Video summary

Governance beyond the boardroom: Insights for finance leaders

Main summary

Key takeaways

Business

Governance beyond the boardroom (PwC accounting podcast)

Core message

  • Corporate governance must be fit-for-purpose and treated as an interconnected system—board oversight ↔ executive management ↔ key functions—especially as reporting, risk, technology/data, and disclosure become more interdependent.
  • Finance leaders (controllers/CFO teams/CAOs) act as a “choke point” for information flow, enabling the board to make better decisions through timely, complete, accurate, and synthesized reporting.

Practical themes and operating “playbooks” mentioned

1) Use KOSO as a reference + common language (not a checklist)

  • The KOSO guidance (developed with COSO) is intended to:
    • Provide shared terminology for boards and management
    • Help teams assess whether governance is structured intentionally for their context
  • Key clarification:
    • It is not “checklist-driven” compliance (“mark items done”); it’s a discussion framework.

2) Bridge board governance and management governance (reduce silos)

  • A common challenge: governance, GRC, and reporting are often handled in separate lanes, producing incomplete pictures for decision-makers.
  • Recommendations:
    • Build an internal culture of cross-functional transparency
    • Escalate issues early and involve the right functions at the right time
    • Create synthesized views so the board isn’t seeing conflicting assessments (e.g., risk vs internal audit vs compliance)

3) Improve information flow and packaging to board/audit committees

  • Board effectiveness depends on what it receives.
  • Management responsibility:
    • Ensure information is balanced, complete enough, accurate, and timely
    • Package materials with:
      • Simple executive summaries
      • Clear “what do we want the board to do?” prompts
      • Management’s recommendations and alternatives considered
      • A unified view when possible (avoid “three different reports on the same risk”)

4) Governance for disclosure: escalate correctly and proactively

  • Move from ad hoc disclosure processes to a disciplined approach:
    • Use the guidance as a catalyst to review whether disclosure committees escalate the right matters to the board in a cohesive way
  • Note: proactive rethinking is harder than post-incident cleanup—so a structured catalyst helps.

5) Scenario planning for disclosure-worthy events

  • Go beyond cyber: perform scenario planning for other events that can trigger disclosure requirements.
  • Include board/executive expectations:
    • When should the board have been aware?
    • When to bring executive management into the decision?

6) Use an “authority matrix” lens for escalation thresholds

  • Reinforce what gets escalated and when, typically starting with board and executive expectations.
  • Emphasize documenting escalation in practice (thresholds, pathways, ownership).

7) Technology/data governance (including AI): oversight + controls + change management

  • Finance helps drive governance conversations about:
    • Access, validation, documentation
    • Change management for technology/platform changes
    • Responsible AI use and data quality
    • Risks of “human-in-the-loop” and how outputs may differ from operational realities
  • Board guidance principle:
    • Boards don’t need technical detail, but should understand:
      • Where AI is being used
      • How management governs it (risk + controls)

8) Align committee coverage for cross-cutting issues (e.g., AI)

  • Example pattern: firms previously expanded compensation committees to cover “human capital.”
  • Parallel idea: AI’s impact on workforce/human capital may require committee mandate adjustments so issues don’t sit solely in one silo (audit/risk/sustainability) without a cohesive story.

9) Connect risk management, internal control, and accountability (finance is central)

  • KOSO’s “risk management and internal control” principle is emphasized as foundational, not an afterthought.
  • Board-level discussion should include:
    • Don’t focus only on a top risks list or only internal audit findings
    • Ensure controls are keeping pace with changes (AI integration, systems/operating model transformation)
    • Confirm assurance coverage is aligned across functions and synthesized upward cohesively

Concrete actionable recommendations (implied)

  • Start governance modernization with 1–2 priority areas, especially where disruption would test governance.
  • Benchmark board materials against the KOSO principles’ intent:
    • Check whether reporting is synthesized, executive-friendly, and includes management recommendations/alternatives.
  • Run disclosure scenario exercises and document escalation triggers.
  • Review governance ownership for cross-functional topics (AI, supply chain → pricing/margins, technology/data) so the right committees and leaders are involved.
  • Ensure finance supports follow-through by:
    • Documenting resolutions after escalations
    • Linking issues to reporting and internal control implications

Metrics / KPIs

  • No explicit numeric KPIs, targets, or timelines were provided.
  • The emphasis is on governance effectiveness dimensions such as:
    • Information quality and timeliness
    • Escalation discipline
    • Assurance coverage
    • Synthesized board decision-making

Presenter / sources

  • Heather Horn (host, PwC accounting podcast)
  • Karen Robinson (Director, PwC Governance Insights Center)
  • Matt Duppy (Managing Director, PwC Governance Insights Center)
  • COSO / KOSO corporate governance framework (KOSO described as developed in collaboration with COSO)

Original video