
---
title: The responsibilities of a Board of Directors
subtitle:
lang:
nav_top: nav_top.html

---

A **Board of Directors** is responsible for the company's overall governance, strategic oversight, and accountability. The Board normally does **not** manage daily operations. Instead, it supervises senior management and ensures that the company is being directed properly.

The central principle is:

> **The Board governs the company; management operates the company.**

## 1. Appoint and supervise the CEO

One of the Board's most important responsibilities is to appoint the chief executive officer or general manager and hold that person accountable.

The Board should:

* Appoint, evaluate, and, when necessary, replace the CEO.
* Define the CEO's authority and responsibilities.
* Approve the CEO's compensation.
* Set performance expectations.
* Review the CEO's performance periodically.
* Ensure that the CEO reports material problems promptly.
* Avoid interfering unnecessarily in routine management decisions.
* Ensure that the CEO develops capable managers.
* Maintain an emergency succession plan for the CEO.

The Board should not directly supervise ordinary employees unless exceptional circumstances require it.

## 2. Approve company strategy

Management normally develops the strategy, while the Board reviews and approves it.

Responsibilities include:

* Review the company's mission and long-term direction.
* Evaluate target markets.
* Review major products and services.
* Evaluate growth plans.
* Review major technology strategies.
* Approve entry into important new markets.
* Review major changes in the business model.
* Challenge assumptions behind management's plans.
* Ensure that strategy is realistic given the company's resources.
* Review strategic progress periodically.

The Board should ask:

> Where is the company going, why is it going there, and what could prevent it from succeeding?

## 3. Approve major business plans and budgets

The Board should review and approve major financial plans.

This may include:

* Annual operating budget.
* Capital expenditure budget.
* Hiring plans.
* Financing requirements.
* Revenue targets.
* Profitability targets.
* Cash-flow forecasts.
* Major investment plans.
* Significant research and development programs.

The Board should compare actual results with approved plans and require explanations for significant deviations.

## 4. Monitor financial condition

The Board must understand whether the company is financially sound.

Responsibilities include reviewing:

* Revenue.
* Expenses.
* Gross margin.
* Operating profit or loss.
* Cash balance.
* Cash-flow forecasts.
* Accounts receivable.
* Accounts payable.
* Debt.
* Capital requirements.
* Major liabilities.
* Financial forecasts.

The Board should pay particular attention to liquidity.

A company may be profitable on paper but still fail because it cannot meet its obligations when they become due.

## 5. Ensure reliable financial reporting

The Board should make sure financial information is accurate and trustworthy.

Responsibilities include:

* Review financial statements.
* Ensure appropriate accounting policies are used.
* Review unusual financial transactions.
* Ensure adequate accounting controls.
* Review material accounting judgments.
* Ensure financial information provided to shareholders is reliable.
* Review external auditor findings where applicable.
* Ensure management responds appropriately to accounting weaknesses.

## 6. Oversee internal controls

The Board should ensure that reasonable controls exist to protect company assets.

Examples include controls over:

* Bank accounts.
* Payments.
* Purchases.
* Payroll.
* Customer refunds.
* Company credit cards.
* Asset disposal.
* Inventory.
* System administrator access.
* Sensitive data.

The Board does not normally design these controls itself. It makes sure management has established adequate controls.

## 7. Oversee risk management

The Board should understand the major risks facing the company.

These may include:

* Financial risk.
* Customer concentration risk.
* Technology risk.
* Cybersecurity risk.
* Legal risk.
* Regulatory risk.
* Employee risk.
* Key-person risk.
* Supplier risk.
* Intellectual-property risk.
* Business continuity risk.
* Reputation risk.
* Market risk.

The Board should ensure that management:

* Identifies material risks.
* Assigns responsibility for them.
* Establishes appropriate controls.
* Monitors those risks.
* Reports major changes to the Board.

The Board does not need to eliminate all risk. Taking reasonable risk is part of business.

Its responsibility is to ensure that important risks are **understood and deliberately managed**.

## 8. Oversee cybersecurity and information risk

For a software company, cybersecurity deserves explicit Board attention.

The Board should ensure that management has adequate arrangements for:

* Cybersecurity governance.
* Access control.
* Privileged accounts.
* Multifactor authentication.
* Software vulnerabilities.
* Server security.
* Cloud security.
* Customer-data protection.
* Backup systems.
* Disaster recovery.
* Incident response.
* Employee security training.
* Third-party security risk.

The Board normally should not configure firewalls or servers itself.

Instead, it should ask questions such as:

> Who主管 cybersecurity?

> What are our most serious cybersecurity risks?

> Have backups actually been tested?

> What would happen if production systems were unavailable for two days?

## 9. Oversee legal and regulatory compliance

The Board should ensure that the company has reasonable systems for complying with applicable laws and regulations.

