In short: across more than 3,000 board evaluations in 17 countries, four recurring gaps explain roughly 80% of the King V readiness shortfall we see. Boards hold policies and charters but cannot evidence the outcomes those documents were meant to produce; evaluation cycles lean on a single quantitative survey when King V’s outcomes-based standard expects qualitative interview too; AI governance sits with IT or a cyber committee instead of the board itself; and disclosure content gets reconstructed after the evaluation instead of generated by it. Each gap has a specific, well-understood fix, and none of them require starting from zero.
Why “Substantially Ready” is the most common first score - and why that is fine
When a board works through a structured King V self-assessment for the first time, the honest answer to most items lands somewhere between Developing and Gap rather than Established. That produces an overall band of Materially Exposed or Substantially Ready far more often than King V Ready. Boards sometimes read that as a bad result. It is not - King V is deliberately outcomes-based rather than checkbox-based, and it raises the bar on purpose. The useful question is not whether your board scored perfectly on the first pass. It is whether the gaps that produced that score are the same four gaps almost every board has, because those four are well understood and specifically fixable.
Across more than 3,000 board evaluations in 17 countries, four recurring gaps account for roughly 80% of the King V readiness shortfall Celagenix encounters. If your own score landed in the Materially Exposed band, expect at least three of the four to apply to your board right now.
Gap one: evidence, not policy
The single most common finding is also the simplest to state. Boards have charters, codes of ethics, remuneration policies and risk frameworks in genuine abundance - but when asked to produce the actual outcomes those documents were supposed to generate, the evidence is not there. A code of ethics exists, but there is no documented instance in the last 12 months of it shaping a material board decision. A risk framework exists, but the risk register itself has not been reviewed this quarter.
King V’s Principle 9 - the formal evaluation of the board’s own performance - is the clearest example of why this matters, and it is worth calling out specifically. It is the keystone of King V’s accountability architecture: boards that cannot evidence a structured evaluation cycle covering the board-as-a-whole, individual directors, the CEO and each committee are functionally non-compliant on most of the other twelve principles too, because Principle 9 is the mechanism that is supposed to surface whether the other twelve are actually working. A policy is not evidence. An evaluation with documented findings and an owned action plan is.
How boards close it: per-principle outcome statements, drafted directly from evaluation evidence rather than from the policy document itself - a discrete, evidenced statement for each of the 13 principles, not a reference back to a charter.
Gap two: the qualitative gap
Most boards that do run a self-assessment run a quantitative survey and call it an evaluation. That is a reasonable instinct - a survey is fast, comparable, and easy to administer. It is also not enough under King V’s own bar. Board dynamics, dissent, and decision quality are not things a Likert-scale survey can capture. A director may rate “board effectiveness” an 8 out of 10 on a form while privately believing the chair dominates every discussion and dissenting views never make it into the minutes. A structured, confidential one-on-one interview surfaces that. A survey alone does not.
This is precisely why King V’s own evaluation-methodology principle rewards evaluations that combine structured quantitative scoring with confidential qualitative interview, rather than relying on a single instrument - and why the interview has to be independent and confidential enough that directors will actually say what they think, including about each other and about the chair.
How boards close it: confidential one-on-one director interviews, conducted by an independent governance advisor rather than in-house, layered on top of the quantitative scoring rather than instead of it.
Gap three: AI governance is delegated, not owned
This is the newest of the four gaps, and the fastest-growing. Most boards still treat AI risk as an IT matter or fold it into an existing cyber committee’s mandate. Under King V, AI oversight is explicitly a board obligation, not a delegated one. That distinction shows up in four places a board should be able to answer for directly: whether AI is named as its own category in the risk register (distinct from “technology” or “cyber”); whether the board receives a current inventory of the organisation’s actual AI use-cases, including any touching customer or employee data; whether a board-approved AI policy exists covering ethical use, model risk, third-party AI procurement and human oversight; and whether the board itself has, or has a documented plan to acquire, enough AI literacy to oversee that risk meaningfully rather than rubber-stamping it.
How boards close it: a focused AI Governance Status Assessment that scores the board specifically against these four competencies, rather than assuming existing cyber governance already covers it.
Gap four: disclosure as an afterthought
The fourth gap is procedural rather than substantive, but it costs real time every cycle. The Company Secretary or governance lead typically reconstructs disclosure-ready content from the evaluation report after the fact - re-reading findings, re-drafting them into publishable per-principle statements, checking them back against the original evidence. That reconstruction step loses fidelity every time it happens, and it routinely adds weeks to a disclosure timeline that did not need to be that long.
How boards close it: generating disclosure-ready, per-principle outputs as a direct product of the evaluation cycle itself - in a publishable format from day one - rather than extracting them from a report after the evaluation is already finished.
What this means for your next cycle
None of these four gaps require a board to rebuild its governance function from scratch. Each is a specific, addressable change to how the next evaluation cycle is scoped and run: evidence over policy references, interview alongside survey, the board naming AI risk as its own line item, and disclosure output built into the process rather than bolted onto the end of it. Boards that address all four going into their next cycle consistently move from Materially Exposed toward King V Ready inside a single reporting period.
Score your own board against these same items
The full structured checklist behind this article is free to complete - 27 items across King V’s 13 principles, disclosure requirements, evaluation methodology and AI governance, with the same four-band scoring used here. Enrolment in Celagenix® Academy also unlocks a live-scored interactive version.
Get the free King V Readiness Checklist →Frequently asked questions
It is a structured self-assessment result, typically expressed as one of four bands - Compliance Risk, Materially Exposed, Substantially Ready, or King V Ready - based on how a board answers a set of evidence-based questions across King V’s principles, disclosure requirements, evaluation methodology, and AI governance. Most boards land in the middle two bands on a first pass; that reflects King V’s deliberately high, outcomes-based bar rather than an unusual result.
Principle 9 is King V’s own requirement that the board formally evaluate its own performance - the board-as-a-whole, individual directors, the CEO, and each committee - with documented findings and an action plan. It functions as the accountability mechanism for the other twelve principles: without a working evaluation cycle, a board has no reliable way to know whether its charters, risk oversight, or disclosure practices under the other principles are actually functioning as intended.
King V treats AI risk the same way it treats other material risks the board is accountable for overseeing: with a named category in the risk register, an inventory of actual use-cases, a board-approved policy covering ethical use and third-party procurement, and enough board-level AI literacy to oversee it meaningfully. Delegating AI oversight entirely to IT or a cyber committee leaves that board obligation unmet even if the technical controls themselves are sound.
On its own, generally not to the standard King V expects. A quantitative survey captures ratings but not board dynamics, dissent, or decision quality - the things a confidential one-on-one interview is specifically designed to surface. King V’s own methodology principle rewards evaluations that combine both rather than relying on a survey instrument alone.
BoardEvaluator™ maps its 19 evaluation modules directly to King V’s 13 principles and the disclosure and AI-governance requirements alongside them, combines structured quantitative scoring with independent qualitative interviews in a single cycle, and produces per-principle disclosure-ready outputs directly - rather than requiring a manual reconstruction step after a generic survey tool closes.