Climate on Board
Every strategy will now have to work within climate constraints, which places climate well beyond the disclosure section of the annual report. This briefing aims to give you sufficient fluency in the frameworks to ask the right questions and to govern the subject.
Lesson 1: The board's climate duty
Your starting point is duty: in most jurisdictions across the region the legal hook is the ordinary duty of care and loyalty, and a foreseeable, financially material risk that a board fails to weigh is a governance failure, whatever the topic. Climate now meets that bar through transition risk (policy, carbon pricing, technology shifts), physical risk (heat, water stress, infrastructure damage) and liability risk.
The principles for effective climate governance from the World Economic Forum (WEF) and Chapter Zero, the global network of directors focused on climate, give you the cleanest board-level frame: accountability sits with the full board and cannot be pushed into a delegated corner; the board needs sufficient command of the subject to challenge management; and climate belongs inside strategy, capital allocation, incentives and disclosure.
Your practical first move as a new director is to ask where climate sits in the risk register, who owns it at executive level and when the board last spent thirty minutes on it, because the answers will show you the maturity of the whole governance system.
Bring to the boardroom: Where does climate risk sit in our risk register, and who owns it? When did this board last discuss it as a strategy item?
Lesson 2: Reading a transition plan
IFRS S2, the climate standard of the International Sustainability Standards Board (ISSB), organises climate reporting into governance, strategy, risk management and finally metrics and targets, building on the architecture of the earlier Task Force on Climate-related Financial Disclosures (TCFD). Your job as a director is to interrogate the reporting rather than to draft it, which is management's work, and the four-pillar structure is your interrogation map.
On strategy, ask whether the plan names the scenarios tested, including a credible below-two-degrees case and a disorderly-transition case, and whether capital expenditure actually follows the stated plan. Read a net-zero pledge that leaves capital expenditure unchanged as a statement of intent rather than as a strategy, because your investors will read it the same way.
On metrics, distinguish scope 1 and 2 (operations) from scope 3 (value chain). In Gulf economies scope 3 usually dwarfs the rest, and it is where customer, financier and regulator pressure lands first. Ask which targets are absolute, which are intensity-based and what happens to executive pay if they are missed.
Bring to the boardroom: Which climate scenarios has management tested the strategy against, and does our capital allocation match the transition plan we publish?
Lesson 3: Climate in Arab and North African boardrooms
The regional context you are stepping into is specific: COP28 in the UAE and the Saudi and Gulf net-zero pledges (UAE 2050, Saudi Arabia and Bahrain 2060) moved climate from the sustainability team to sovereign strategy. Regulators followed: several exchanges across the region now require or strongly encourage ESG disclosure for listed companies, and sovereign wealth funds increasingly screen for it.
Water stress, heat and food security are the physical risks that reach boards across the region first. When you ask about the cooling load of assets, the water intensity of operations or the climate resilience of key suppliers, you are doing core fiduciary work, and a colleague who characterises those questions as activism has misread what your role now requires.
In an interview, your fluency shows in specifics: a bank is exposed through financed emissions, a developer through building codes and cooling, a logistics firm through fuel transition and heat limits on outdoor labour. When you can name the exposure for the sector in front of you, you demonstrate climate literacy, while a candidate who recites pledges does not.
Bring to the boardroom: Which of our assets, suppliers or revenue lines is most exposed to heat, water stress or carbon pricing? What happens to us if that exposure arrives two years earlier than we assume?
Lesson 4: The state of disclosure in 2026
Reporting is consolidating around one baseline. S&P Global Sustainable1 counted 28 jurisdictions that had adopted the ISSB standards, IFRS S1 and S2, on a voluntary or mandatory basis as at 22 April 2026, with a further twelve planning to. Qatar is among those where the requirement took effect at the start of 2026. For you as a director in this region that matters directly: the ISSB architecture is the one worth learning, because your regulator, your auditor and your financier are all converging on it.
Europe moved the other way, and you should get the detail right because a lot of commentary is out of date. The Council gave final approval on 24 February 2026 to the Omnibus I simplification, and the resulting Directive (EU) 2026/470 has been in force since 18 March 2026, raising the threshold of the Corporate Sustainability Reporting Directive (CSRD) to companies above one thousand employees and 450 million euros of net turnover. EFRAG, the EU's financial reporting advisory body, has advised the Commission to cut mandatory datapoints by 61 percent and to align the standards more closely with the ISSB. The revised standards are due to be adopted by delegated act. The point most commentary misses is that double materiality survived: Europe still asks what the company does to the world as well as what the world does to the company.
The summary for your board is therefore that fewer companies are caught by the European regime, that the global baseline is ISSB and that the two regimes are converging. When you can say that cleanly, and you know which standard applies to the company in front of you, you are already ahead of the general conversation.
Bring to the boardroom: Which reporting regime actually binds us, and on what timetable? Are we building to the International Sustainability Standards Board (ISSB) baseline, or to something narrower we will have to redo?
Self-check: 5 board scenarios
- Management presents a net-zero 2050 pledge. The capital plan for the next five years is unchanged from last year. The strongest board response is:
- Which risk pairing best describes climate exposure for a Gulf-based bank?
- Under the ISSB / TCFD architecture, the four pillars a board should expect climate reporting to cover are:
- A fellow director says climate belongs to management rather than to the board. The most accurate response is:
- Scope 3 emissions matter to a board in the region primarily because:
Nature on Board
The World Economic Forum put 44 trillion dollars of economic value generation, more than half of global GDP, as moderately or highly dependent on nature in its New Nature Economy Report of 2020. This briefing extends your oversight from climate to the living systems on which your business depends, using the frameworks now available to govern them.
Lesson 1: Nature as a balance-sheet issue
Nature loss reaches your business through dependencies (water, pollination, soil, marine stocks, a stable coastline) and impacts (what operations do to ecosystems, which returns as regulatory, legal and reputational risk). The World Economic Forum's Nature Risk Rising report put 44 trillion dollars of economic value generation, over half the world's total GDP, as moderately or highly dependent on nature; that was 2020, and a 2023 update by PwC restated it as 55 percent of global GDP, or 58 trillion dollars. Either way it is the board-level headline, and your question as a director is which of your revenue lines sits in that half.
The WEF and Chapter Zero guiding principles for climate and nature governance deliberately extend the climate frame, treating climate and nature as a single strategic question. If your board has already run the climate learning curve, widen that same machinery to cover nature instead of building a second one.
In the Arab world the dependencies are stark and specific: desalination and groundwater, coastal real estate behind reefs and mangroves, fisheries and agricultural supply chains exposed to soil and water degradation. Each one sits on the balance sheet as an operating dependency, and each one belongs in your risk conversation on those terms.
Bring to the boardroom: Which of our revenue lines depends on water, coastal protection, pollination or other ecosystem services, and what is our exposure if that service degrades?
Lesson 2: TNFD and the LEAP walkthrough
The Taskforce on Nature-related Financial Disclosures (TNFD) mirrors the climate architecture: governance, strategy, risk and impact management, metrics and targets. Its working method, LEAP, is your practical tool: Locate where the business touches nature, Evaluate dependencies and impacts, Assess risks and opportunities, Prepare to respond and report.
Your board commissions LEAP and interrogates the output, while running it is management's work; make your first commissions narrow, covering a single site, commodity chain or water basin, so that an abstract topic turns into assets, basins and numbers with names attached.
The distinction for you to hold onto is double materiality: what nature loss does to your company (financial materiality) and what your company does to nature (impact materiality). Regulators and large customers increasingly ask for both, and the second is where your social licence is won or lost.
Bring to the boardroom: Have we run even a narrow LEAP assessment, meaning Locate, Evaluate, Assess and Prepare, on our most nature-dependent operation? What did it name as our top dependency and top impact?
Lesson 3: Giving nature a voice in governance
Nature on Board, this platform's sister initiative, argues that the living systems a business depends on should be represented in governance. Its methods run from nature-conscious board practice (standing agenda time, nature items in the risk register) to appointing a Nature Proxy, a person briefed to speak for the ecosystems the business touches.
One of its methods is the interspecies board meeting simulation, a live board exercise in which participants take the perspective of the species and systems a company depends on. It ran at the Dubai Future Forum in November 2025, with around forty people sitting as nature proxies. There is no published evaluation of what such exercises change, so you should treat the format as a way of keeping the long horizon in view during deliberation rather than as a technique with measured effects.
For your first seat, the practical lesson is smaller: bring one nature-dependency question to strategy discussions and one to risk, because that is how the topic enters the minutes, and the minutes are how governance changes.
Bring to the boardroom: If a director here were formally responsible for the ecosystems we depend on, what would they say about the decision in front of us?
