Insights / Board Governance · Risk Oversight
Board Governance Insight · Celagenix® Academy

Emerging Risks at Board Level: What Oversight of AI, Climate and Cyber Actually Looks Like

When the Transnet ransomware attack seized a region’s supply chain, the board’s question was not who clicked the link. It was whether the board had overseen a risk everyone knew was rising.

In short: AI, climate and cyber do not create a new legal duty - they apply the existing duty of care, skill and diligence under section 76(3) of the Companies Act to fast-moving territory. For cyber, the board cannot delegate accountability and must be able to meet POPIA’s section 22 breach-notification obligation. For climate, the board is accountable for the disclosures it signs and must govern a long-horizon risk. For AI, the priority is knowing where AI is used and ensuring accountability structures exist, including under POPIA section 71. The strongest oversight artefact is a documented record of the questions the board asked - because oversight you cannot demonstrate is, in law, oversight you did not exercise.

In July 2021, Transnet - one of South Africa’s largest state-owned enterprises - was hit by a ransomware attack that crippled operations at the Durban, Ngqura, Port Elizabeth and Cape Town harbours. Container terminals ground to a halt and a force majeure was declared. The supply chain for an entire region seized up, not because of a strike or load-shedding, but because of a cyber intrusion the organisation’s controls did not stop. The question the board had to answer afterwards was not “who clicked the link?” It was this: had the board provided adequate oversight of a risk everyone in the room knew was rising? Cyber, climate and artificial intelligence are three risks moving faster than most board agendas. Here is what oversight of them looks like - and what it does not.

The duty is old; the risk is new

Emerging risks do not create a new legal duty. They apply an existing one to unfamiliar territory. Under section 76(3) of the Companies Act 71 of 2008, a director must exercise their powers and perform their functions in good faith and for a proper purpose, in the best interests of the company, and - critically - with the degree of care, skill and diligence that may reasonably be expected of a person carrying out those functions. That standard does not exempt you because artificial intelligence is technical, because climate science is contested, or because cyber-security is specialised. It asks what a reasonable director in your position ought to have done, including seeking the information and expertise needed to oversee the risk. King V frames the same duty as governing risk and opportunity in a way that supports the organisation’s strategic objectives. The difficulty is that these risks move at a pace the standard quarterly board cycle was never designed for. The oversight failure is rarely “we ignored it”; it is far more often “we discussed it too slowly, too shallowly, and too late”.

Cyber: from IT problem to board accountability

Start with cyber, because it is the most mature of the three. The most common oversight failure is treating cyber-security as a matter fully delegated to the Chief Information Officer. Operational responsibility can be delegated; oversight accountability cannot. Adequate cyber oversight means the board receives regular, intelligible reporting on the organisation’s material exposures - not raw technical dashboards - and confirms that an incident-response plan exists and has been tested, not merely written. There is also a hard legal edge. Under section 22 of the Protection of Personal Information Act, where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify both the Information Regulator and the affected data subjects. That obligation cannot be met by a board that first hears of a breach when it reads about it in the newspaper. The single most powerful oversight artefact is unglamorous: a standing cyber-risk item on the risk or audit committee agenda, with named accountability and a documented trail of the questions the board asked.

Climate: disclosure, materiality and the long horizon

Climate risk presents two distinct exposures. Physical risk is the direct impact of extreme weather, water scarcity and flooding on assets and operations - think of the 2022 KwaZulu-Natal floods and their effect on manufacturing and logistics. Transition risk is the financial impact of moving to a low-carbon economy: carbon pricing, stranded assets, and shifting investor expectations. The disclosure environment has hardened. The JSE Sustainability and Climate Disclosure Guidance published in 2022 sets clear expectations for listed issuers, and the Carbon Tax Act 15 of 2019 puts a direct price on emissions. The oversight challenge is the horizon: the most serious impacts may sit beyond the current board’s tenure, yet the board must still take a long-term, integrated view of value creation. Adequate climate oversight looks like this - climate integrated into the strategy discussion rather than quarantined in a sustainability report, the board reviewing scenario analysis rather than a single optimistic projection, and the board taking responsibility for the accuracy of climate disclosures. The integrated report the board approves is a document for which the board is accountable, and overstating climate performance is a disclosure risk with regulatory and reputational consequences.

