundamentally different. The board’s real job isn’t hands-on technology. It’s governance.

One of the most important principles in governance is the separation between oversight and management.

Management decides how things are done. The board oversees whether the right things are being done.

Yet I regularly see technology-skilled board members crossing that line.

Ironically, the board brought them in to reduce technology risk. Instead, they created governance risk.

 

Please don’t appoint your current vendor

Sometimes I also see boards appointing current technology vendors or service providers to governance roles.

The reasoning usually sounds sensible: They know your organisation, and they know technology issues (at least some).

While this may be true, what’s forgotten is that they may also commercially benefit from the information discussed in meetings, and the decisions that are made.

Even if the individual is completely ethical, the conflict of interest remains. Boards need independent judgement, not advice from someone whose company may benefit from the outcome.

If you need a vendor’s opinion, invite them to present to the executive team or board when you need specific advice on an issue.

That’s very different from giving them a governance role where they have the authority to influence decisions.

 

Every director owns technology risk

Another misconception is that appointing one technology expert somehow transfers responsibility from all the other directors to them. It doesn’t.

In fact, the Australian Institute of Company Directors (AICD) and the Australian Information Security Association (AISA) state in their joint cybersecurity handbook that:

“Directors of all sizes of organisations have a key governance role to play in being aware of the cyber threat landscape, prioritising cyber resilience at their organisations, and developing capabilities for the oversight of cyber risk and effective responses to cyber crises.”

That statement is directed at directors generally, not a designated technology director.

A technology-skilled director can help the board ask better questions, but they don’t take responsibility away from the rest of the board.

So, what should boards look for in recruiting a technical expert?

If I were recruiting a technology-skilled director tomorrow, I’d look for governance experience or education as an absolute mandatory.

I’d want somebody who can:

 

In many cases, I’d be looking for a former CIO, technology executive or experienced director with broad IT and governance experience over somebody with deep technical expertise in a single area.

 

Five questions to ask before appointing an IT expert

Therefore, before appointing someone because they “work in IT”, ask:

  1. Have they previously served on a board or committee?
  2. Have they completed director training through organisations such as the Australian Institute of Company Directors or Better Boards?
  3. Can they clearly explain the difference between governance and management?
  4. Are they independent of our major technology suppliers and procurement decisions?
  5. Will they help the whole board build capability, or are they likely to become the person everyone defers to?
  6. Can they answer your questions and be a translator for the rest of the board in plain English?

The answers to those questions will often tell you far more than their technical qualifications.

Final thoughts

Technology and cyber risk mitigation are ultimately a responsibility of every board director.

The role of a technology-skilled board member is not to take that responsibility away from the rest of the board. It’s to help the board ask better questions and provide better oversight.

So, when you’re choosing a technology expert, don’t just ask whether they understand technology. Ask whether they understand governance.

Otherwise, they could be creating more risks than mitigating them.

I regularly help Not for Profits with IT governance. If you want a second opinion, let me know.

 

P.S. If you found this article helpful, you might want to read these too:

Tammy Ven Dange is a former charity CEO, Association President, Not for Profit Board Member and IT Executive. Today, she helps NFPs with strategic IT decisions, especially around major investments and risk mitigation.

Exit mobile version