Lesson 4: Nature reporting and the ISSB
Nature reporting is moving to the ISSB, which matters when your board is choosing which framework to learn. In November 2025 the ISSB decided to take on standard-setting for nature-related risks and opportunities, drawing on the TNFD framework. The TNFD announced in the same breath that it will complete the technical work already in progress by the third quarter of 2026 and then pause any further guidance development, handing the baton over. The ISSB is targeting an exposure draft ready for the biodiversity COP17, which convenes in Yerevan from 19 to 30 October 2026.
The form this will take is commonly misreported, so get it right. At its April 2026 meeting the ISSB agreed the vehicle will be an IFRS Practice Statement on nature-related disclosures, complementing IFRS S1 and S2 without changing what those standards require. There is no IFRS S3, and if you assert that there is you will lose credibility with any chief financial officer present. Note also, as the ISSB chair has put it, that providing material nature-related disclosures is not optional because IFRS S1 already requires it, so the obligation does not begin with the new guidance.
What this means for you in practice is that the TNFD's LEAP approach and its four pillars remain the working method, and the ISSB is expected to build on them rather than replace them. Learning LEAP now is your on-ramp to whatever the ISSB publishes, so the investment will keep its value.
Bring to the boardroom: Are we tracking the International Sustainability Standards Board (ISSB) nature exposure draft due around the biodiversity COP17 in October 2026, and would our current nature work carry over into it?
Self-check: 5 board scenarios
- A developer's flagship coastal project sits behind a degrading reef and mangrove belt. In TNFD terms, the reef is:
- The LEAP approach stands for:
- Double materiality means a board should weigh:
- The most effective first step for a board new to nature governance is:
- A Nature Proxy on a board is:
Human Rights and Business
This briefing covers how you oversee the human consequences of the business, from your own workforce to the far end of your supply chain, using the UN Guiding Principles as the operating standard.
Lesson 1: A director's summary of the UNGPs
The UN Guiding Principles on Business and Human Rights (2011) rest on three pillars: the state duty to protect, the corporate responsibility to respect and access to remedy. The middle pillar is yours: respecting rights means your company avoids infringing them and addresses harms it is involved in, everywhere it operates, whatever local enforcement looks like.
The operating tool is human rights due diligence: identify actual and potential harms, act on the findings, track effectiveness and communicate. For you this is a system to demand and interrogate, exactly like financial controls: who owns it, what did it find last year, what changed as a result.
The salient-risk concept keeps it governable for you by narrowing your attention to the most severe potential harms to people connected to the business. In relevant sectors across the region the recurring salient risks are migrant worker recruitment fees and conditions, heat exposure for outdoor labour and supply-chain labour standards.
Bring to the boardroom: What are our three most salient human rights risks, and who owns the due diligence system that found them? What changed because of it?
Lesson 2: The board's social oversight in practice
Treat worker voice as a governance instrument: grievance channels that people actually use, and whose patterns reach your board, are an early-warning system for operational, legal and reputational failure, and silent channels are a red flag worth naming.
Contractor and supplier chains are where most harm and most exposure sit. Your board-level question is whether the company's commercial terms (price, speed, penalties) are consistent with the labour standards it publishes. Where they are not, the published standards exist on paper only, and courts and journalists increasingly read them that way.
Remedy is the test of sincerity: when harm occurs, does your company acknowledge, correct and compensate, or does it litigate and delay? You and your fellow directors set that posture, and it defines the company's social licence far more than any policy document does.
Bring to the boardroom: Do our commercial terms with contractors make our published labour standards achievable, and what did our grievance data tell us last quarter?
Lesson 3: Diversity as a rights and performance question
Board diversity is where this platform started, and it belongs in this briefing because the composition of your board determines both fairness and what the board is able to see. A board drawn from one life experience has a fixed field of vision and keeps missing the same risks, including the human ones.
The regional case for action is well documented: on the Heriot-Watt and Aurora50 GCC Board Gender Index, women held 7 percent of board seats across the Gulf Cooperation Council (GCC) states in January 2026, roughly one seat in fourteen, and most listed Arab and North African companies still have all-male boards. Quotas, disclosure rules and investor pressure are moving at different speeds across the region, so you should know the rule in your own market.
Inclusion extends beyond gender: age, nationality, disability and socio-economic background all widen what a board can see. Your practical instrument is the nomination process: where seats are advertised, how shortlists are built and whether your board's skills matrix names lived experience alongside professional skills.
Bring to the boardroom: How is our shortlist built when a seat opens, and which stakeholder groups have no one at this table?
Lesson 4: Human rights as enterprise risk
The Conference Board, working with the law firm Weil, concluded in a July 2025 report that human rights due diligence in the supply chain is no longer a peripheral corporate responsibility issue but a core legal, compliance and commercial requirement, and that the shift demands stronger board oversight. Their first recommendation is the one for you to remember: integrate supplier due diligence into enterprise risk management with board-level oversight, with accountability shared across the legal, procurement and compliance functions and with a written route for escalating supplier violations and failed audits.
The commercial consequences are already measurable. The same report records that under the United States forced-labour import law, customs had detained 16,781 shipments valued at 3.7 billion dollars as at 1 June 2025, with fewer than forty percent of them released, which is inventory stopped at a border rather than an abstraction. Customs publishes a running dashboard, revised in 2026, so check the current figure before you quote one. If your company exports into the United States or Europe, or supplies those who do, this is a supply-chain continuity risk that belongs on your risk register.
Two questions do most of the work in your first year, and both are easy for you to ask without expertise. Where does human rights sit in our enterprise risk management framework, and who owns escalation when a supplier issue is found? If the answer to either is vague, or if it names only the sustainability report, the oversight is not yet real.
Bring to the boardroom: Where does human rights sit in our enterprise risk framework, and who owns the escalation the day a supplier violation is found?
Self-check: 5 board scenarios
- Under the UNGPs, the corporate responsibility to respect human rights applies:
- A contractor's workers paid recruitment fees to secure their jobs. The board's soundest framing is:
- A grievance channel has recorded almost no complaints for two years. A well-governed board reads this as:
- The strongest governance instrument for improving board diversity is:
- Access to remedy, the UNGPs' third pillar, means at board level:
Cyber Risk on Board
Cyber is the clearest case of a governance duty that outlives the rule written for it. This briefing covers what you owe on cyber as a board member even while the disclosure requirements around it are being renegotiated.
Lesson 1: The duty that survives the rule
The United States is currently demonstrating that a board's cyber duty outlasts the rule written around it. On 13 January 2026 the chairman of the United States Securities and Exchange Commission (SEC) instructed the Division of Corporation Finance to carry out a comprehensive review of Regulation S-K, the rule set that contains the cybersecurity risk management, strategy and governance item. Be precise here, because the episode is easy to overstate: that statement did not mention cybersecurity at all, and the only disclosure item it advanced was Item 402 on executive compensation. The pressure on the cyber item came from industry. On 10 April 2026 five banking and securities trade associations formally asked the Commission to rescind Item 106 of Regulation S-K, the cybersecurity risk management, strategy and governance item, in its entirety, along with the dedicated incident-reporting item on Form 8-K, and to fall back on the general principles-based reporting route. The comment file closed on 13 April 2026 and the outcome is undetermined; as of July 2026 the rules remained in force.
What those same associations proposed to keep is the revealing part. Their fallback position preserves exactly two things: how cyber risk is integrated into enterprise risk management and strategy, and how the board of directors oversees it. In other words, the industry pressing hardest to strip the rule back still treats board-level cyber oversight as the part that must remain, which tells you where the durable obligation sits.
For you as a first-time director the lesson generalises well beyond cyber: the duty is the thing to learn. Disclosure regimes are being written, softened and rewritten across every jurisdiction at present, so the current text of any one of them is a short-lived thing for you to have memorised, while an understanding of what a board is actually for keeps its value. A caution on scope: this is United States securities regulation, so it binds a company in the region only through a US listing. In the Gulf, cyber oversight increasingly travels with new national data-protection regimes, so if you sit there you should ask how the two are governed together rather than in separate silos. Treat the US debate as a signal of where expectations settle rather than as law that reaches the region automatically.
Bring to the boardroom: If no rule required us to disclose our cyber oversight, would what this board actually does still stand up to scrutiny?
Lesson 2: Whole-board cyber competence
The most common mistake boards make on cyber is to hire one expert and relax. The National Association of Corporate Directors (NACD) asks such a board a direct question: is this strategy really deferring to one individual a responsibility that the full board should undertake? Its own answer is that the board should not treat the addition of a cyber expert as a reason to stop maintaining a foundational level of cyber-risk understanding and competence among all its members. It is a useful position for you to be able to state in an interview, because it shows an understanding that oversight is a whole-board duty that no single hire can discharge.
