More organisations are recognising the need to include IT expertise at board level – as such, the CIO’s role in the boardroom is crucial, writes Land Bank CTOO and 2023 Public Sector CIO of the Year Faith Burn.
For more than 15 years I have served as both a CIO and a non-executive director across industries including aviation, pharmaceuticals and energy. My experience includes SOEs and multinational corporations.
This dual vantage point has provided me with a unique perspective on what boards truly require from CIOs. I have both made my own mistakes as a CIO and have needed more from the CIO as a board member, therefore my views are from my own lived experiences.
The question is not only about what information CIOs should present, but also about how they should present it, how they should steward resources and how they should frame the role of technology in the long-term sustainability of the business.
Sitting on both sides of the table has given me clarity on where, in my view, CIOs often misstep and, more importantly, where they can deliver the greatest value.
Boards need clear, accessible reporting
Boards are evolving and more organisations are recognising the need to include IT expertise at board level. Despite this trend, many boards still do not have IT skills embedded within their composition. This creates a challenge: when CIOs present reports filled with technical jargon, boards often feel overwhelmed.
Too often CIOs believe they are communicating clearly, yet the link between technical initiatives and business impact is missing. Even when the CIO avoids technical language, the board is sometimes left to translate the implications themselves. Depending on individual directors’ comfort with technology, this can lead to misinterpretations, leaving the CIO and the board misaligned.
The responsibility lies with the CIO to present reports in plain business language and to articulate how IT initiatives connect directly to business outcomes. The question every board member silently asks is, “What does this mean for our business?” If that link is not made explicitly clear, the board cannot make informed decisions.
Accountability and transparency on investments
IT budgets are often significant. In some industries, IT budgets range between one percent and three percent of an organisation’s revenue. When translated into absolute terms, this can represent very large sums.
As board members, we therefore expect CIOs to demonstrate stewardship of IT resources. Stewardship in this context means ensuring that projects are prioritised in areas that drive the greatest business impact, that execution is managed tightly to avoid over-expenditure and that reporting on progress is both transparent and measurable.
It is not enough for IT teams to focus on the technology or solution they are implementing. They must also demonstrate that they understand what business problem they are solving. If, for example, the CIO is implementing an inventory improvement project, the discussion with the board should not focus solely on the software or system being installed. It should focus on the desired business outcomes such as tighter controls, reduced losses and ultimately a stronger balance sheet.
We want to see evidence that you, the CIO, understand the business context, not just the technology.
Clarifications on cybersecurity
Cybersecurity has become one of the gravest concerns for boards. Yet CIOs frequently fall into the trap of reporting their cyber posture in overly technical terms. Even directors with strong IT backgrounds sometimes need to re-read such reports to decipher what is being communicated.
I have found that analogies can be useful in simplifying complex concepts, but they must be applied carefully. Board members are highly educated and experienced and analogies that come across as condescending can undermine credibility. The key is to communicate in a respectful, accessible way that avoids technical jargon while still conveying the seriousness of the issue.
Context is also a key consideration for boards. They benefit when CIOs share industry-specific trends, case studies and lessons learnt from other organisations that have experienced cyberattacks. By situating the company’s posture within a wider industry perspective, CIOs provide boards with the information they need to calibrate their level of concern and make informed decisions about risk.
Proactivity on digital transformation
One of the most important responsibilities of the CIO is to articulate how the organisation will digitally transform. Boards are acutely aware that companies that fail to adapt will fall behind or disappear entirely.
A digital transformation plan should always be framed in terms of business outcomes. We are less concerned about the mechanics of a cloud migration or the technical details of a data platform. Rather, we want to understand how these initiatives will improve agility, enable new revenue streams, strengthen resilience or enhance customer experience.
In today’s environment, addressing artificial intelligence (AI) is paramount for CIOs. The rapid evolution of AI and generative AI has created both opportunities and risks that boards cannot afford to ignore.
CIOs should present their views on AI trends and industry use cases, explain what AI could mean for their organisation and educate the board on the foundational requirements such as cloud adoption, data governance and ethical considerations.
In my view, one of the most serious mistakes a CIO can make is to avoid the conversation on AI. Board members are exposed to AI regularly, in both their professional and private lives. They expect their CIO to have an informed view on how AI fits into the organisation’s strategy.
Transparency on IT risks
Another critical area of concern for boards is risk. CIOs must be transparent about both operational and strategic risks facing the IT function and they must explain how those risks are being managed.
As board members, we want to know how prepared the organisation is to recover from disruptions. Business continuity and disaster recovery are particularly important. CIOs must provide clear reporting on the organisation’s readiness to withstand and recover from unplanned disasters, whether they are cyberattacks, infrastructure failures or natural events.
When CIOs report candidly on risks and mitigations, they build trust. When they downplay risks or hide challenges, boards lose confidence.
Summarised, what non-executive board members need from CIOs is as follows:
- CIOs must watch their language and tone. Reports must be in clear English, free from jargon and never condescending.
- CIOs must demonstrate stewardship of IT resources by ensuring accountability and transparency in all IT investments.
- CIOs must engage the board on the latest trends in technology, including AI and articulate how digitalisation can continuously transform the business.
- CIOs must be transparent about risks and provide reassurance on preparedness for disruptions.
The relationship between CIOs and boards works best when CIOs remember that their role is not simply to manage technology but to interpret and translate it in ways that inform strategy, protect the organisation and enable sustainable growth.
















