Ask a board where responsibility for the boardroom's electronic integrity sits, and the honest answer at most companies is: nowhere. Facilities owns the furniture, IT owns the videoconferencing, security owns the door. Nobody owns the question of whether the room can be heard.

The control gap

Modern governance frameworks are exhaustive about information in written form. Inside information procedures, insider lists, disclosure committees, data-room protocols, all assume information lives in documents and systems. Yet every material matter a board decides exists first, and longest, as conversation. Results are debated aloud for weeks before an announcement. Transactions are negotiated aloud for months before a circular. The gap between how carefully companies control the document and how casually they treat the discussion of it is the single most consistent finding of our practice.

Regulators do not grade this gap explicitly, until something escapes. Then the question asked of directors becomes brutally simple: what steps did you take to protect inside information? "We assumed the room was fine" is not an answer that has aged well in any jurisdiction.

What a control looks like

Treating boardroom privacy as a governance control means giving it the properties every other assurance activity has. It needs an owner, typically the company secretary or general counsel, and a defined scope: the boardroom, committee rooms, the executive floor and the conferencing infrastructure those rooms depend on. Cadence should match exposure. Quarterly suits most issuers, with event-driven coverage ahead of results and transactions and a higher tempo during contested situations. Independence is non-negotiable, for the same reason external audit exists. Finally it needs documentation: dated reports in the committee record demonstrating the control operated.

Implemented this way, an electronic audit programme costs a rounding error against the exposures it addresses, and produces something rare in security spending: a document trail proving diligence, valuable precisely when something goes wrong elsewhere.

The questions directors should ask

Three questions surface the gap quickly. When was this room last independently inspected? Who controls access to it between meetings, and would we know if that control failed? And if this discussion appeared in the press on Monday, could we demonstrate we took reasonable steps to prevent it? A board that cannot answer all three has found its next agenda item.