The expectation on your board is already high. The NACD's 2026 director handbook on cyber-risk oversight reports that 86 percent of Fortune 100 companies disclose cybersecurity as an expertise sought on the board or cite it in at least one director biography. That measures what boards put in a proxy statement rather than what they can actually do, but the direction is unambiguous: cyber literacy is now part of the baseline your board's skills matrix is expected to cover.
The appetite to close the gap still lags that expectation. In the NACD's 2025 board practices and oversight surveys, only 34 percent of public company directors rated improving the board's cybersecurity expertise as very or extremely important, and 40 percent said the same about assigning committee oversight responsibilities for cyber risk; private company directors were more concerned on both counts, at 45 and 49 percent. The public company samples run to about 160 responses, so read them as indicative rather than precise. Either way your opening as a prepared newcomer is real: arriving with genuine cyber literacy and a view on how the board should structure its oversight places you ahead of most of the field.
Bring to the boardroom: Does this board treat cyber as one director's specialism, and what would it take for every member here to challenge a cyber report competently?
Lesson 3: Oversight that would survive an incident
Your cyber oversight is judged in hindsight, on the day something happens. The two elements the industry itself wants preserved are the right skeleton for you to build on: is cyber genuinely integrated into enterprise risk management and strategy, rather than living as a technology report, and is your board's own oversight structure clear enough to describe in a sentence.
Practical governance follows from those two. Establish which committee holds cyber and whether that is written down anywhere, and ask whether your board has ever seen the incident response plan and whether the plan has been exercised rather than merely written. Then pin down the escalation trigger: at what threshold management has to tell the board and whether that threshold has ever been tested against a real event. It is equally worth asking when your board last received an independent view of the company's security posture rather than a self-assessment from the people responsible for it.
Resist two comfortable answers. A compliance certificate describes a single moment in time, and an absence of incidents may only be evidence that nobody has looked hard enough, or that detection is weak, so it is thin proof of resilience.
Bring to the boardroom: What is our escalation trigger for telling this board about an incident? When did we last run a live exercise of the response plan, and who last assessed us independently?
Self-check: 5 board scenarios
- The financial industry has asked the SEC to rescind the prescriptive cybersecurity disclosure item. What should a director conclude about the board's cyber duty?
- A board responds to rising cyber risk by recruiting one director with a security background and considers the matter handled. The best assessment is:
- Management assures the board there have been no cyber incidents this year. The strongest board response is:
- A critical supplier that processes the company's customer data is breached. Management says the company's own systems were untouched, so there is nothing to report to the board. The strongest board response is:
- A candidate based in the region is asked in an interview about the US cybersecurity disclosure rules. The most credible answer:
Responsible AI
AI now acts inside the business at machine speed, pricing products, screening candidates, advising customers and making decisions. This briefing covers what you must keep sovereign as a board, what you can delegate and the guardrails that make delegation safe.
Lesson 1: What boards govern when machines decide
The governance problem is delegation at speed and scale, because an AI system can make thousands of consequential calls (credit, hiring, pricing, medical triage) between your board meetings. Rather than reviewing those calls, your job is to govern the conditions under which they are made: purpose, boundaries, accountability and escalation.
The OECD AI Principles and the emerging regulatory wave (the EU AI Act's risk tiers and national AI strategies from the UAE, Saudi Arabia, Qatar and Egypt) converge on the same board-relevant core: risk-proportionate control, human accountability that cannot be delegated to a vendor or a model, transparency appropriate to the use and demonstrable safety before deployment.
Sort the AI in your business into three groups: what the company builds, what it buys and what its people use informally, often called shadow AI. Each needs an owner, an inventory and a route to the risk register. Most organisations discover the third bucket is the largest and the least governed.
Bring to the boardroom: Do we hold an inventory of the AI systems we build, buy and quietly use, and who is the single accountable owner for each consequential one?
Lesson 2: The 2026 regulatory map
You need to know what already binds and what is still coming, because commentary frequently gets this wrong. Under the EU AI Act, two things have applied since 2 February 2025: the bans on prohibited practices and a duty on providers and deployers to support AI literacy among their staff. Obligations for general-purpose AI models followed on 2 August 2025. The rules for high-risk systems were then pushed back by the Digital Omnibus on AI, which the European Parliament approved on 16 June 2026 and the Council on 29 June 2026, and which was signed on 8 July 2026 and awaits publication in the Official Journal. It moves the Annex III categories, including employment, education, biometrics and critical infrastructure, to 2 December 2027, and AI built into regulated products to 2 August 2028. What it does not move is 2 August 2026: the transparency obligations still arrive on that date.
Two distinctions keep you out of trouble. The first is provider versus deployer: the general-purpose AI obligations bind the companies that build foundation models rather than every company that uses a copilot built on one. The supplier carries those duties, and your job as a deployer is to ask whether they have been discharged. The second is scope: the Act reaches a company in the region only where it places AI on the EU market or its system's output is used in the EU, so treat it as the benchmark that travels rather than as law that automatically applies.
The literacy duty is your useful hook for this whole briefing. It is a best-effort duty rather than a certifiable standard, and the same omnibus softens it further, from ensuring a sufficient level of AI literacy to supporting its development among staff. Still, a regulator has now written down that the people deploying these systems should understand them well enough to use them responsibly, and boards are not exempt from the logic. Where your company falls in scope, ask what it is doing to build that literacy, and where it does not, the question still works as good governance.
Bring to the boardroom: Have we mapped our AI systems against the EU AI Act's risk tiers, and are we in scope at all? What did our model providers tell us about their own obligations?
Lesson 3: The questions that expose AI risk
On any consequential system, five questions expose most of the risk for you. What decision does it make or shape, and about whom? What data trained it, and does that data import bias or rights problems (privacy, consent, provenance)? What is the failure mode, and who catches it, how fast? Can we explain an individual outcome to the person affected, a regulator, a court? And what is the exit: can we switch it off, roll back or substitute a human process without stopping the business?
Model risk compounds silently: performance drifts as the world changes, vendors update behaviour without notice and automation bias makes humans rubber-stamp machine output. Expect monitoring with thresholds and a named human override rather than a one-time validation at launch.
Give third-party AI procurement-grade scrutiny: contractual audit rights, incident notification duties, data-use limits and clarity on who is liable when the model is wrong. If the vendor cannot answer the five questions, your company inherits the risk unpriced.
If you want a source to stand behind in an interview, Deloitte's Center for Board Effectiveness publishes an AI governance roadmap for directors. Among the questions it puts under strategy is the inventory one: does management have a current inventory of how machine learning and generative AI are being used in the company. It groups the headline risks as inaccuracy and hallucinations, as intellectual property infringement and breach of confidentiality and as unethical use or bias, and it states explicitly that the list is not exhaustive. Its first question, though, is aimed at the board itself: does the board have the experience and expertise to advise on the strategy and then monitor the progress of its implementation. Quoting that one in a nominations conversation serves you well, because it is the question the board should already be asking about you.
Bring to the boardroom: For our most consequential AI system, which named human can switch it off? Can we also explain an individual outcome and detect drift?
Lesson 4: Where agentic AI adoption outran governance
The frontier has moved from systems that recommend to systems that act. An agent books, orders, replies, escalates and chains its own steps, which means the old control point (a human reviewing an output before it takes effect) quietly disappears. Deloitte's 2026 State of AI in the Enterprise survey, covering 3,235 technology and business leaders in twenty-four countries across four regions, this region among them, found that only 21 percent say their organisation has a mature governance model for agentic AI, while 74 percent expect their companies to be using agents at least moderately by 2027. Read those two numbers together and your job is obvious: adoption is climbing much faster than the guardrails around it.
Before agents run in production, require a defined scope of authority for each agent written as what it may do without a human, hard limits on the money and data it can touch, logging good enough to reconstruct why it acted, a named human accountable for its behaviour and a tested way to stop it. Ask also what happens when two agents interact, because emergent behaviour between systems is where the surprises arise.
This is also where you are genuinely competitive as a first-time director. The EY Center for Board Matters reviewed the eighty Fortune 100 companies that had filed proxy statements and annual reports by 31 July 2025 and found that 11 percent disclosed board-level education or training on AI, up from 8 percent the year before. That measures disclosure rather than practice, but the direction is clear: most sitting boards are learning this at the same time as you, and your preparation closes a gap that experience alone would not.
Bring to the boardroom: Which of our AI systems can already act without a human in the loop, and who can switch each one off? What is each one's defined limit?
Lesson 5: Governing with AI as well as over it
The same technology you are governing can strengthen governance. Board-grade uses are emerging: scanning the risk landscape, stress-testing assumptions in scenario work, summarising long diligence packs and surfacing dissenting signals from operational data that management summaries smooth over.
The discipline is to let AI draft while your board decides, so the technology remains an input rather than an authority. Confidentiality is the hard constraint; board papers cannot be pasted into consumer tools, so any board use needs an approved, contained deployment with clear data terms.
Keep human judgement sovereign over entering or exiting a business, over decisions that materially affect people's lives and rights and over anything you must personally answer for to shareholders, regulators or courts, because those choices carry moral and strategic weight. You can delegate a task for efficiency, but your board still answers for the outcome, which is why judgement on these decisions stays human.
Bring to the boardroom: Where could AI genuinely sharpen this board's work, and which decisions do we agree in advance will never be delegated to it?
Self-check: 6 board scenarios
- Management proposes an AI screening tool for hiring, trained on ten years of the company's own hiring data. The board's sharpest concern is:
- Accountability for a consequential AI-made decision sits with:
- The best board-level control for AI systems across the business is:
- Automation bias in a governance context means:
- The chair asks a candidate how they would oversee the agentic AI the company is piloting in customer operations. The answer that shows board-grade thinking is:
- Which decision should a board explicitly refuse to delegate to AI?
Duties and Liability
This briefing sets out what you are personally answerable for as a director, in the terms the law actually uses. It is the part a nominating committee tests, and the part that attaches to you personally rather than to the board as a body.
Lesson 1: The duties in the words the statute uses
Across the region the duty is stated in strikingly similar language, because most modern Gulf company law draws on the same civil-law lineage. Saudi Arabia is the clearest to read. Article 26 of the Companies Law, issued by Royal Decree M/132 and in force since 19 January 2023, is headed Duty of Care and Loyalty and lists seven obligations that you take on personally: exercise your duties within the limits of the powers vested in you, exert extensive efforts to serve the interest of the company and promote its success, make or vote on decisions independently, exercise the diligence and care reasonably expected of a board member, avoid situations involving conflict of interest, disclose any direct or indirect interest you have in the company's business and contracts and accept no benefit granted to you by third parties in relation to your position. That is seven obligations in one article, and every one of them is testable.
Read this as a director rather than as a lawyer and the list has a clear shape. Two of the seven obligations concern your competence, namely care and diligence and staying inside the powers vested in the role, and three concern your allegiance: acting in the company's interest, avoiding conflicts and taking nothing from third parties for the position. That leaves disclosure and independent decision-making, which is the one most people miss. It means that if a shareholder nominated you to the board, you still owe the duty to the company rather than to the person who put you there. In a region where most boards carry shareholder nominees, that single word does a great deal of work.
The UAE has moved in the same direction and more recently. Federal Decree-Law No. 32 of 2021 was amended by Federal Decree-Law No. 20 of 2025, which expanded directors' duties to include acting with due care and in the company's best interests, and added an express obligation to disclose related-party transactions above statutory thresholds, alongside conflicts-of-interest registers and formal minute-keeping. Across the region the movement is one way: from duties stated as principle toward duties that must be documented as procedure.
Two things follow if you sit outside the Gulf. The Maghrib runs on a different legal lineage: Moroccan companies are governed by Law 17-95 on sociétés anonymes, in the French tradition, where the board is a conseil d'administration and the division between chairman and chief executive is drawn differently from the Gulf model. In the Levant the duties are layered rather than consolidated: in Jordan the governance rules for companies listed on the Amman exchange come from the Securities Commission and the Central Bank instructions as much as from the companies law, and they are built on the OECD principles.
The instruction to you is the same everywhere: find the instrument that governs your own company in your own jurisdiction and read the duties article itself, which is usually one article and usually short. No regional summary, this one included, substitutes for the sentence you are actually bound by.
Bring to the boardroom: Which of my duties would I struggle to evidence if a regulator asked me to, six months after the decision?
Lesson 2: Where liability actually bites
The fear you probably carry into a first appointment is of being sued for a commercial decision that went badly, and that is rarely what happens. Business judgement, honestly exercised on a reasonable basis, is not where liability tends to arise.
Liability concentrates in a narrower and unglamorous set of places: failing to file, to disclose or to keep records; trading while the company cannot meet its obligations; approving accounts there was no reasonable basis to believe; failing to act on something you were told, or should have asked about; and distributing to shareholders what was not lawfully distributable. Most of these are failures of process and attention rather than strategy, and several attach to you personally and individually rather than to the board as a body.
The consequences are not only financial. Morocco's Law 20-19, promulgated in April 2019 and amending Law 17-95 on sociétés anonymes, extended the liability of directors and chief executives to misconduct committed under their management and to acts outside the company's interest, and gave the court power to order the return of profits made from those acts and to bar the individual from managing, administering or representing any company for twelve months. A disqualification of that kind ends a board career more decisively than a damages award, and you should know that the power exists.
The practical consequence is that your protection is built in ordinary time rather than in a crisis, by asking the question and by having the answer minuted. If you consistently ask, and your questions appear in the record, you are in a materially different position from a director who was present and silent, even where both of you voted the same way.
Bring to the boardroom: If this decision were examined in two years, what in the record would show that I applied my own mind to it?
Lesson 3: Indemnities, insurance and the gaps in both
Two different things get confused here: an indemnity is a promise by the company to cover you, while directors' and officers' insurance is a policy bought from an insurer. You want both, and both have limits that most directors do not expect.
An indemnity is only as good as the company giving it, which means it is worth least at precisely the moment you are most likely to need it, when the company is insolvent or the company itself is the claimant. Company law also limits what can be indemnified: a company generally cannot indemnify a director against their own fraud or dishonesty, and it should not be able to, since that would defeat the duty.
D&O insurance has its own architecture. Side A responds when the company cannot indemnify the director, and it is the layer that actually protects you personally as a non-executive. Ask three questions before you accept any board appointment: is there Side A cover and at what limit; is the limit shared across every director and the company itself so that early claimants exhaust it; and does cover survive if the company is sold or fails, which is when claims tend to arrive. Ask them before acceptance rather than after, because the answers are much harder to obtain once you are inside and the relationship is established.
Bring to the boardroom: Have I seen the directors and officers (D&O) liability policy, its limit, and whether that limit is shared, or have I only been told that cover exists?
Lesson 4: Reserved matters, delegation and the minute
A board cannot decide everything, so it delegates; what it cannot do is delegate away its own accountability, and the line between the two is drawn in a document most new directors never ask to see: the schedule of matters reserved to the board. You should ask for it early.
That schedule is the single most useful piece of paper you can read as a new director. It sets out what only the board may approve, what management may do within limits and where those limits sit in money and in kind. If the company does not have one, that is itself a finding, and a good first contribution from you. If it has one that has not been reviewed in five years, the thresholds have almost certainly been overtaken by inflation and by the size of the business.
The minute matters just as much. Minutes are not a transcript and should not try to be, but they are the record that determines what a court or a regulator believes happened. Three things belong in them: the decision, the fact that alternatives and risks were considered and any dissent. If you disagreed and the minute does not record your disagreement, you are treated afterwards as having agreed. Asking for your concern to be recorded is the mechanism the law provides rather than an act of hostility, and experienced chairs expect it.
Bring to the boardroom: Have I read the schedule of reserved matters, and does it still reflect the size and risk of this business?
Self-check: 4 board scenarios
- A director is nominated to a board by the shareholder who employs them. On a vote where that shareholder's interest and the company's diverge, the duty is to:
- Which situation is most likely to create personal liability for a non-executive director?
- A candidate is offered a non-executive seat. On protection, the question that matters most is:
- A director raises a serious concern about a proposal, and the board approves it anyway. The step that protects the director's position is to:
Committees and the Numbers
This briefing gives you what each committee actually owns, along with enough financial fluency to interrogate a board pack. The audit seat is the one you are most likely to be offered first, and the one with the sharpest exposure.
Lesson 1: What each committee actually owns
Four committees do most of the work, and their boundaries matter to you because a question asked in the wrong one gets a polite answer and no follow-up.
Audit owns the integrity of the financial statements, the internal control and risk systems, the internal audit function and the relationship with the external auditor. Remuneration owns executive pay design, and the harder question of what the pay structure is actually incentivising. Nomination owns board composition, succession and evaluation, which makes it the committee that decides what the board will be capable of in three years. Risk, where it is separate from audit, owns the forward view: appetite, tolerance and emerging exposures, as against audit's largely backward-looking assurance.
The common failure is the gap between them: climate and cyber both land between risk and audit, and culture falls between remuneration and nomination, so each can end up owned by no committee at all. When something important has no committee home, it reaches the board only when it has already become an incident. A useful early question from you as a new director is simply: which committee owns this, and if the answer is unclear, say so.
