{"id":1516,"date":"2025-11-12T01:05:11","date_gmt":"2025-11-12T01:05:11","guid":{"rendered":"https:\/\/itlawco.com\/?p=1516"},"modified":"2025-11-13T19:42:52","modified_gmt":"2025-11-13T19:42:52","slug":"it-governance-under-king-v","status":"publish","type":"post","link":"https:\/\/itlawco.com\/fr\/it-governance-under-king-v\/","title":{"rendered":"IT governance under King V (South Africa, 2025 Update)"},"content":{"rendered":"\n\t\t<div id=\"fws_6a5f8bbf54a04\"  data-column-margin=\"default\" data-midnight=\"dark\"  class=\"wpb_row vc_row-fluid vc_row\"  style=\"padding-top: 0px; padding-bottom: 0px; \"><div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\"><div class=\"inner-wrap row-bg-layer\" ><div class=\"row-bg viewport-desktop\"  style=\"\"><\/div><\/div><\/div><div class=\"row_col_wrap_12 col span_12 dark left\">\n\t<div  class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \"  data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\" >\n\t\t<div class=\"vc_column-inner\" >\n\t\t\t<div class=\"wpb_wrapper\">\n\t\t\t\t\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p data-start=\"364\" data-end=\"849\">The release of the <a href=\"https:\/\/itlawco.com\/king-v-code-the-future-of-corporate-governance-in-south-africa\/\">King V Code on Corporate Governance for South Africa (2025)<\/a> marks the most decisive shift in local governance practice since the introduction of integrated reporting. For the first time, data, information, technology and AI form a standalone governance pillar. This article explains King V\u2019s expectations for IT governance, why they matter, and how South African organisations can operationalise them across sectors, ownership structures and maturity levels.<\/p>\n<h2 data-start=\"856\" data-end=\"909\">What King V requires: Principle 10 explained<\/h2>\n<p data-start=\"910\" data-end=\"945\">King V\u2019s <strong data-start=\"919\" data-end=\"935\">Principle 10<\/strong> provides:<\/p>\n<blockquote data-start=\"947\" data-end=\"1104\">\n<p data-start=\"949\" data-end=\"1104\">The governing body governs data, information and technology in a way that enables the organisation to sustain and optimise its strategy and objectives.<\/p>\n<\/blockquote>\n<p data-start=\"1106\" data-end=\"1257\">This principle reframes IT governance as a strategic, ethical, legal and risk-driven duty of the governing body\u2014not an internal technical function.<\/p>\n<h2 data-start=\"1259\" data-end=\"1306\">Scope of IT governance under King V<\/h2>\n<p data-start=\"1307\" data-end=\"1337\">Governing bodies must oversee:<\/p>\n<ul>\n<li data-start=\"1341\" data-end=\"1408\"><strong data-start=\"1341\" data-end=\"1360\">Data governance<\/strong> (lifecycle, classification, quality, privacy)<\/li>\n<li data-start=\"1411\" data-end=\"1485\"><strong data-start=\"1411\" data-end=\"1437\">Information governance<\/strong> (accuracy, integrity, availability, security)<\/li>\n<li data-start=\"1488\" data-end=\"1557\"><strong data-start=\"1488\" data-end=\"1513\">Technology governance<\/strong> (acquisition, use, development, disposal)<\/li>\n<li data-start=\"1560\" data-end=\"1624\"><strong data-start=\"1560\" data-end=\"1577\">Cybersecurity<\/strong> (prevention, detection, response, assurance)<\/li>\n<li data-start=\"1627\" data-end=\"1673\"><strong data-start=\"1627\" data-end=\"1641\">Resilience<\/strong> (BCP\/DR planning and testing)<\/li>\n<li data-start=\"1676\" data-end=\"1752\"><strong data-start=\"1676\" data-end=\"1710\">Third-party digital ecosystems<\/strong> (outsourcing, cloud, cross-border risk)<\/li>\n<li data-start=\"1755\" data-end=\"1827\"><strong data-start=\"1755\" data-end=\"1780\">Emerging technologies<\/strong> (including ethics, opportunity\u2013risk balance)<\/li>\n<li data-start=\"1830\" data-end=\"1900\"><strong data-start=\"1830\" data-end=\"1857\">Artificial intelligence<\/strong> (oversight, explainability, human control)<\/li>\n<\/ul>\n<blockquote>\n<p data-start=\"1902\" data-end=\"2077\">For regulated industries\u2014banking, insurance, healthcare, mobility, fintech\u2014these duties interact with POPIA, PFMA, JSE Listings Requirements, NCA, FAIS and sectoral standards.<\/p>\n<\/blockquote>\n<h2 data-start=\"2084\" data-end=\"2158\">Governing data and information: The board\u2019s direct accountability<\/h2>\n<p data-start=\"2159\" data-end=\"2239\">King V introduces a lifecycle-based approach to data and information governance.