This may include:

* Corporate law.
* Tax law.
* Employment law.
* Privacy law.
* Consumer-protection law.
* Intellectual-property law.
* Software licensing requirements.
* Industry-specific regulation.
* Securities requirements, where applicable.

The Board should be informed promptly of serious legal disputes, investigations, or regulatory violations.

## 10. Protect shareholders' interests

Directors act for the company and should consider the interests of the company and its shareholders in accordance with applicable law.

Responsibilities may include:

* Treat shareholders appropriately.
* Ensure significant information is disclosed where required.
* Avoid improper use of company assets.
* Review transactions involving directors or related parties.
* Prevent management from using company resources primarily for personal benefit.
* Ensure major corporate decisions are properly authorized.

## 11. Manage conflicts of interest

Directors should disclose conflicts of interest.

Examples include situations where a director:

* Owns a supplier.
* Has an interest in a customer.
* Is involved with a competing company.
* Receives a personal benefit from a company transaction.
* Has family members involved in a proposed transaction.

The Board should have procedures for:

* Disclosure.
* Independent review.
* Recusal where appropriate.
* Recording decisions.

## 12. Approve major transactions

Certain transactions should normally require Board approval.

Depending on the company's articles, bylaws, applicable law, and internal policies, these may include:

* Major borrowing.
* Major capital expenditure.
* Acquisition of another company.
* Sale of a substantial business unit.
* Significant investments.
* Issuance of shares.
* Major leases.
* Important long-term contracts.
* Related-party transactions.
* Purchase or sale of major assets.
* Establishment of subsidiaries.
* Major litigation settlements.

The precise approval thresholds should be documented.

## 13. Capital structure and financing

The Board should oversee how the company is financed.

Responsibilities may include:

* Review borrowing requirements.
* Approve significant loans.
* Approve equity financing.
* Review changes to share capital.
* Evaluate investor proposals.
* Consider dilution of existing shareholders.
* Review financing risks.
* Ensure sufficient capital is available for the company's strategy.

## 14. Dividend decisions

Where applicable, the Board may:

* Review distributable profits.
* Consider cash requirements.
* Consider future investment requirements.
* Approve or recommend dividends in accordance with applicable law.
* Balance shareholder returns against the company's need for capital.

## 15. Executive compensation

The Board should establish appropriate compensation for senior management.

Responsibilities may include:

* CEO salary.
* Executive bonuses.
* Incentive plans.
* Stock options.
* Performance targets.
* Severance arrangements.

Compensation should encourage long-term company performance rather than inappropriate short-term risk taking.

## 16. Management succession

The Board should make sure the company can continue if key executives leave unexpectedly.

Responsibilities include:

* CEO succession planning.
* Emergency CEO replacement.
* Identifying potential future leaders.
* Reviewing succession for critical senior positions.
* Ensuring important knowledge is not concentrated in one individual.

For a small software company, key-person risk can be especially significant.

## 17. Review organizational structure

The Board may periodically review whether management has an appropriate organizational structure.

Questions include:

* Are responsibilities clearly assigned?
* Does every critical function have someone who主管 it?
* Are management roles clear?
* Are there gaps or unnecessary overlaps?
* Is authority properly delegated?
* Are there adequate backup personnel?

The Board generally approves the senior-level structure rather than detailed employee assignments.

## 18. Oversee major personnel matters

Ordinary employment decisions belong to management.

However, the Board may appropriately become involved in:

* Appointment of senior executives.
* Removal of senior executives.
* Executive compensation.
* Serious allegations involving the CEO.
* Major fraud investigations.
* Serious ethical violations.
* Succession planning.

The Board should avoid becoming a substitute HR department.

## 19. Corporate governance policies

The Board should establish or approve appropriate governance rules.

These may include:

* Delegation of authority.
* Approval limits.
* Conflict-of-interest policy.
* Code of conduct.
* Related-party transaction policy.
* Whistleblower procedures.
* Information-security governance.
* Document-retention policies.
* Board meeting procedures.

## 20. Ethics and corporate culture

The Board should influence the ethical standards of the company.

It should expect management to promote:

* Honesty.
* Compliance with law.
* Accurate reporting.
* Respectful treatment of employees.
* Proper handling of customer data.
* Responsible use of company resources.
* Prompt escalation of serious problems.

The behavior tolerated by the Board and senior management usually becomes the practical culture of the organization.

## 21. Protect intellectual property

For a software company, intellectual property may be its most important asset.

The Board should ensure management appropriately protects:

* Source code.
* Software copyrights.
* Trademarks.
* Patents where applicable.
* Trade secrets.
* Proprietary algorithms.
* Customer databases.
* Confidential documentation.
* Domain names.

It should also ensure that employee and contractor agreements properly address intellectual-property ownership.

