A board of directors exists because ownership and day-to-day control of a company are separated. Shareholders cannot watch executives directly, so they entrust a governing body with ultimate accountability for the company's direction and survival, including its ability to withstand disruption. From an owner's perspective, the board is the mechanism that asks management hard questions before a crisis, not after it. That is why resilience belongs on the board's agenda as part of protecting enterprise value, not as a technical afterthought.
The board's mandate is anchored in company law, the articles of association and a board charter, and its resilience duties show up in committee terms of reference and standing agenda items. Most boards delegate the detail to a risk or audit committee while keeping the final decisions for the full board. A typical situation: after a serious data-centre outage, the board asks management to present impact tolerances for critical services and a funded recovery plan, then tracks progress quarterly. Gulf governance codes increasingly expect this oversight to be documented rather than assumed.
The classic failure comes in two forms: a board that dives into operational detail and becomes a second management team, or a board that hears about continuity only when something has already broken. Both leave shareholders without the protection the board exists to provide. ISO 37000 is a useful reminder that governance means directing and overseeing, not executing. In the ERGP programme this theme is developed in module M1, Resilience governance and the board.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme