When technology decisions belong at board level

Your Board approved the technology budget in June, in about twenty minutes. By the following March, agents were drafting and sending customer correspondence and recommending claim outcomes inside three products that had been running for years. No deployment crossed the financial delegation or needed a new business case, because each one extended a product already in operation. The Board learned what it had approved when the platform invoice outran its forecast and an auditor asked who had authorised automated decisions on customer claims.

In Brief


  • The Board governs technology at the irreversibility boundary above the portfolio, and only there. Everywhere else it sets the envelope within which the Product Portfolio Executive decides.
  • Four conditions bring a decision to the Board: a cost threshold exceeded, a material change in risk profile, a risk threshold approached or breached, and a lifecycle stage boundary crossed.
  • Each trigger fires against something the Board has fixed in advance. A ceiling, appetite statement or stage definition that was never written gives the trigger nothing to measure.
  • AI weakens all four the same way: spending and agent authority build up inside products already in operation, below any single decision the Board would see.

Board involvement in technology portfolio governance is triggered by four conditions: investment exceeds a defined cost threshold, a change materially alters the organisation’s risk profile, a defined risk threshold is approached or breached, or a product crosses a lifecycle stage boundary at which its strategic case needs reconfirming (Hodgson, 2026, Chapter 7). Outside those triggers, the Board sets the envelope and leaves the decisions inside it to the Product Portfolio Executive. The four conditions say when the Board decides. Whether they work depends on what the Board has fixed before any of them fires, and on whether the evidence reaching it still reflects what AI-augmented products are doing.

Set the envelope before the triggers

The envelope is the Board’s standing contribution to technology governance: an investment ceiling, a risk appetite and the strategic boundaries within which the Product Portfolio Executive operates with full authority (Hodgson, 2026, Chapter 7). The Board sets conditions, and the Portfolio Executive decides within them (Hodgson, 2026, Chapter 11). A Board that approves individual investments, reviews individual product decisions and asks for status reports at steering committee frequency turns the quarterly portfolio review into an upward briefing, and the reallocation it exists to produce stops happening (Hodgson, 2026, Chapter 7).

Regulated boards already own part of the envelope. The Board of an APRA-regulated institution sets the risk appetite within which it expects management to operate and approves the risk appetite statement (Australian Prudential Regulation Authority [APRA], 2019). The Australian Securities Exchange (ASX) recommendations currently in force ask a listed entity’s Board or risk committee to review the risk management framework at least annually and to confirm the entity is operating with due regard to the appetite the Board has set (ASX Corporate Governance Council, 2019). In a non-corporate Commonwealth entity, the accountable authority determines risk appetite and tolerance under the Commonwealth Risk Management Policy (Department of Finance, 2022). Each instrument places the appetite with the governing body and leaves its translation into technology terms to the organisation. That translation is the Board’s first design task, because a trigger defined against an appetite nobody has expressed for technology has no reference point.

Trigger (Evolve, Chapter 7)What the Board fixes in advanceWhat the Product Portfolio Executive bringsHow AI weakens it
Investment exceeds a defined cost thresholdAn investment ceiling for the portfolio and each product line, stated as total cost of ownershipConsumption against the ceiling by product line, at the cadence spending movesConsumption spending grows daily without any single approval
A change materially alters the risk profileA risk appetite statement specific enough to define a material change in technology riskA pattern assessment of whether each governance boundary is effective, needs moving, or lacks evidenceAgent authority widens inside a product already in operation
A defined risk threshold is approached or breachedA measured threshold and the method for aggregating exposure across productsEvidence-Based Management (EBM) evidence, with the four AI debt questions answeredAI debt degrades the evidence the threshold is read from
A product crosses a lifecycle stage boundaryStage definitions and the evidence each transition requiresThe product’s stage classification and its restated strategic caseA team working at machine speed finishes against a stale target before the next review

Note. The trigger column is Evolve (Hodgson, 2026, Chapter 7). The remaining columns are ZXM’s synthesis from Chapters 6, 8, 9, 10, 11 and 15 of the book.

Thresholds that consumption spending slips under

A cost threshold works when spending arrives as a decision. Consumption-based AI spending rarely does. A single poorly scoped agent can consume a month’s budget in a day, and its cost varies with model choice and reasoning depth rather than infrastructure volume (Hodgson, 2026, Chapter 15). A threshold applied per business case or per procurement never fires, because neither event occurs. The threshold registers the growth only when it is read against total cost of ownership per product line, where build, operation, maintenance and retirement sit in one budget line that the portfolio review assesses against value (Hodgson, 2026, Chapter 15). Delegation follows the same structure: the team spends within the Sprint boundary, the Product Manager within the product’s investment envelope, and the portfolio review reallocates across products (Hodgson, 2026, Chapter 15). Applied in that structure, the cost trigger brings the Board in when a product line’s cost of ownership, or the portfolio’s, would pass the ceiling the Board set.