Bring to the boardroom: Which committee owns the risk that worries me most, and does that committee know it owns it?
Lesson 2: Inside the audit committee
The audit committee is where you are most likely to be placed as a numerate first-time director, and it carries the sharpest personal exposure, because approving accounts there was no reasonable basis to believe is one of the clearest routes to liability.
Your real work there is testing judgement rather than recalculating anything. Every set of accounts contains a small number of places where management had latitude: revenue recognition timing, provisions and their release, impairment of goodwill and other assets, the valuation of anything not traded in a liquid market and going-concern. Those are the places where a reported number rests on an opinion rather than on an observation, and your job is to know which judgements moved, in which direction and why.
A practical discipline is to ask management, every cycle, for the list of significant judgements and the direction each one moved compared with last period, and then to ask the auditor, separately, for their own list. Where the two lists differ, you have found the conversation worth having. Where the lists always match perfectly and never change, treat that as a sign that nobody is genuinely testing anything rather than as reassurance.
Bring to the boardroom: Which accounting judgements moved this period, and did any of them move in the direction that flatters the result?
Lesson 3: Going concern, impairment and the pack
Going concern and impairment carry more weight than anything else in the board pack in front of you, and both are frequently nodded through.
Going concern is the assertion that the company can meet its obligations as they fall due for at least the next twelve months. It rests on a cash forecast and on facilities that may have conditions attached. Your questions are specific: what does the forecast assume about collections and about renewals, what happens to headroom if the main assumption is wrong by twenty-five percent and are any covenants close enough that an ordinary bad quarter would breach them. A covenant breach converts long-term debt into an immediate liability, which is how solvent-looking companies fail quickly.
Impairment is the admission that an asset is worth less than the balance sheet says. Because it is a judgement, it can be deferred, and deferring it is one of the most common ways a difficult year is smoothed. You should ask what discount rate and growth assumptions the impairment test used, and whether those assumptions are the same ones used in the strategic plan presented to the board. When the impairment model is more optimistic than the strategy, one of the two documents is wrong, and it is worth establishing which before an auditor does.
Bring to the boardroom: If our central assumption is wrong by twenty-five percent, do we still meet our covenants, and when did we last test that?
Lesson 4: The auditor and the private session
The external auditor is appointed by the shareholders and reports to them, however much the seating in most meetings suggests they are management's supplier. The audit committee is the mechanism that keeps that relationship honest, and the single most useful instrument you have on it is the private session.
A private session means the committee meets the auditor with no executive present. It should happen every cycle as routine rather than by exception, because a session convened specially signals that something is wrong and therefore never gets convened, and making it routine is what makes it usable.
Three questions are worth asking every time, and they are more revealing than any technical enquiry. Where did you and management disagree, and how was it resolved? What was the most difficult judgement in this audit? And if you could change one thing about how this company reports, what would it be? Then, in the committee's own private time and without the auditor present, ask the question that runs the other way: is the audit fee low enough, or the non-audit work large enough, that the auditor's independence is under pressure? An auditor earning considerably more from advisory work than from the audit is in a structurally difficult position, whatever anyone's intentions.
Bring to the boardroom: When did this committee last meet the auditor with no executive present, and was it routine or an exception?
Self-check: 3 board scenarios
- Goodwill from an acquisition three years ago has not been impaired, though that business has missed plan every year since. The most useful audit committee question is:
- A private session between the audit committee and the external auditor is most effective when it is:
- Which pairing of items in a board pack most deserves to be read together?
Board Composition
This briefing examines how a board is composed and what that composition lets the board see. It is the subject this organisation exists for, and it is a governance control you can use.
Lesson 1: Composition as a governance control
A board's composition works in the same way as an internal control: it is a mechanism that determines what gets caught before it becomes a loss, though you will usually hear it discussed only as a description of the people on the board.
A board can only challenge what someone present recognises as worth challenging. Where every director has come through the same industry and the same firms over the same period, the board will be strong on the risks that career teaches and will miss the others, and the blindness comes from nobody present having the reference to notice rather than from any failure of intelligence. That is why composition is the first control a board has: it is set before any decision is taken, and it determines the range of what can be questioned afterwards.
The claim here is about information and challenge, and you can examine it in your own boardroom. The claim about profitability, as the next lesson sets out, is on much weaker ground than it is usually asserted to be.
Bring to the boardroom: On the last decision this board approved quickly, who around the table had the background to test it?
Lesson 2: The business case, examined
You will routinely be told that diverse boards outperform, usually with a figure attached from a consultancy study. Before you repeat that in a nomination committee, you should know that the evidence is much weaker than most people quoting it realise, and a colleague present may well know it.
The most cited studies claiming a link between leadership diversity and financial performance have not held up. Jeremiah Green and John Hand published a quasi-replication in Econ Journal Watch in March 2024, testing the same relationships on S&P 500 firms, and found no statistically significant relation between executive racial and ethnic diversity and industry-adjusted operating margin, sales growth, gross margin, return on assets, return on equity or total shareholder return. Their sharper criticism is methodological: the original work measured financial performance over the years running up to the point at which executive demographics were recorded, so the causal arrow may well run the other way, with successful firms going on to appoint more diverse leadership rather than diversity producing the success. They also could not obtain the underlying datasets or even the names of the firms in them, which is why theirs is a quasi-replication rather than a replication. The scope deserves noting before you use the finding: their tests cover US listed firms and the ethnic and racial diversity of executives rather than board gender diversity in this region. Alex Edmans, a finance professor who is explicit that he supports diversity on moral grounds, has made the wider argument at length in his 2024 book on how studies mislead: the financial case is routinely made with evidence that would not be accepted for any other business proposition.
The criticism leaves the case for diverse boards on ground that actually holds. Composition changes what a board can see and how quickly it recognises a risk outside the collective experience of the room. That claim rests on how error correction works in groups, and because it can be checked in a specific boardroom it holds up when a sceptical colleague asks you for the study. A weak argument for a sound conclusion is a liability, and in a nomination committee it will be found.
Bring to the boardroom: If a colleague asked me for the evidence behind the business case, could I give them something that survives being checked?
Lesson 3: The skills matrix and the gap it is supposed to find
The instrument a nomination committee uses is the skills matrix: the competences the board needs, mapped against the competences it has. Built properly it is the most useful document a board produces about itself. Built badly, which is common, it becomes a grid that confirms the board already has everything it needs.
Two failures account for most of that. The first is deriving the matrix from the directors rather than from the strategy: a matrix that lists what the current board is good at and calls that the requirement will never show a gap. The requirement has to come from where the company is going and what threatens it, which means the matrix should change when the strategy changes and should be rebuilt rather than rolled forward. The second is self-assessment: a board that scores itself will report itself competent at cyber, at climate and at whatever else has been in the news, so the resulting matrix measures how the board feels about itself when what is needed is a measure of what it can do.
The output that matters is the gap, and a matrix that finds no gap has failed. For you as a new director this is also the fastest way to be useful: ask to see the skills matrix, ask what the board concluded was missing and ask what was done about it, because the answers tell you whether the nomination committee is genuinely composing a board or ratifying the one it already has.
Bring to the boardroom: What did our last skills matrix identify as missing, and what did the nomination committee do about it?
Lesson 4: What actually moves the number
The regional picture is precise, and you should carry it accurately. The Gulf Cooperation Council (GCC) Board Gender Index, produced by Heriot-Watt University with Aurora50 and covering 759 listed companies, reported in its third edition, published in April 2026 on data as at January 2026, that women hold 7 percent of GCC board seats, up from 6.9 percent the year before. Underneath the average, the range is wide: the UAE at 15.0 percent, Bahrain 10.5, Oman 7.0, Kuwait 5.6, Qatar 3.2 and Saudi Arabia 2.9.
The UAE figure is the instructive one. It stood at 3.5 percent in 2020 and reached 15 percent by 2026, after listed companies were required to include women on their boards. That is roughly a fourfold change in six years, set against a regional average that moved by a tenth of a percentage point in the most recent year. Whatever you think of mandates, that is the observable difference between a requirement and an aspiration, and you should know it before offering a view on either.
One more number repays your attention. The 403 GCC board seats held by women are held by 341 individuals, so a meaningful share sit on more than one board. A small group carrying multiple seats is a governance issue in its own right, because time and attention are finite and over-boarding is a real constraint on effectiveness. It is also a signal that the pipeline is being drawn from too narrow a pool, which points at the nomination committees before it points at supply, since the committees that say they cannot find candidates are usually looking in the places that produced the board they already have.
