PDF of the publication

Data governance: what the board really needs to look at

Through a roundtable discussion enriched by real-life situations and open exchanges of experiences, several key convictions emerged, along with some helpful tips for board members. This provided valuable insights into a topic that now directly impacts decisions, risks, and the value of the company.

On September 15, 2026, APIA Swiss held a meeting in Geneva:

around a question that now directly concerns boards of directors: How to approach data as a governance issue?

Organized and moderated by Edouard Lambelet, a member of the APIA Swiss committee, the meeting aimed to compare the experiences of the panel with those of the directors present.

And that's precisely what happened. Questions, examples, and experiences circulated in both directions. Some points were agreed upon, others were challenged. Underlying all of this was a central question for the administrator: how far should one go? Far enough to ask the right questions and exercise their oversight role without replacing management.

Knowing what to really ask

The topic of KPIs quickly illustrated this boundary.

The problem isn't having more and more dashboards. It's knowing which ones These are the few pieces of information that the council really needs to carry out its mandate.

And the work often begins even before the figure: what exactly does this indicator measure? Does everyone share the same definition? Can we really trust it?

The experiences mentioned have shown that this work is built up gradually with management, through successive adjustments. And when an indicator becomes truly useful, it quickly ceases to be a simple reporting tool for the board: management and teams also take ownership of it.

This is an important first reference point for the board: clarify what it needs to decide and challenge, without dictating how the company should produce information.

Data is everywhere — but you still have to master it.

Data permeates the entire company: customers, operations, production, margins, human resources, CRM, ERP, artificial intelligence… It contributes to management and, increasingly, to the very value of the company.

The discussion quickly brought the topic back to a very concrete question: Where is the critical information actually located? Who holds them? Which version is authoritative? And would the company still be able to access them if a person or partner were to disappear?

Because there is not “the” data, but “data”. They are born in different places, serve different purposes, and must be able to communicate with each other.

Dependency has been widely discussed. Some essential information sometimes exists only in the mind of an employee, in their own files, or in a way of working that only they have mastered. Other information depends heavily on a service provider or partner.

For the board, the question is therefore not to understand the mechanics in detail, but to know if the company truly retains control over what is essential to it.

Without trust in the data, there can be no good management

Trust This was one of the recurring themes of the evening. A board can only properly challenge a margin, a forecast or operational performance if it can rely on the information presented to it.

But one point in particular resonated: Data problems almost never reach the board labeled “data problem”.

They appear more often in the form of a different number depending on the person being spoken to, a difficult answer to obtain, information that does not overlap, or an indicator whose definition varies depending on who is using it.

Hence a useful reflex: when faced with a vague or contradictory answer, to ask whether the problem lies upstream, in the quality of the information itself.

Good information should be easy to find.

Another very concrete lesson emerged from the discussions. If important information requires a week of work every time the council requests it, there is probably a fundamental problem.

The challenge is not just to have the right information once. The goal is to be able to easily find it, update it, and link it to other information without starting from scratch.

This is an important difference between a company that "has data" and a company that actually knows how to use it.

For the board, the correct signal to look for is therefore quite simple: when essential information is requested again a few weeks or months later, Is it available quickly and consistently?

Who is responsible?

The question of data ownership has been widely debated. Assigning each piece of data to a specific business function seems natural. However, the same information can be useful simultaneously to finance, operations, sales, and production.

A pragmatic distinction emerged: The person who produces or enters the data must answer for its quality; the professions are then responsible for the use they make of it.

For the council, the challenge is not to allocate these roles itself. It is to ensure that they are clearly attributed and effectively assumed.

The debate naturally turned to the questions cybersecurity, resilience and dependence on third parties. THE European Cyber Resilience Act This has been specifically mentioned as a factor likely to change practices, directly for the players involved in the European market, but also through a chain effect for many Swiss companies.

And what about AI in all of this?

Artificial intelligence has obviously become a factor in the discussions.

But here again, the discussion quickly returned to a very simple reality: An intelligent tool powered by inconsistent, poorly defined, or unreliable data will not produce miracles.

The idea that companies are gradually becoming, in one way or another, data companies resonated widely in the room.

AI does not create this reality; it simply makes it much more visible and gives even more value to well-managed data.

For the board, this doesn't mean becoming an AI expert. It mainly means understanding that The company's ability to leverage these new tools depends largely on what it has built upstream.

How far should the administrator go?

The evening ended with a deliberately simple recommendation:

What are the ten KPIs I really need to properly fulfill my mandate?

Then a few questions: where do they come from? Who guarantees their quality? Can I trust them? Are they easy to trace? Is there an addiction behind them that the council should be aware of?

Perhaps that's where the right boundary lies.

The council's role is not to go into the details of the tools or the operational organization. It is about understanding the situation well enough to identify risks, ask the right questions and ensure that management controls them.

Data governance then becomes less of a new area of expertise to add to the administrator's job description than an additional radar to be integrated into the normal exercise of his mandate.

A big thank you to Aimé Achard, Stanislas Bressange, Nicolas Gauderon And Cédric Pompéï, as well as to all the directors present, for the frankness and generosity of the discussions. The very open sharing of successes as well as difficulties encountered allowed everyone to leave with some ideas and undoubtedly some new questions to ask at their next meetings…