What every Board should be preparing for, as information, technology and artificial intelligence risk move from the server room to the boardroom.
Download PDFDigital governance was once a technical matter, quietly delegated to IT departments and compliance officers. That era is closing. As institutions come to depend on cloud infrastructure, artificial intelligence, mobile banking, electronic records and biometric systems, the governance of digital risk has become inseparable from the governance of the enterprise itself.
Boards are now expected to demonstrate not merely that their organisations comply with the law, but that they possess the structures to identify, manage and continually monitor information, technology, AI and cybersecurity risk. In Kenya, this shift is being driven by a maturing Data Protection Act, sharpening expectations from the Office of the Data Protection Commissioner, rising cyber threats, and emerging global standards for responsible AI.
The institutions that endure will not necessarily be those that spend the most on technology — they will be those that earn confidence in how that technology is governed. This is the discipline of Digital Trust Governance.
For years, compliance programmes were built to answer a narrow set of questions: Have we registered with the regulator? Do we have a privacy policy? Have staff signed confidentiality agreements? Do we hold consent forms? Have we appointed a Data Protection Officer?
These remain necessary questions. But they no longer satisfy what Boards, regulators, investors, customers and insurers are now asking. The questions that matter today sit a level higher:
Compliance answers legal questions. Governance answers strategic ones.
The Data Protection Act, 2019 laid Kenya’s legal foundation for protecting personal data. Since then, regulation has steadily clarified what organisations owe in practice — accountability, lawful processing, security safeguards, data subject rights, breach notification, registration, cross-border transfers and processor obligations.
This is a living framework, shaped continually by guidance notes, enforcement activity and practical interpretation. Organisations that treat compliance as a single implementation project, rather than an ongoing governance discipline, will find themselves perpetually behind. The direction of travel is unmistakable:
Regulators increasingly expect demonstrable governance, not documentary compliance.
Digital risk is now enterprise risk. A Board cannot reasonably treat information governance as a matter for management alone — not when a single cyber incident can simultaneously trigger operational disruption, regulatory investigation, litigation, reputational damage, financial loss and a collapse in customer confidence.
Modern Boards already oversee financial reporting, operational resilience, legal compliance, environmental and social governance, enterprise risk and strategic transformation. Digital Trust now intersects with every one of these responsibilities — which is precisely why its governance belongs at Board level, not two tiers below it.
04Artificial intelligence brings genuine opportunity for innovation — and governance questions that few organisations have yet considered with the seriousness they deserve: automated decision-making, algorithmic bias, transparency, explainability, human oversight, the procurement of third-party AI systems, employee use of generative AI, and the protection of confidential information entered into AI platforms.
While Kenya continues to develop AI-specific legislation, the absence of a dedicated law is not the absence of responsibility. Existing obligations around fairness, accountability, security and privacy already reach into most AI deployments. Boards need governance frameworks before regulation compels them — not after.
05Ransomware, phishing and supply-chain compromise have made one thing clear: cybersecurity is now a governance challenge, not merely a technical one. Most successful attacks exploit weaknesses in oversight — not weaknesses in technology.
Cybersecurity should therefore be evaluated not only through technical assessment, but through governance maturity.
06Kenyan institutions increasingly operate inside international digital ecosystems — through cloud providers, international schools, financial partners, healthcare networks, technology vendors, NGOs and export-oriented businesses that routinely exchange information across borders.
Even where foreign legislation carries no direct force in Kenya, customer expectations and contractual requirements frequently import a higher governance standard regardless. Boards would therefore be well served to monitor developments beyond Kenya’s borders — international privacy standards, responsible AI principles, cross-border transfer safeguards, and global assurance practice.
07Executives frequently ask why an organisation should invest beyond the minimum the law requires. Increasingly, the answer is commercial rather than legal. Strong Digital Trust governance builds customer confidence, strengthens investor assurance, improves regulatory relationships, reduces legal exposure, and sharpens procurement outcomes.
Trust is becoming measurable — and organisations that can demonstrate mature governance will distinguish themselves from those that cannot.
Every Board should be able to put the following questions to management, and expect a considered answer:
What are our most significant digital risks?
How are these risks reported to the Board?
Have we independently assessed our Digital Trust maturity?
How do we govern artificial intelligence across the organisation?
Are our third-party technology providers appropriately managed?
How quickly could we detect and respond to a significant data incident?
Are our privacy, cybersecurity and technology governance programmes integrated, or operating in isolation?
How do we know our governance arrangements remain effective?
These questions move the conversation beyond compliance and towards strategic governance — where it belongs.
09Financial statements are independently audited because stakeholders require confidence in what they report. The same logic is beginning to apply to digital governance. An independent Digital Trust Assurance engagement examines how an organisation governs its information, personal data, technology, cybersecurity, artificial intelligence, third-party digital risk, governance structures and regulatory preparedness.
Its purpose is not simply to catalogue legal deficiencies, but to give Boards independent insight into governance maturity — and a clear path toward continual improvement.
Digital transformation has permanently reshaped the governance responsibilities of the modern Board. The question is no longer whether an organisation processes personal data or depends on digital systems — virtually all of them do. The more important question is whether those systems are governed with enough independence, accountability and strategic oversight to sustain the confidence of regulators, customers, employees and investors.
Compliance remains essential. It is simply no longer sufficient on its own. The institutions that inspire lasting confidence will be those that demonstrate mature Digital Trust Governance.
“When did your Board last receive an independent assessment of how effectively your organisation governs information, technology, cybersecurity, artificial intelligence and legal risk?”
If that question cannot be answered with confidence, it may be time to consider an independent Digital Trust Assurance review.
We help leadership teams understand, govern and continuously improve Digital Trust through structured, evidence-based advisory engagements.
A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.