<\/p>\n<h3 data-start=\"2241\" data-end=\"2270\">Policy &amp; planning<\/h3>\n<p data-start=\"2271\" data-end=\"2291\">Boards must approve:<\/p>\n<ul>\n<li data-start=\"2295\" data-end=\"2323\">data governance frameworks<\/li>\n<li data-start=\"2326\" data-end=\"2362\">information classification schemes<\/li>\n<li data-start=\"2365\" data-end=\"2397\">privacy and security standards<\/li>\n<li data-start=\"2400\" data-end=\"2438\">cross-border and outsourcing protocols<\/li>\n<\/ul>\n<h3 data-start=\"2440\" data-end=\"2476\">Oversight and monitoring<\/h3>\n<p data-start=\"2477\" data-end=\"2519\">The governing body must be satisfied that:<\/p>\n<ul>\n<li data-start=\"2523\" data-end=\"2583\">data and information are managed ethically and responsibly<\/li>\n<li data-start=\"2586\" data-end=\"2647\">cyber and privacy incidents are identified and responded to<\/li>\n<li data-start=\"2650\" data-end=\"2702\">compliance with POPIA and other laws is maintained<\/li>\n<li data-start=\"2705\" data-end=\"2751\">third-party risks are effectively controlled<\/li>\n<li data-start=\"2754\" data-end=\"2817\">quality, completeness and usability of information are upheld<\/li>\n<\/ul>\n<h3 data-start=\"2819\" data-end=\"2840\">Assurance<\/h3>\n<p data-start=\"2841\" data-end=\"2975\">Internal audit, risk, privacy and cybersecurity functions must provide periodic assurance on effectiveness, compliance and ethics.<\/p>\n<h2 data-start=\"2982\" data-end=\"3060\">Technology governance: Strategy, resilience, risk and responsible use<\/h2>\n<p data-start=\"3061\" data-end=\"3127\">Under King V, technology becomes part of strategic value creation.<\/p>\n<h3 data-start=\"3129\" data-end=\"3160\">Strategic direction<\/h3>\n<p data-start=\"3161\" data-end=\"3193\">The board must set strategy for:<\/p>\n<ul>\n<li data-start=\"3197\" data-end=\"3236\">technology acquisition and investment<\/li>\n<li data-start=\"3239\" data-end=\"3273\">digital architecture and systems<\/li>\n<li data-start=\"3276\" data-end=\"3318\">responsible retirement of legacy systems<\/li>\n<li data-start=\"3321\" data-end=\"3389\">alignment with the organisation\u2019s business model and risk appetite<\/li>\n<\/ul>\n<h3 data-start=\"3391\" data-end=\"3428\">Organisational resilience<\/h3>\n<p data-start=\"3429\" data-end=\"3532\">King V elevates resilience and disaster recovery as explicit governance duties. Boards must ensure:<\/p>\n<ul>\n<li data-start=\"3536\" data-end=\"3557\">tested BCP\/DR plans<\/li>\n<li data-start=\"3560\" data-end=\"3588\">minimal downtime tolerance<\/li>\n<li data-start=\"3591\" data-end=\"3624\">continuity of critical services<\/li>\n<li data-start=\"3627\" data-end=\"3665\">cyber-resilience across infrastructure<\/li>\n<\/ul>\n<h3 data-start=\"3667\" data-end=\"3719\">Outsourced technology and cloud services<\/h3>\n<p data-start=\"3720\" data-end=\"3739\">Boards must ensure:<\/p>\n<ul>\n<li data-start=\"3743\" data-end=\"3758\">due diligence<\/li>\n<li data-start=\"3761\" data-end=\"3793\">minimum assurance requirements<\/li>\n<li data-start=\"3796\" data-end=\"3814\">enforceable SLAs<\/li>\n<li data-start=\"3817\" data-end=\"3847\">jurisdictional risk controls<\/li>\n<li data-start=\"3850\" data-end=\"3888\">exit strategies for critical vendors<\/li>\n<\/ul>\n<p data-start=\"3890\" data-end=\"3997\">This applies across cloud providers, AI models, SaaS, managed security services, and digital supply chains.<\/p>\n<h2 data-start=\"4004\" data-end=\"4073\">Cybersecurity and digital risk: A board-level responsibility<\/h2>\n<p data-start=\"4074\" data-end=\"4153\">Cybersecurity is no longer a technical control\u2014it is a governance function.<\/p>\n<p data-start=\"4155\" data-end=\"4174\">Boards must ensure:<\/p>\n<ul>\n<li data-start=\"4178\" data-end=\"4230\">effective cyber prevention, detection and response<\/li>\n<li data-start=\"4233\" data-end=\"4263\">alignment with risk appetite<\/li>\n<li data-start=\"4266\" data-end=\"4311\">root-cause reviews of significant incidents<\/li>\n<li data-start=\"4314\" data-end=\"4370\">uplift of security capabilities where weaknesses exist<\/li>\n<li data-start=\"4373\" data-end=\"4415\">reporting into risk and audit committees<\/li>\n<\/ul>\n<p data-start=\"4417\" data-end=\"4541\">Cyber-risk exposure now affects an organisation\u2019s assessment of ethical culture, conformance, legitimacy and value creation.