Bring to the boardroom: When we last recruited a director, where did the search actually look, and how did that differ from where the current board came from?
Self-check: 4 board scenarios
- A nomination committee member cites a consultancy study showing diverse boards financially outperform. The most useful contribution from a fellow member is:
- A board's skills matrix shows full coverage across every competence listed. The most likely explanation is:
- Women hold 7 percent of GCC board seats overall, but 15 percent in the UAE, up from 3.5 percent in 2020. The clearest reading is:
- 403 board seats held by women in the GCC are held by 341 individuals. For a nomination committee this most usefully signals:
Integrity and Financial Crime
Conflicts, inside information, fraud and financial crime are the failures that can end your board career, and most of them begin as something that looked ordinary at the time.
Lesson 1: Conflicts and the related-party transaction
The related-party transaction is the characteristic governance failure of a controlled company, and controlled companies are the norm across much of this region. It is worth being precise about why, because the usual framing, that related-party dealing is inherently improper, is wrong, and it gets in the way of your doing anything useful about it.
Transacting with a connected party is often perfectly legitimate and sometimes commercially sensible, because the counterparty is known and the relationship is durable, so terms can be agreed quickly. The failure lies in the absence of three protections around the transaction rather than in its existence: disclosure, so the board knows; independent assessment, so someone without an interest tests whether the terms are at arm's length; and abstention, so the interested party is not among those approving it.
The regulatory direction is firmly toward documentation. Federal Decree-Law No. 20 of 2025, which amended the UAE commercial companies law, added an express duty to disclose related-party transactions above statutory thresholds, together with conflicts-of-interest registers and formal minutes. Article 26, the Saudi provision setting out directors' seven core duties, requires you to disclose any direct or indirect interest in the company's business and contracts, and separately bars you from accepting a benefit from a third party in connection with your position. Your obligation has shifted from feeling conflicted and acting well to a duty discharged by declaring the interest, recording it and standing aside, in a form that can be inspected afterwards.
Bring to the boardroom: Was the interested party present when this was approved, and who without an interest tested the terms?
Lesson 2: Inside information and the discipline it demands
As a director on a listed board you routinely hold information that would move the price if it were known. That is the ordinary state of the job, and it changes what you may do with your own money and what you may say to other people.
Inside information is generally defined by three tests together: it is precise, it is not public and a reasonable investor would likely use it in deciding whether to deal. The three matter jointly: a vague sense that things are going well fails the precision test, a well-known market rumour fails the non-public test, but a specific figure a fortnight before results, which the market has not seen, meets all three comfortably.
The disciplines are mundane, and none of them is optional for you. Dealing belongs only in open windows, and a window being open is permission from the calendar rather than from the facts: if you hold something specific and unpublished you may not deal, whatever the window says. You may share nothing with a spouse, because a tip that leads to someone else's trade is generally an offence whether or not the tipper gained. An insider list must be kept, because regulators ask who knew and when, and a company that cannot answer looks culpable regardless of whether anyone actually traded. If the information leaks, the only real question is how quickly the company announces it to the market.
Bring to the boardroom: Do I currently hold anything precise and unpublished that would change how a reasonable investor acts?
Lesson 3: Fraud and what the board owes a whistleblower
Most fraud comes to light through a report, most often from an employee, rather than through an audit, which makes the reporting channel a control that your board owns.
Judge a whistleblowing arrangement on four things. Can a report be made outside the ordinary management line, given that the most serious cases implicate that line? Is anonymity genuinely available, and does the mechanism actually preserve it? Where do reports arrive, and does the audit committee see every one, including those that were closed quickly and especially those concerning senior people. And what happened to the reporters afterwards, which is the question almost nobody asks and the only one that reveals whether the channel is trusted.
That last point deserves weight, because a channel that receives nothing is usually a sign of fear rather than of health. When your board is told there were no reports this year, you should be uncomfortable, and should ask instead for volume and pattern over several years, how many reports were substantiated, how long they took to resolve and whether anyone who reported subsequently left the organisation.
Bring to the boardroom: How many whistleblowing reports arrived this year, and what happened afterwards to the people who made them?
Lesson 4: Laundering, sanctions and bribery: the board's exposure
Financial crime is where your exposure as a director is least intuitive, because liability can attach to a failure to prevent rather than to any act of participation. You do not have to have known about the crime for liability to arise: in several regimes it is enough that the systems you were responsible for were inadequate.
The regional picture moves, and moves in both directions, which is why treating any country as permanently high-risk is inaccurate. At its plenary of 17 to 19 June 2026 the Financial Action Task Force (FATF) added Iraq and Bosnia and Herzegovina to the list of jurisdictions under increased monitoring and removed Algeria and Namibia, leaving twenty-two jurisdictions listed, five of them Arab states. Listing is a technical finding about the machinery for detecting money laundering rather than a judgement about a country's people or its business community, and it comes with an agreed programme to fix it, which countries do complete and exit. Algeria's removal at that same plenary shows that the exit route is real.
For your board the consequences are operational. Listing makes it harder to keep the international banking relationships that clear the company's payments, lengthens payment chains and increases the diligence a counterparty will run on the company. If the company operates in or through a listed jurisdiction, your questions are: has our banking access changed, how long are settlements now taking and what has that done to working capital. On bribery, the exposure that matters most sits with third parties, since agents, distributors and intermediaries generate a large share of enforcement cases, and your question is whether anyone has actually looked at who they are and what they are paid for.
Bring to the boardroom: Which third parties act for us in our hardest markets, who checked them, and when?
Self-check: 4 board scenarios
- The company proposes to lease a warehouse from an entity owned by the chair's family. The board should treat this as:
- The trading window opens tomorrow, and a director holds a specific, unpublished figure that the market has not seen. The director may:
- The audit committee is told the whistleblowing line received no reports this year. The most appropriate response is:
- A country the company trades through is added to the FATF list of jurisdictions under increased monitoring. The board's first question should be:
The Controlled Company
Most boards in this region have a controlling shareholder, which is a different job from the one most governance training describes. Pretending otherwise leaves you unprepared for the boardroom you actually enter.
Lesson 1: What control actually changes
Of the hundred largest Arab family businesses ranked by Forbes Middle East in 2023, more than sixty percent were major shareholders in a company listed on a regional exchange, most of them among the founding shareholders. Listed and widely held are not the same thing here. When you join a listed board you are often still joining a controlled company, and the same holds in the Maghrib and the Levant, where large private groups and long-held family holdings dominate outside the state sector. Confident figures are also quoted for the share of Gulf non-oil output or private-sector employment that family firms account for; the published estimates range from about sixty to about ninety percent depending on which consultancy is asked, none of them traces to a statistics office, and you are better off not quoting any of them.
What changes is where the decision happens. On a widely held board, the boardroom is genuinely where the outcome is determined, because no single shareholder can carry a vote alone. On a controlled board it frequently is not: the outcome may be settled before the meeting, and the meeting ratifies it. If you do not understand this you will mistake ratification for deliberation and conclude the board is functioning well.
This does not leave you powerless. Your influence on a controlled board runs through what gets onto the agenda, what the board is told and when, what is recorded in the minute, what an independent committee is asked to examine and ultimately through your willingness to resign publicly. Those are real instruments, even though none of them is the instrument of outvoting anyone, and if you only know how to use the vote you will find you have nothing to use.
Bring to the boardroom: On the last significant decision, was this board deliberating or ratifying, and would I be able to tell the difference from the minutes?
Lesson 2: Minority protection and where it comes from
Where a controlling shareholder can carry any vote, the protection of everyone else has to come from somewhere other than the ballot. Across the region it comes from four places, and you should know which of them your company is actually subject to.
The first is related-party rules, which is why that lesson sits in the Integrity briefing: thresholds above which a transaction needs disclosure, independent assessment and approval without the interested party voting. The second is independent director requirements, which set how many independents a board must have and, more importantly, what must be referred to them. The third is disclosure obligations to the market, which are what let a minority shareholder discover anything at all. The fourth, and the most variable, is the courts.
Every market in the region has minority protections on paper, and what varies is whether they are enforced. They differ enormously in whether a minority shareholder has any realistic route to a remedy, how long that route takes and whether pursuing it is commercially survivable. Ask your company secretary a plain question early: has any minority shareholder here ever formally challenged anything, and what happened? The answer tells you the real strength of the protections, which is rarely the same as the strength of the drafting.
Bring to the boardroom: What must be referred to the independent directors here, and who decides what reaches them?
Lesson 3: The family constitution and the succession that tests it
Family-controlled groups often run two systems at once. There is the company, with its board and its company law, and there is the family, with its own council, its constitution or charter and its own way of settling things. Both systems are real, and the failure comes from a lack of clarity about which one decides what.