AI: the newest and least governed

Artificial intelligence is where the oversight gap is widest, because adoption inside organisations is running well ahead of governance. AI is already making or influencing decisions in credit scoring, recruitment, fraud detection and customer engagement - often without the board being fully aware of where and how. The board should understand three categories of AI risk. First, bias and fairness: a model trained on skewed data can produce discriminatory outcomes at scale, with clear implications under equality and consumer-protection law. Second, accountability and explainability: if a decision cannot be explained, it cannot be defended to a regulator, a court, or a customer. Third, data and privacy: AI systems consume personal information, which brings you straight back to POPIA, and section 71 in particular restricts decisions based solely on automated processing that profile a person and carry legal or similarly significant effects. Adequate AI oversight begins with a question most boards cannot yet answer: where in this organisation is AI being used, and who is accountable for it? From there - is there an approved AI-use policy, and is there meaningful human oversight of material automated decisions? Oversight here is not about the board understanding the algorithms; it is about the board ensuring accountability structures exist.

A worked example: the AI credit-scoring proposal

Consider your position as a non-executive director on the risk committee of a JSE-listed financial-services company. Management tables a proposal to deploy an AI-driven credit-scoring model that will approve or decline retail loan applications automatically. The paper is impressive: faster decisions, lower costs, a competitive edge, and a recommendation to approve. The temptation is to note the efficiency gain and move on. What does adequate oversight require of you? First, ask about bias: on what data was this model trained, and has it been tested for discriminatory outcomes across race, gender and geography? Second, ask about section 71 of POPIA: are these decisions solely automated, and if so, is there a mechanism for a person to request human intervention? Third, ask about explainability: if the Information Regulator or a declined applicant asks why a loan was refused, can the organisation give a defensible answer? Notice what you are not doing. You are not writing the model, and you are not vetoing innovation. The correct outcome is rarely a flat yes or no - it is approval subject to conditions: bias testing completed, a human-review pathway established, and a reporting-back date set, with every one of those conditions recorded in the minute.

Oversight you cannot demonstrate

Across all three risks the pattern is identical: the duty of care applied early enough to matter, and documented well enough to demonstrate. In your next board meeting, treat AI, climate and cyber not as technical topics to be delegated but as standing oversight matters - put each one on the agenda, ask the questions that test whether accountability exists, and ensure those questions are recorded in the minutes. Because when an emerging risk becomes a live crisis, the record of what the board asked, and when, is what stands between diligent oversight and personal liability. Oversight you cannot demonstrate is, in law, oversight you did not exercise.

Explore BoardEvaluator™

How well does your board oversee emerging risk?

BoardEvaluator™ assesses the effectiveness of the board as a whole - including how it governs fast-moving risks like AI, climate and cyber - and produces a structured, evidence-based view of where oversight is strong and where it is thin.

See the Board-as-a-Whole evaluation

Frequently asked questions

Do emerging risks like AI and climate create new duties for directors?

No. They apply an existing duty to unfamiliar territory. Section 76(3) of the Companies Act 71 of 2008 requires directors to act with the degree of care, skill and diligence reasonably expected - a standard that is not waived because a risk is technical or specialised. King V frames the same obligation as governing risk and opportunity in support of the organisation’s strategy.

Can a board delegate cyber risk to the IT function?

It can delegate operational responsibility, but not oversight accountability. Adequate cyber oversight means the board receives intelligible reporting on material exposures, confirms that a tested incident-response plan exists, and can meet POPIA section 22, which requires notifying the Information Regulator and affected data subjects where there are reasonable grounds to believe personal information was accessed by an unauthorised person.

What does board oversight of climate risk involve?

Governing two exposures - physical risk (extreme weather, water scarcity, flooding) and transition risk (carbon pricing, stranded assets, shifting investor expectations) - against a disclosure environment shaped by the JSE Sustainability and Climate Disclosure Guidance (2022) and the Carbon Tax Act 15 of 2019. The board reviews scenario analysis, integrates climate into strategy, and is accountable for the accuracy of the climate disclosures it approves.

What are the main categories of AI risk a board should understand?

Three: bias and fairness (a model trained on skewed data can discriminate at scale); accountability and explainability (a decision that cannot be explained cannot be defended to a regulator, court or customer); and data and privacy (AI consumes personal information, engaging POPIA, including section 71 on solely automated decisions). Oversight is about ensuring accountability structures exist, not understanding the algorithms.

How should a board respond to a proposal to deploy an automated credit-scoring model?

Not with a flat yes or no, but with approval subject to conditions. The board should ask whether the model has been tested for discriminatory outcomes, whether the decisions are solely automated and offer a human-review pathway under POPIA section 71, and whether a declined applicant or the Regulator could be given a defensible explanation - then approve subject to bias testing, a human-review pathway and a reporting-back date, all recorded in the minutes.

← Back to Insights