<\/p>\n<h2 data-start=\"4548\" data-end=\"4597\">Governance of emerging technology and AI<\/h2>\n<p data-start=\"4598\" data-end=\"4682\">King V is the first local governance code to include direct obligations relating to:<\/p>\n<h3 data-start=\"4684\" data-end=\"4744\">Emerging, innovative and disruptive technologies<\/h3>\n<p data-start=\"4745\" data-end=\"4764\">Boards must ensure:<\/p>\n<ul>\n<li data-start=\"4768\" data-end=\"4810\">technology creates sustainable value<\/li>\n<li data-start=\"4813\" data-end=\"4867\">risks and opportunities are evaluated proportionally<\/li>\n<li data-start=\"4870\" data-end=\"4913\">impacts align with organisational context<\/li>\n<li data-start=\"4916\" data-end=\"4978\">technological decisions remain ethical and legally compliant<\/li>\n<\/ul>\n<h3 data-start=\"4980\" data-end=\"5026\">Artificial intelligence governance<\/h3>\n<p data-start=\"5027\" data-end=\"5051\">Boards must demonstrate:<\/p>\n<ul>\n<li data-start=\"5055\" data-end=\"5105\"><strong data-start=\"5055\" data-end=\"5079\">clear accountability<\/strong> for AI-driven decisions<\/li>\n<li data-start=\"5108\" data-end=\"5153\"><strong data-start=\"5108\" data-end=\"5140\">human oversight and override<\/strong> mechanisms<\/li>\n<li data-start=\"5156\" data-end=\"5193\"><strong data-start=\"5156\" data-end=\"5174\">explainability<\/strong> and transparency<\/li>\n<li data-start=\"5196\" data-end=\"5233\"><strong data-start=\"5196\" data-end=\"5208\">fairness<\/strong> and non-discrimination<\/li>\n<li data-start=\"5236\" data-end=\"5290\"><strong data-start=\"5236\" data-end=\"5260\">security and privacy<\/strong> measures embedded in models<\/li>\n<li data-start=\"5293\" data-end=\"5339\"><strong data-start=\"5293\" data-end=\"5315\">ethical guardrails<\/strong> for automated systems<\/li>\n<\/ul>\n<p data-start=\"5341\" data-end=\"5477\">This aligns with global trends (EU AI Act, OECD principles, NIST AI RMF) and positions King V at the frontier of responsible innovation.<\/p>\n<h2 data-start=\"5484\" data-end=\"5549\">King V\u2019s apply-and-explain disclosures for IT governance<\/h2>\n<p data-start=\"5550\" data-end=\"5584\">Organisations must report whether:<\/p>\n<ul>\n<li data-start=\"5588\" data-end=\"5657\">data and information are managed \u201ceffective, compliant and ethical\u201d<\/li>\n<li data-start=\"5660\" data-end=\"5725\">privacy breaches and cyber incidents were managed appropriately<\/li>\n<li data-start=\"5728\" data-end=\"5776\">technology processes deliver intended benefits<\/li>\n<li data-start=\"5779\" data-end=\"5816\">disruptive-tech risks are addressed<\/li>\n<li data-start=\"5819\" data-end=\"5873\">AI accountability and human-control mechanisms exist<\/li>\n<\/ul>\n<p data-start=\"5875\" data-end=\"5997\">This increases transparency expectations for integrated reports, sustainability reports and annual governance disclosures.<\/p>\n<h2 data-start=\"6004\" data-end=\"6070\">Practical use cases: What King V means in real operations<\/h2>\n<h3 data-start=\"6071\" data-end=\"6097\">Financial services<\/h3>\n<ul>\n<li data-start=\"6100\" data-end=\"6151\">AI-driven credit scoring must have human override<\/li>\n<li data-start=\"6154\" data-end=\"6202\">cyber resilience becomes a risk appetite issue<\/li>\n<li data-start=\"6205\" data-end=\"6271\">board committees must review model risk, not just financial risk<\/li>\n<\/ul>\n<h3 data-start=\"6273\" data-end=\"6310\">Technology and SaaS companies<\/h3>\n<ul>\n<li data-start=\"6313\" data-end=\"6370\">customer data lifecycle controls must be board-approved<\/li>\n<li data-start=\"6373\" data-end=\"6431\">cloud subcontracting must include assurance and controls<\/li>\n<li data-start=\"6434\" data-end=\"6497\">responsible-AI frameworks become a competitive differentiator<\/li>\n<\/ul>\n<h3 data-start=\"6499\" data-end=\"6526\">Retail and mobility<\/h3>\n<ul>\n<li data-start=\"6529\" data-end=\"6577\">large datasets trigger heightened privacy risk<\/li>\n<li data-start=\"6580\" data-end=\"6633\">IT downtime directly affects revenue and legitimacy<\/li>\n<li data-start=\"6636\" data-end=\"6682\">board must ensure robust supplier governance<\/li>\n<\/ul>\n<h3 data-start=\"6684\" data-end=\"6724\">Public sector and municipalities<\/h3>\n<ul>\n<li data-start=\"6727\" data-end=\"6766\">technology committees may be required<\/li>\n<li data-start=\"6769\" data-end=\"6844\">resilience of critical public infrastructure becomes a governance outcome<\/li>\n<li data-start=\"6847\" data-end=\"6890\">alignment with PFMA\/MFMA oversight duties<\/li>\n<\/ul>\n<h2>How ITLawCo can help<\/h2>\n<table>\n<thead>\n<tr>\n<th style=\"text-align: left;\"><strong>Service area<\/strong><\/th>\n<th style=\"text-align: left;\"><strong>What ITLawCo