A family constitution typically covers who may work in the business, how shares may be transferred and to whom, how dividends are set, how the family speaks to the board and how disputes are resolved. It is usually not legally binding in the way the articles are, which is precisely why the relationship between the two documents matters. When the family council reaches a view and your duty points elsewhere, your obligation is unchanged and unambiguous: the duty runs to the company. It is much harder to do than to write, and knowing that in advance is most of your preparation.
Succession is where this is tested, and the founder transition is the most common governance crisis in the region. The pattern is recognisable: a founder-chair who has held the ownership and the authority together, a next generation that is better educated and commands less automatic deference and a board that has never had to function without one person's judgement at the centre. The questions you should ask long before that moment are whether a successor has been named, whether the board has ever met without the founder present and whether anyone has tested what the constitution actually says happens.
Bring to the boardroom: If the founder were unavailable from tomorrow, what does the documentation say happens, and has anyone read it recently?
Lesson 4: Being the independent on a controlled board
If you are a first-time director, the independent seat on a controlled board is frequently the one on offer, because controlled companies need independents to satisfy a listing rule or to reassure a lender. That is worth understanding, since it indicates what the role is actually for.
Establish four things before you accept, because after accepting the answers become much harder to obtain. Do you have direct access to management, or does everything route through the controlling family or its representative? Is there a genuine independent quorum, meaning enough independents that a committee can meet and reach a view without the controller present? What actually gets referred to the independents, and who decides that? And what happened to the last independent director who dissented, which is the single most informative question available to you and the one people are most reluctant to answer.
Clarity about the exit belongs in the same preparation. On a controlled board, your ultimate instrument is resignation, and it only works if the reason is on the record: a quiet resignation for personal reasons teaches nobody, while a resignation with a recorded reason is a governance act. You do not have to plan to use it, but you should know in advance that it is the instrument you hold, because deciding that under pressure, during the meeting itself, is how directors end up staying through things they should not have stayed through.
Bring to the boardroom: Has an independent director left this board after disagreeing here, and why did they go?
Self-check: 4 board scenarios
- A director joins the board of a listed company where one family holds 68 percent. The most accurate description of the position is:
- Assessing minority protection in an unfamiliar market, the most revealing question is:
- The family council resolves that the company should proceed with a transaction. A director's assessment is that it is not in the company's interest. The duty:
- Before accepting a seat on a controlled board, the question most people fail to ask is:
State-Linked Boards
Many of the region's most significant boards are state-owned, sovereign-fund held or somewhere between. Your duties stay the same, but whose expectations reach the boardroom changes, along with what it takes for you to keep your own judgement intact.
Lesson 1: Whose mandate prevails when objectives diverge
State-linked companies are common across every part of this region, in different forms. In the Gulf they are often sovereign-fund holdings or national champions with commercial mandates. In Algeria and Egypt large public enterprise sectors sit alongside private markets. In the Levant and the Maghrib, public utilities, ports, phosphates and airlines carry both a commercial and a public purpose. The governance question is the same everywhere: what happens when those two purposes point in different directions.
A dual mandate is legitimate: a state shareholder is entitled to pursue employment, regional development or security of supply through a company it owns. The failure is not the public objective itself but the objective arriving informally, unfunded and unrecorded, so that it shows up later as commercial underperformance nobody can explain.
The Organisation for Economic Co-operation and Development (OECD) guidelines on the corporate governance of state-owned enterprises, revised in 2024, give the cleanest principle for this, and it is worth remembering as a single sentence: a public policy objective imposed on a company should be mandated and publicly disclosed, and the net cost of a public service obligation should be separately funded, proportionate and disclosed. Your practical job is to insist that any objective arriving from the shareholder be written down and priced. Once it is written down, the board can be held to a fair account of its performance. While it stays informal, the board is being judged on a target it was never given in writing.
Bring to the boardroom: Which of our obligations exist because a shareholder wants them rather than because they make commercial sense, and are they written down and costed?
Lesson 2: Appointment, removal and the independence that survives them
Independence is harder to hold when the shareholder is a ministry or a fund, because the appointment and the removal usually sit with the same institution whose proposals you may need to challenge. That pressure is structural, and you will do better when you say so out loud.
Ask how appointments are actually made: whether there is a nomination process with published criteria or whether seats are allocated, whether terms are fixed and staggered or serve at pleasure and whether removal requires any stated cause. Fixed terms with stated removal grounds are the single strongest structural protection for an independent mind, and their absence tells you how much of your independence depends on nobody minding.
If you are nominated by a state shareholder you are not that shareholder's delegate, exactly as a director nominated by a family is not the family's delegate. Your duty runs to the company, and independent judgement is a duty in its own right. In practice this most often arises over information: being asked to brief the shareholder on a matter the board has not yet decided. Establish the protocol early, because agreeing it in advance is far easier than improvising it under pressure.
Bring to the boardroom: How is a director removed here, and does it require stated cause? What is the protocol for briefing the shareholder?
Lesson 3: Disclosure and the public interest in it
State-linked companies often disclose less than listed peers, on the reasoning that with a single known shareholder there is no dispersed investor base to inform. The reasoning is incomplete, because the ultimate owner is the public, and the case for disclosure is therefore at least as strong as it is for a listed peer.
Three practical questions follow for you. Are the accounts audited to the same standard a listed company would face, and by whom? Are related-party transactions with other state entities identified and disclosed, given that in a large public sector most counterparties may be related parties, which makes the ordinary threshold test nearly meaningless without care? And is anything published about performance against the public objectives the company carries, since a company that is asked to pursue non-commercial goals and reports only commercial results is being measured on half its mandate.
This is also something you can propose in your first year. Proposing that the company publish what it was asked to do, what it cost and what it delivered is hard to argue against and rarely already in place.
Bring to the boardroom: If most of our counterparties are related parties, how do we identify the transactions that genuinely need scrutiny?
Self-check: 3 board scenarios
- The shareholding ministry asks the company to keep open a loss-making regional facility for employment reasons. The best board response is:
- Which feature most protects a director's independence on a state-linked board?
- In a large public sector where most counterparties are other state entities, the related-party regime is at risk of:
Work Outside the Formal System
In every market in this region, a share of the work a company depends on sits outside formal protection, in different forms and for different reasons. This is a governance question about your own company's conduct, and it continues the human rights briefing.
Lesson 1: What the numbers do and do not describe
Informal employment is a large share of work across North Africa, and your first discipline is to quote the number with its date attached. The most cited comparative figures come from the World Bank's study of Egypt, Morocco and Tunisia, published in June 2023, which puts informal employment at 77.3 percent in Morocco, 62.5 percent in Egypt and 43.9 percent in Tunisia, and informality across the region as a whole at 68 percent. Read the publication date and the survey date as separate things, because they are: those three country figures come from the labour force surveys of 2018 in Morocco and Egypt and 2019 in Tunisia. A 2023 report is not 2023 data, and different studies use different denominators.
National statistics are more current and worth going to directly. Morocco's Haut-Commissariat au Plan (HCP) ran a full national informal sector survey with fieldwork from April 2023 to March 2024, reporting in May 2025. It counted 2.03 million informal production units, up more than 353,000 on 2014, with trade the largest activity at 47 percent, followed by services at 28.3 percent and construction at 11.6 percent. The boundary deserves your notice: that survey covers non-agricultural units only, which is exactly the definitional choice that makes headline informality figures diverge.
Which way the figure is moving matters as much as where it stands. On the measure of employees working without a contract, the OECD's 2024 economic survey of Morocco, drawing on HCP data, records a fall from 67.2 percent of all employees in 2000 to 51.2 percent in 2022; the HCP's own annual results for 2024 put it lower again, with 52 percent of employees now holding a contract and 48 percent without one. If you quote a level without its trend you invite a changing situation to be read as a permanent characteristic.
Two readings of these numbers are wrong. Informality is not criminality: the World Bank attributes informality to institutional design, naming gaps in social protection, special tax regimes and exemptions, lengthy and costly dismissal procedures and the fact that registering a business delivers little in return. Nor is it a regional peculiarity, since large informal sectors exist in many economies at similar income levels. What they do describe is a strongly gendered pattern: the same OECD survey, again citing the HCP, estimates that in agriculture 82 percent of women work informally against 46 percent of men. Work outside formal protection is not distributed evenly between women and men.
Bring to the boardroom: Which of our market and demand figures are drawn only from formal-sector data, and what would they miss?
Lesson 2: The Gulf's version of the same question
The same question appears in the Gulf in a different form. Across the GCC a large share of the workforce is migrant, and the governance issues are recruitment, wage payment, mobility between employers and the conditions of accommodation and work.