## 22. Oversee open-source and third-party software risks

The Board usually does not review individual libraries, but should ensure that management has appropriate processes for:

* Open-source license compliance.
* Third-party software licensing.
* Security vulnerabilities.
* Dependency management.
* Proprietary software rights.
* Software supply-chain risk.

## 23. Business continuity and disaster recovery oversight

The Board should ensure that management can continue critical operations after serious disruption.

It should periodically review:

* Backup strategy.
* Restore testing.
* Disaster-recovery plans.
* Emergency contacts.
* Alternative infrastructure.
* Key-person contingency plans.
* Critical supplier dependencies.
* Cyberattack recovery plans.

## 24. Insurance oversight

The Board should ensure appropriate insurance has been considered.

Depending on the company, this may include:

* General liability.
* Professional liability.
* Cyber insurance.
* Property insurance.
* Directors and officers liability insurance.
* Employment-related insurance.
* Business interruption insurance.

## 25. Review major customer and supplier dependencies

For a small company, losing a single large customer or supplier can threaten the business.

The Board should understand:

* Revenue concentration.
* Major customer dependencies.
* Critical cloud providers.
* Critical technology suppliers.
* Payment processors.
* Major distribution partners.
* Single-source suppliers.

Management should have contingency plans where concentration creates material risk.

## 26. Monitor company performance

The Board should receive regular management reports.

For a small software company, a practical Board dashboard might include:

| Area       | Typical indicators                      |
| ---------- | --------------------------------------- |
| Finance    | Revenue, profit/loss, cash, receivables |
| Sales      | Pipeline, new customers, renewals       |
| SaaS       | MRR, ARR, churn                         |
| Product    | Releases, major defects, roadmap        |
| Customers  | Support volume, complaints, retention   |
| Technology | Availability, major outages             |
| Security   | Significant incidents, vulnerabilities  |
| Employees  | Headcount, turnover, critical vacancies |
| Projects   | Major milestones and delays             |
| Risk       | Important changes in major risks        |

The Board does not need hundreds of metrics. It needs enough information to identify important developments.

## 27. Require corrective action

When the Board identifies significant weaknesses, it should require management to address them.

For example:

> Board identifies repeated production outages → CEO/CTO investigates → management produces corrective plan → Board reviews progress.

The Board's job is not necessarily to implement the technical solution.

Its responsibility is to ensure that the problem is being appropriately managed.

## 28. Board meetings and records

The Board should conduct meetings in an organized manner.

Responsibilities include:

* Schedule meetings.
* Establish agendas.
* Provide directors with relevant information beforehand.
* Review management reports.
* Discuss important decisions.
* Record resolutions.
* Maintain meeting minutes.
* Record conflicts of interest.
* Follow up on agreed actions.

Board minutes should document important decisions without becoming a transcript of every conversation.

## 29. Maintain independence of judgment

Directors should exercise their own judgment rather than merely approve whatever management proposes.

They should:

* Ask questions.
* Request additional information where necessary.
* Challenge unrealistic assumptions.
* Consider alternatives.
* Identify risks.
* Record disagreement where appropriate.

A Board that simply approves everything presented by the CEO provides little meaningful governance.

## 30. What the Board should normally NOT do

A Board of Directors should generally **not** handle routine operational activities such as:

* Writing software.
* Managing ordinary customer tickets.
* Approving normal employee leave.
* Configuring servers.
* Creating routine invoices.
* Running payroll.
* Purchasing ordinary office supplies.
* Supervising individual developers.
* Making minor website changes.
* Performing routine sales follow-ups.

Those are management and operational responsibilities.

The Board should instead ensure that appropriate people are assigned to those functions and that management reports significant results and problems.

# Board versus CEO versus operational owner

A useful distinction is:

| Level                     | Main responsibility                   |
| ------------------------- | ------------------------------------- |
| **Board of Directors**    | Governance and oversight              |
| **CEO / General Manager** | Overall company management            |
| **Function owner / 主管**   | Accountable for a particular function |
| **Employee / operator**   | Performs the actual tasks             |

For example, for cybersecurity:

**Board**

> Ensures cybersecurity risk is being appropriately governed.

**CEO**

> Ensures the company allocates appropriate people and resources to cybersecurity.

**CTO — cybersecurity owner / 主管**

> Establishes the cybersecurity program and makes sure it operates properly.

**DevOps engineer/developers**

> Perform patching, configuration, monitoring, coding, and remediation.

# The Board's core responsibilities in one sentence

The Board of Directors is responsible for:

> **Selecting and supervising senior management, approving the company's strategic direction and major decisions, overseeing financial condition, risk, compliance, internal controls and corporate governance, and protecting the long-term interests of the company and its shareholders.**

For a small software company, an especially important discipline is maintaining the distinction between **Board governance** and **daily management**. A director may also be the CEO or CTO, but when acting as a director, that person should think about whether the company is being properly governed—not simply about today's operational tasks.
