Introduction

In an era where data breaches have become alarmingly commonplace, the need for robust data governance has never been more critical. Every piece of sensitive information collected by organizations carries the potential for misuse or exposure. In South Africa, the recent changes brought about by King V, particularly the enforcement of Principle 10, are set to redefine how boards govern data. This new principle does not merely suggest best practices; it makes boards directly accountable for data management, an unprecedented shift designed to protect consumers and businesses alike.

The Significance of Principle 10

Principle 10 articulates that governing bodies must oversee data management in a manner that supports the organization’s strategic objectives. This accountability extends beyond mere oversight into the essential parameters of data acquisition, usage, dissemination, and disposal. The goal is to cultivate a culture of responsibility and transparency within organizations.

As the IoDSA aptly points out, the most significant variations introduced by King V occur in the data and technology chapter. This section shifts the focus from treating data as a secondary asset to recognizing it as a governed entity in its own right. Such a transformation necessitates that boards not only manage data but also account for it.

Accountability at All Levels

For many organizations, the typical response to governance changes involves delegating responsibilities to a risk committee or an IT department. However, as Principle 10 highlights, this approach lacks the rigorous accountability necessary to ensure effective data management.

The board must now ensure that those on the ground, including the CIO and database administrators, can succinctly and accurately identify where sensitive data resides and how it is governed.
This necessity is underscored by growing concerns surrounding data breaches and the fallout resulting from insufficient governance.

The Realities of Data Management

Boards are tasked with a set of pressing questions about their data environments: Where is sensitive data stored? Who has access to it? Are the systems managing this data still supported? These are not simple inquiries. With a staggering 79% of cyber-attacks initiated by compromised identities, the stakes have never been higher.

Statistics from the Information Regulator reveal that thousands of security compromises stem from human error, making it clear that governance failures often lurk at layers of data management that are invisible to the casual observer. An alarming instance involved a college's CFO who mistakenly shared sensitive employee information along with unrelated finance policies—an all-too-common governance lapse that shows the significant consequences of inadequate data management.

The Importance of Evidence

As we consider the broader context of Principle 10, it becomes evident that evidence of effective governance must pre-date inquiries from auditors or regulators. According to recent findings, the average dwell time for an attacker in an organization's IT environment is a mere eighteen days—far shorter than many quarterly reporting cycles.

“We would have noticed,” is no longer a defensible claim when threats can manifest so swiftly.
This reality elevates the urgency of actionable data governance practices within organizations.

A Call for Preparedness

The implications for South African enterprises are profound; many may currently lack a formalized data governance framework. A survey by Redgate highlighted that nearly 77% of organizations do not have established guidelines for data management. With the pressure mounting, organizations must now prioritize developing responsible governance policies that are not only theoretical but backed by operational realities.

The emphasis on accountability manifests through robust assessments and audits to ensure all data management practices align with Principle 10.

Assurance should mean more than a tick-box exercise; it requires a comprehensive understanding and inventory of data assets that is known and managed at every level of the organization.

The Role of Technology in Governance

As organizations aim to comply with King V, technology emerges as both a facilitator and a challenge in data governance. Boards must ensure that investments yield positive returns and that technology is not a hindrance to effective governance. Practically, this means understanding how cloud services, applications, and databases fit into the data governance framework.

One of the largest recurring technology costs for many South African businesses is their Microsoft estate, which includes licenses and subscriptions—this expenditure must also fall under the governance umbrella.

Looking Ahead: 2027 and Beyond

The first reports corresponding with Principle 10 will arrive in 2027, but the year they will depict is already unfolding. Organizations that prepare thoroughly will likely thrive in the wake of King V's mandates, while those merely putting their governance in place on paper may find themselves exposed and vulnerable.

As organizations draw closer to the impending deadlines for compliance, vigilance must be their hallmark.

“The real danger for boards will lie in their assumptions about what constitutes effective data governance,” the author notes.
Boards must resist the temptation to treat accountability as a surface-level concern; instead, animating it will require deep engagement and integration throughout their organizational practices.

Conclusion

Ultimately, the conversation around accountability in data governance is not merely an academic one—it is inherently practical, with real consequences for organizations and their stakeholders. Emphasizing a proactive approach to data management today will inevitably set the stage for a more secure and ethically compliant future. The author, Johan Lamberts, a managing director with considerable experience in technology and data management, asserts,

“Principle 10 does not change the nature of a database estate. It changes who is accountable for it.”
The onus is now on boards to embrace this accountability, ensuring that they are prepared for whatever challenges lie ahead as they navigate an increasingly complex landscape.