These reforms are recent and substantial. Qatar adopted Law No. 19 of 2020 on 30 August 2020, removing the requirement for a migrant worker to obtain a no-objection certificate from an employer before changing jobs, which the International Labour Organization recorded as the first such step in the region; its Workers' Support and Insurance Fund, created in 2018 and operating from 2020, pays out where wages have gone unpaid. Wage protection systems requiring salaries to be paid through monitored bank transfers have spread across the region and address the most common abuse, which is simple non-payment. In October 2025 Saudi Arabia announced the end of the kafala sponsorship system after some fifty years, replacing it with a contract-based framework under which workers may change employer at contract expiry, travel without an employer's exit permission and hold their own passports. Rights organisations that welcomed the announcement have been explicit that the test is implementation rather than the text, so treat it as a changed baseline being monitored rather than as a settled outcome.
These reforms do not reach everything. Coverage of domestic workers is uneven, recruitment fees charged in origin countries continue to place workers in debt before they arrive, and reforms aimed at skilled and wealthy migrants have moved faster than those for low-wage workers. For you the exposure sits in the company's own labour chain, because reform at national level does not answer for what a particular contractor or recruiter is doing on the company's behalf, so your useful work is examining that chain instead of scoring a jurisdiction.
Bring to the boardroom: Who recruits the people who work on our sites, and did any of those workers pay a fee to get the job?
Lesson 3: What a board can actually ask
Your board controls only the company's own conduct, so that is where the questions below sit.
On the labour chain, ask how far into your supply chain work outside formal protection reaches, and at which tier. Most companies know their direct suppliers and assume the rest, which is where the exposure concentrates. Ask whether people doing continuing work for you are engaged in ways that leave them without contract, cover or recourse, whether directly, through labour contractors or through intermediaries. On cash, ask where the business handles significant cash and whether the controls are proportionate to that reality rather than to a cashless assumption imported from somewhere else. On competition, where you compete with operators carrying lower compliance costs, ask whether that pressure reaches your own incentives and whether you would know if it had.
One further question is easy to miss because it looks like a finance matter rather than a rights one. Market sizing, share and demand figures drawn from formal-sector data alone will understate a market where a large share of activity is informal. If your board makes capital allocation decisions on those numbers it is working from a partial picture. Knowing which of the company's figures carry that blind spot is a governance improvement, and on this subject it is unusually also a commercial advantage.
Finally, there is the opportunity, which is real and often missed. Extending contracts, protection and formal payment channels to people currently outside them is a business case as well as a rights position: it improves retention and quality and reduces exposure, and several governments in the region are actively incentivising it. The informal economy is also where a great deal of the region's entrepreneurship and employment sits, and many established companies began there. It is not only a risk for you to manage.
Bring to the boardroom: How deep into our own supply chain have we actually looked, and how do we know?
Self-check: 4 board scenarios
- A board is told that informal employment is high in a market it operates in. The most useful next question is:
- Morocco's own labour data shows employees without a contract falling from 67.2 percent in 2000 to 51.2 percent in 2022 and 48 percent in 2024. The significance for a board is that:
- Which best describes the governance relevance of Gulf labour reforms such as wage protection systems and the announced end of kafala sponsorship?
- A company's market share figures are built entirely from formal-sector data in a market with substantial informal activity. This is primarily:
How Seats Are Actually Filled
Every other briefing prepares you to be worth electing. This one concerns the election itself, which is the part that decides whether your preparation is ever used.
Lesson 1: Who actually elects directors
Most guidance about getting a board seat, including most of what circulates in this region, is written as though a nomination committee chooses directors. It does not, and as far as the instruments show, it does not anywhere in the Arab world. Directors are elected by the shareholders at the general assembly, while the committee screens who reaches the ballot.
The texts are unambiguous: Saudi Arabia's Corporate Governance Regulations have the committee "provide recommendations to the Board" (Article 62(2)), and require the slate put to the assembly to exceed the number of seats (Article 63(b)). Decision 3/RM of 2020 from the UAE's Securities and Commodities Authority (SCA) lists ten tasks for the Nomination and Reward Committee at Article 59, and selecting or recommending candidates is not among them. Jordan's Securities Commission instructions omit nominating directors from the committee's duties entirely.
This changes what preparation means for you: a file that satisfies the committee carries you onto the ballot and no further. Everything the committee assesses, meaning your record, independence and disqualifying facts, is a threshold test. The contest happens afterwards, where votes are counted, and it is decided by people whose names are on the share register.
Bring to the boardroom: For the seat I am pursuing, do I know who casts the votes, and who only reviews my file?
Lesson 2: The arithmetic of one seat
Board elections in Saudi Arabia, the UAE and Qatar use cumulative voting, and Saudi Arabia makes it mandatory: Article 5(a) of the Implementing Regulation of the Companies Law for Listed Joint Stock Companies requires it, and forbids using the voting right of a single share more than once. Each shareholder has votes equal to their shares, and may pile all of them on one candidate or spread them.
That rule is far better for you as an outsider than it first appears. Under ordinary majority voting, whoever controls the most votes fills every seat and a newcomer has no route at all. Under cumulative voting the question changes from whether you can outvote the largest holder to whether enough of the register will concentrate on you.
The standard formula puts the votes needed to secure one seat at slightly more than the total divided by the number of seats plus one. On a nine seat board that is a little over 10 percent. That is well short of a majority and needs no blessing from the controlling shareholder. Carry the number with you, because it converts a vague ambition into a target you can actually assess before spending a year on it.
Bring to the boardroom: How many seats is this board electing, and how many votes does it take to win one of them?
Lesson 3: Appointed seats and the shape of the register
Some seats never reach the ballot. Article 5(b) of the same Saudi regulation lets a company's bylaws name a shareholder with the right to appoint directors outright. There is a cap: appointed seats may not exceed half the board or three, whichever is fewer. In the UAE, Commercial Companies Law Article 148 gives the federal or a local government board appointment rights wherever it holds 5 percent or more of the capital, with no election at all.
Those seats leave the contest, so the remaining seats cost more votes each. Three appointed seats on a nine seat board means six are elected, and the fraction you need rises from about 10 percent to about 14. One provision cuts the other way and is worth your knowing: Article 5(b)(4) bars a shareholder who exercises an appointment right from also voting those same shares for the remaining seats.
Then there is the question of who holds the votes. Ownership across the Gulf is concentrated, with the largest shareholder averaging roughly a third of a company and only about a tenth of firms widely held (Martinez-Garcia and others, International Journal of Emerging Markets, 2022, 692 firms). That largest holder is most often the state, then holding companies, then families. The picture of the region as dominated by family owners is a non-Gulf one: in Jordan, family control runs through roughly two thirds of listed firms.
Bring to the boardroom: On this board, how many seats are actually elected rather than reserved, and who holds blocks big enough to decide one?
Lesson 4: How far a candidate may go
You are not confined to filing a form and waiting. Saudi Article 56(a) lets a shareholder appoint as proxy any natural person, from the shareholders or from outside, provided that person is not a board member. A candidate for a seat is by definition not yet a board member. Article 58 adds that unless the bylaws set a cap, a single proxy may hold any number of proxy letters and vote regardless of how many shares that represents.
One disclosure threshold applies before you gather any proxies. Under the Rules on the Offer of Securities and Continuing Obligations, a person who becomes the owner of, or acquires an interest in, 5 percent or more of a class of voting shares must notify the Exchange. That threshold sits below the 10 to 14 percent that wins a seat, so if you succeed at assembling votes you will pass it on the way. Whether holding proxies counts as acquiring an interest is not settled in the glossary of the Saudi Capital Market Authority (CMA) itself, and the wider of the two definitions of acting in concert covers co-operating, even informally, to exercise voting rights. Take advice from a Saudi capital markets lawyer before any action on this rather than after.
The strongest single predictor of an appointment in this region is a referral from someone already on the board, ahead of any of the mechanics above. Only 32 percent of GCC boards have a formal selection process at all (GCC Board Directors Institute, Board Effectiveness Review, November 2025). Diversity on Board does not broker introductions, and the mechanics above are not a substitute for one. What the mechanics offer you is a route that does not require knowing anyone, which is worth understanding for exactly that reason.
Bring to the boardroom: If I assembled the votes I need, would I cross a disclosure threshold, and have I taken advice on it?
Self-check: 4 board scenarios
- A candidate is told that their file impressed the nomination committee. What does that actually secure?
- A nine seat board elects all nine by cumulative voting. Roughly what share of the votes secures one seat?
- The bylaws let a named shareholder appoint three of the nine directors. What follows for a candidate?
- A candidate is considering gathering proxies from shareholders to support their own election. The first thing to establish is: