Modern Governance, Challenges, Behaviours & Boardroom Influence

NED Capital Knowledge Centre  |  Adrian Lawrence FCA, Founder

The governance agenda facing UK company boards in 2025-2026 is the most complex it has been in the post-Cadbury era. The codification of corporate governance in the 1990s established the framework — independent NEDs, audit and remuneration committees, the comply-or-explain principle — within which UK boards have operated for three decades. That framework remains intact. What has changed is the scope and technical complexity of what boards are now expected to govern: artificial intelligence systems whose implications boards are still learning to assess, climate transition risks that require scientific and financial literacy to govern credibly, geopolitical shocks that affect supply chains and market access in ways that corporate strategy frameworks have not traditionally accommodated, and a regulatory environment that has expanded faster than most boards have been able to absorb.

This guide identifies the governance challenges that are generating the most board-level concern and presents an honest assessment of what adequate governance looks like in each area — including where most boards are currently falling short.

AI Governance — The Challenge Boards Are Least Prepared For

Of all the modern governance challenges facing UK boards, artificial intelligence governance is the one where the gap between what boards are expected to do and what they are currently doing is largest. The FCA, the ICO and Ofcom have all published expectations for board-level AI oversight. Most board members do not have the technical familiarity with AI systems to assess whether management’s AI governance framework is adequate, let alone to challenge specific AI deployment decisions.

The board’s AI governance responsibility has two distinct dimensions. The first is AI ethics and risk — ensuring that AI systems the organisation deploys do not produce biased, inaccurate or unexplainable outcomes that create regulatory or reputational risk. The ICO’s Children’s Code, Article 22 of UK GDPR on automated decision-making rights, and sector-specific regulatory guidance all create specific compliance governance obligations. See our AI Ethics Board Member page for more on this governance function.

The second is AI transformation governance — ensuring that the organisation’s AI adoption strategy is credible, that AI investment is delivering the expected returns and that AI implementation programmes are governed effectively. See our AI Transformation NED page for more on this dimension.

What adequate board AI governance currently looks like: at minimum, the board has a clear picture of which AI systems are being used, what decisions they are influencing or making, and whether the firm has assessed the bias and explainability characteristics of each material AI application. Boards that have approved AI investments without this baseline understanding are not providing adequate AI governance.

ESG — From Aspiration to Regulatory Obligation

Environmental, social and governance considerations have moved from voluntary best practice in 2015 to mandatory regulatory obligation in 2025. TCFD-aligned climate disclosure is mandatory for large UK companies. The FCA’s anti-greenwashing rule is in force. ISSB standards are moving toward mandatory UK adoption. Boards that are still treating ESG as a reputational management exercise rather than a regulatory compliance function are operating with an outdated governance framework.

The specific governance gaps that the current regulatory environment is exposing: many boards have approved net zero commitments without adequately governing the pathway to achieve them — a combination that the FCA’s anti-greenwashing rule specifically targets. Boards have overseen the production of annual sustainability reports without applying the same data integrity scrutiny to those reports that the audit committee applies to financial statements. And boards have been engaging with institutional investors on ESG governance without a clear understanding of the specific ESG regulatory obligations that apply to their company.

The governance improvement that most boards need is not strategic — most have ESG commitments in place. It is operational: ensuring that ESG data is collected, verified and reported with the same rigour as financial data; that ESG targets have credible delivery plans behind them; and that the board is receiving honest reporting on ESG progress rather than curated communications designed to support the company’s reputational narrative. See our ESG Board Chair page and our What Is ESG? guide for more.

Geopolitical Risk — A New Category of Board Governance

Russia’s invasion of Ukraine in 2022, the ongoing US-China trade and technology conflict, the Middle East instability affecting shipping and energy markets, and the structural shift in Western governments’ approach to economic security and critical supply chains have introduced a category of board-level strategic risk that corporate governance frameworks were not designed to accommodate.

Most UK boards do not have directors with direct geopolitical analysis expertise. They have directors with operational experience of specific markets and directors with financial or legal expertise — but not directors who can assess the governance implications of a geopolitical scenario with the same structured rigour they would apply to a financial risk. The result is geopolitical risk governance that is either too superficial (a general acknowledgement that geopolitical uncertainty is elevated) or too reactive (responding to events after they have materially affected the business rather than anticipating them in advance).

What adequate geopolitical risk governance looks like: the board has a specific, documented assessment of the company’s geopolitical exposures — by geography, by supply chain dependency, by customer concentration and by regulatory exposure in different jurisdictions. The board receives regular reporting on geopolitical developments that are material to those specific exposures — not a general geopolitical news update, but a governance-relevant assessment of what specific scenarios could affect the company and how management is managing those risks. And the board has stress-tested the company’s performance against specific geopolitical scenarios, not just at a conceptual level but with specific financial modelling of the business impact.

Cybersecurity — From IT Risk to Board-Level Governance Priority

The sophistication, frequency and financial impact of cyber attacks have made cybersecurity a primary board-level risk governance priority for most UK companies. The regulatory consequences of a significant cyber incident — ICO fines for data breaches, FCA enforcement for regulated firms, operational resilience regulatory action — alongside the operational disruption and reputational consequences, mean that cyber risk cannot be treated as a technical IT management function that receives a quarterly board update.

The governance gap that most boards have is not awareness — most boards are aware that cyber risk is significant. The gap is challenge capability: the ability to assess whether management’s cybersecurity posture is adequate for the specific threat environment the company faces, to probe the assumptions in the management’s cyber risk assessment and to identify when cyber risk reporting is providing reassurance rather than insight. A board that consistently receives green status reporting on cybersecurity and then suffers a significant cyber incident has not been provided with adequate management information — but neither has it been providing adequate governance challenge to require better information.

The specific governance improvement most boards need is not more technical expertise on the board itself — it is better-designed board reporting that gives non-technical directors the information they need to assess whether management’s cyber defences are adequate, and more systematic challenge of the assumptions behind that reporting. A NED with cybersecurity governance experience — who knows what questions to ask — provides more board value than a technical cybersecurity expert who cannot translate technical cyber risk into governance terms.

Boardroom Behaviours — The Governance Challenges You Can’t Find in a Code

Corporate governance codes address structures and processes. They do not — and cannot — address the interpersonal and cultural dynamics of the boardroom that determine whether structural governance is genuine or performative. The most consequential governance challenges in many boardrooms are not structural — they are behavioural.

Groupthink. Boards that have operated together for several years without significant membership change develop shared assumptions, shared blindspots and a shared reluctance to challenge each other that can produce collective governance failures that no individual director’s misconduct would explain. Groupthink is most dangerous in boards that have had recent success — where the board’s implicit view is that its governance has been validated by performance outcomes — and in boards where the chair’s personal authority is so significant that challenge is implicitly discouraged.

Dominant directors. Most boards have at least one director — frequently the chair, sometimes a major shareholder’s representative or a long-serving senior NED — whose views carry disproportionate weight in board discussions and whose positions are rarely challenged by other board members. A dominant director is not the same as an effective director. A board that consistently defers to a dominant voice is not providing the independent collective governance that the director duties of each individual board member require. The board effectiveness evaluation is the appropriate governance mechanism to identify and address dominant director dynamics — but only if the evaluation is conducted with genuine independence from the director in question.

The friendship problem. Board members who have worked together for many years, who socialise together and who have developed genuine personal friendships find it materially more difficult to challenge each other honestly than a group of professional colleagues who are less personally close. The friendship problem is particularly acute in the chair-CEO relationship (where a close personal friendship can compromise the chair’s governance independence) and in the SID’s relationship with the chair (where the chair evaluation process requires the SID to gather and report honest assessments of a person with whom they may have a long-standing personal relationship).

Information asymmetry. Boards depend on the information that management provides — and management controls what information the board receives. Where management has an interest in a board decision going a particular way, the information presented to the board to support that decision will be curated, consciously or unconsciously, to support management’s preferred outcome. The most effective NEDs recognise this dynamic and compensate for it — by seeking information from sources other than the management pack, by asking questions that probe the assumptions behind management’s presentation and by remaining alert to information that is conspicuously absent from the board’s deliberations.

Regulatory Complexity — The Governance Workload Has Increased

The volume and technical complexity of regulatory requirements that bear on company boards has increased substantially over the past decade. TCFD, UK SDR, Online Safety Act, Building Safety Act, Consumer Duty for financial services, the new NHS consumer standards, Awaab’s Law for social housing, the Employment (Allocation of Tips) Act, PSIRF for healthcare — the catalogue of new regulatory frameworks that create board-level governance obligations continues to grow. The cumulative governance workload of a FTSE 250 board in 2025 is materially larger than that of the equivalent board in 2015.

The governance implication is not just that boards need more specialised NED expertise — though that follows naturally from the increased technical governance demands. It is that the board’s overall governance architecture — committee structure, board meeting agenda design, NED time commitment, management reporting frameworks — needs to be regularly reviewed to ensure it is adequate for the current regulatory governance load, not for the load that existed when the governance structures were last reviewed.

The Evolving Expectations of NEDs

The aggregate effect of these modern governance challenges is that the expectations placed on non-executive directors have increased significantly and continue to increase. The NED who provided adequate governance in 2015 — attending quarterly board meetings, contributing to committee work, providing sector-specific challenge — may not be providing adequate governance in 2025 if they have not updated their understanding of AI governance, ESG regulatory obligations, cybersecurity risk and the other technical governance domains that modern boards are expected to oversee.

This evolution in governance expectations creates both a challenge and an opportunity. The challenge is that boards composed of directors appointed primarily for their executive track records — without updating their governance knowledge to reflect the modern governance agenda — are providing governance that is calibrated to an earlier era. The opportunity is that directors who actively develop their understanding of the modern governance challenges, who invest in their governance knowledge as deliberately as executives invest in their professional expertise, become substantially more valuable to the boards they serve.


Related guides: What Is Corporate Governance?  |  Directors’ Duties  |  Board Evaluations  |  What Is ESG?  |  AI Ethics Board Member  |  NED Knowledge Centre

NED Capital recruits non-executive directors for boards across the UK. Call 0203 137 2496 or see our NED Recruitment Agency page to discuss a board appointment.