5 minBusiness
Corporate Boards Face Structural Mismatch as Risk Turns Horizontal
A new analysis argues that the industrial-era board model, built for hierarchical companies and contained risks, is increasingly mismatched with today's interconnected, fast-moving threats that cross functions, borders, and organizational boundaries.
Corporate governance is facing a structural stress test that goes beyond the usual debates over board composition or meeting frequency. The modern board model, shaped during the industrial era when companies were hierarchical and risks were more contained, is now operating in an environment where the most consequential threats move horizontally — across functions, geographies, and organizational boundaries — rather than neatly up and down reporting lines.
This mismatch is not a matter of boards failing to do their jobs. It is a question of whether the underlying architecture of governance, designed for a vertical world, can absorb the weight of a horizontal risk landscape. Cyber incidents rarely stay technical; they quickly become legal, operational, and reputational events. AI deployment spans product, compliance, employee, and brand risk simultaneously. Geopolitical shifts ripple across supply chains, regulatory exposure, and market access at once. These risks spread rather than escalate through established channels.
Boards have responded rationally to expanding expectations by adding more meetings, longer agendas, broader expertise, and greater use of outside advisers. But these adaptations share an assumption that governance can keep pace with complexity by doing more within the existing model. They add layers, inputs, and capacity without fundamentally changing the structure itself. Meanwhile, risk is becoming more interconnected, more external, and faster-moving, creating a growing tension between the cadence of governance and the cadence of change.
A deeper shift sits underneath this tension. Governance traditionally assumes the company is the unit of analysis, but many of the most consequential risks now sit outside the firm in the systems it depends on: cloud infrastructure, AI ecosystems, global supply chains, and digital platforms. A manufacturer, retailer, healthcare provider, or financial institution may not consider technology its core business, yet if it stores data in the cloud or relies on interconnected supply chains, it is exposed to risks it does not control. Boards are no longer just overseeing what the company does; they are overseeing what the company depends on.
The cadence problem compounds the structural one. Boards operate on quarterly meetings, scheduled strategy reviews, and formal reporting cycles. But cyber vulnerabilities emerge overnight, AI systems change through iteration, and geopolitical dynamics shift in weeks rather than quarters. Oversight remains periodic while risk has become continuous. As risks become more distributed, boards need better visibility, but governance has a boundary: boards oversee, they do not manage. Too little visibility makes oversight symbolic; too much risks stepping into management.
Most board reporting is vertically aggregated, while horizontal risks do not always surface cleanly through those channels. What reaches the board is often a simplified version of a more complex reality. Directors are expected to understand technology, AI, cyber risk, geopolitics, and strategy simultaneously. Experience still matters, but its half-life is shrinking, and cognitive bandwidth may be becoming the real limiting factor in governance.
Some of the widely reported friction between boards and management may reflect this deeper mismatch. Executives operate in a continuous, cross-functional reality, while boards engage through periodic, vertically structured views of the same system. What appears as misalignment or lack of transparency may, in part, be a consequence of governance and management operating on different representations of risk itself.
None of this suggests boards are failing. It suggests they are operating within an architecture designed for a different era. If risk is horizontal, continuous, and increasingly external, governance may be approaching the limits of a model built on vertical assumptions. Boards were built to oversee organizations; today they are being asked to oversee systems. That shift points toward forms of governance less dependent on periodic escalation and more oriented toward continuous visibility, less bounded by the firm and more connected to the systems around it, and less reliant on adding layers to existing scaffolding.
This may not mean replacing the board, but it may mean that effective governance can no longer reside entirely within it. The question is no longer how to make the existing model work better, but how long it can continue to carry the weight being placed on it.