The risk threshold fails more quietly. It is read from the evidence the quarterly portfolio review receives, and in an AI-augmented product that evidence is only as reliable as the conditions producing it (Hodgson, 2026, Chapter 11). When governing instructions go unrevised while the operating context moves, agents keep producing compliant output against rules that have stopped being true, and Current Value, Time to Market and the quality signal all separate from what customers experience (Hodgson, 2026, Chapter 11). A threshold calibrated against that evidence reports exposure inside tolerance while the real exposure grows.

The Product Portfolio Executive therefore brings two things to the Board: the aggregated exposure figure, and the answers to four AI debt questions. Are governing instructions carrying revision history? Does the Definition of Done still govern every agent instruction? Are operating model signals reaching the Product COO, and is the Product COO acting on them? Has a budget cycle eroded the team persistence that makes the pattern visible (Hodgson, 2026, Chapter 11)? A negative answer on any one means the exposure figure cannot be relied on, and the Board needs that finding as much as it needs to know about a breach.

Changes that arrive without a decision

The risk profile trigger assumes a change in exposure arrives as a proposal someone presents. With AI, the change more often arrives as an extension of authority inside a product already in operation. An agent that drafted correspondence for review begins sending it; an agent that recommended claim outcomes begins recording them. Each step can be sound on its own evidence. Together they move the irreversibility boundary, the point beyond which a wrong decision cannot be corrected in the product’s next iteration (Hodgson, 2026, Chapter 8), and the organisation’s risk profile moves with it.

What reaches the Board is a pattern assessment of the governance boundary built from Sprint-level evidence: the boundary is effective, it needs moving, or the evidence is insufficient to confirm either. The Board holds the boundary, adjusts it or asks for more evidence before judging it. Whether the product continues is a separate decision made against separate evidence (Hodgson, 2026, Chapter 9). The trigger fires reliably only where a delegation schedule names which governing instructions a team may revise in its own Retrospective and which require a higher tier (Hodgson, 2026, Chapter 15). That schedule is what turns a quiet extension of agent authority into a visible change.

The lifecycle stage trigger depends on classification. Products move through Introduction, Growth, Maturity and Decline, each with its own investment problem and governance posture (Hodgson, 2026, Chapter 6), and a transition between stages is where the strategic case comes back to the Board (Hodgson, 2026, Chapter 7). These are product lifecycle stages. The stage gates of project governance fund a scoped deliverable and offer no clean mechanism to redirect it when an assumption fails (Hodgson, 2026, Chapter 6). A portfolio that holds a mature product at Growth, or a declining product at Maturity, never raises the Board conversation a change of stage requires, as the investment questions for each lifecycle stage show. When classification lags, the Board reconfirms a strategic case the work has already overtaken, and at machine speed that happens faster: an AI-augmented team directed at a target the market has moved past accelerates through the remaining work and delivers an outcome nobody needs before the next review convenes (Hodgson, 2026, Chapter 10).

One decision tested against all four

Take the Board that approved the budget in June. Its three products are in Maturity and stay there, so the lifecycle trigger is silent, and rightly so. The correspondence agent’s own running cost is small, and the invoice overrun came from consumption across all three products. Read per business case, that growth never reached the cost trigger; read as cost of ownership per product line, it would have appeared at the portfolio review months before the invoice. The portfolio’s aggregated exposure figure sat inside tolerance, which the Board could believe only if the AI debt questions had been asked that quarter.

The decision that mattered moved the correspondence agent from drafting to sending, and only the risk profile trigger could have caught it. It catches that decision when two conditions hold: the delegation schedule classes the change as a boundary movement requiring a higher tier, and the Product Portfolio Executive’s pattern assessment reports the boundary as moved. Without both, the organisation operates four triggers and none of them registers the decision the auditor asked about.

What this means for senior leaders: A trigger is only as effective as the term it measures against, and a term written for spending and risk that arrive as proposals will not register what arrives any other way. Before asking whether the four triggers exist, test whether the ceiling, the appetite statement, the stage definitions and the exposure measure would register what AI-augmented products change between reviews.

References

Receive insights on strategy, leadership, and transformation.
By subscribing you agree to our Privacy Policy
© 2026 Zen Ex Machina (ZXM) Pty Ltd. All rights reserved. ABN 93 153 194 220
search previous next tag category expand menu location phone mail time cart zoom edit close