provides<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>IT governance frameworks<\/td>\n<td>Principle 10-compliant policies, standards, and lifecycle frameworks<\/td>\n<\/tr>\n<tr>\n<td>Board &amp; EXCO training<\/td>\n<td>Digital accountability, cyber risk, AI oversight<\/td>\n<\/tr>\n<tr>\n<td>POPIA &amp; global privacy<\/td>\n<td>Compliance, data mapping, cross-border governance<\/td>\n<\/tr>\n<tr>\n<td>Cybersecurity governance<\/td>\n<td>Cyber maturity assessments, incident response, resilience planning<\/td>\n<\/tr>\n<tr>\n<td>AI governance<\/td>\n<td>Model governance, oversight mechanisms, ethical frameworks<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\">Assurance integration<\/td>\n<td style=\"text-align: left;\">Linking IT, cyber, privacy and risk into audit and assurance programmes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 data-start=\"6897\" data-end=\"6938\">FAQs<\/h2>\n<\/div>\n\n\n\n<div class=\"toggles \" data-br=\"none\" data-starting=\"default\" data-style=\"default\"><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf56354\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf56354\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Does King V make IT governance a mandatory board responsibility?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf56354\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf56354\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes. Principle 10 explicitly requires the governing body\u2014not management\u2014to govern data, information, technology and AI.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf567ff\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf567ff\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>How does King V\u2019s IT governance expectation differ from King IV?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf567ff\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf567ff\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>King V broadens governance to include AI oversight, emerging technology, cyber resilience, and proportional disclosure.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf56cd4\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf56cd4\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What must the board disclose about technology under King V?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf56cd4\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf56cd4\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Boards must disclose whether technology, data and information are managed ethically, effectively and in compliance with law.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf571a3\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf571a3\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Are smaller organisations required to implement the same level of IT governance?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf571a3\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf571a3\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>No. King V allows proportionality, but the governing body must still achieve the objective of Principle 10.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf575a9\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf575a9\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Does King V require organisations to have a dedicated Technology Committee?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf575a9\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf575a9\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Not for everyone. Large, complex or high-impact organisations may require one; smaller entities may use combined committees.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf57996\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf57996\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>How does King V expect organisations to manage emerging technologies like AI?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf57996\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf57996\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Boards must ensure AI is governed with human oversight, transparency, fairness, privacy, security and accountability.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf57db4\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf57db4\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Does King V require organisations to manage cloud and outsourced IT risks differently?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf57db4\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf57db4\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes. Boards remain accountable and must ensure due diligence, assurance, contract controls and cross-border governance.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf581a3\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf581a3\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>How does cybersecurity fit into IT governance under King V?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf581a3\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf581a3\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Cybersecurity is a governance duty that intersects with risk, assurance, resilience and incident response.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf58582\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf58582\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What is expected from boards regarding data and information governance?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf58582\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf58582\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Lifecycle governance, classification, quality controls, privacy protection, compliance oversight and assurance.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf58959\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf58959\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Does King V apply to public entities, municipalities, retirement funds and NPOs?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf58959\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf58959\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes. King V applies universally with proportionality guiding implementation.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf58d44\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf58d44\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What happens if an organisation experiences a major cyber or privacy incident?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf58d44\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf58d44\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Boards must ensure effective response, consequence management, lessons learned and future prevention.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a5f8bbf59129\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a5f8bbf59129\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What must organisations do now to become King V-ready in IT governance?<\/a><\/h3><div id=\"toggle-panel-6a5f8bbf59129\" role=\"region\" aria-labelledby=\"toggle-button-6a5f8bbf59129\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Update frameworks, uplift cyber and AI governance, enhance data controls, improve digital literacy and strengthen assurance.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><\/div>\n\t<div class=\"wpb_raw_code wpb_raw_html wpb_content_element\" >\n\t\t<div class=\"wpb_wrapper\">\n\t\t\t<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@graph\": [\n    {\n      \"@type\": \"Organization\",\n      \"@id\": \"https:\/\/itlawco.com\/#organization\",\n      \"name\": \"ITLawCo\",\n      \"url\": \"https:\/\/itlawco.com\",\n      \"logo\": {\n        \"@type\": \"ImageObject\",\n        \"url\": \"https:\/\/itlawco.com\/wp-content\/uploads\/itlawco-logo.png\"\n      }\n    },\n    {\n      \"@type\": \"Article\",\n      \"@id\": \"https:\/\/itlawco.com\/insights\/it-governance-under-king-v#article\",\n      \"headline\": \"IT Governance Under King V\",\n      \"name\": \"IT Governance Under King V\",\n      \"description\": \"Explore how King V reshapes IT governance in South Africa. Learn what boards must do to oversee data, technology, cybersecurity and AI effectively \u2014 with practical steps for aligning organisational governance to Principle 10.\",\n      \"inLanguage\": \"en-ZA\",\n      \"author\": {\n        \"@id\": \"https:\/\/itlawco.com\/#organization\"\n      },\n      \"publisher\": {\n        \"@id\": \"https:\/\/itlawco.com\/#organization\"\n      },\n      \"mainEntityOfPage\": {\n        \"@type\": \"WebPage\",\n        \"@id\": \"https:\/\/itlawco.com\/insights\/it-governance-under-king-v\"\n      },\n      \"datePublished\": \"2025-11-13\",\n      \"dateModified\": \"2025-11-13\",\n      \"image\": {\n        \"@type\": \"ImageObject\",\n        \"@id\": \"https:\/\/itlawco.com\/wp-content\/uploads\/it-governance-under-king-v-digital-governance-south-africa-itlawco.jpeg\",\n        \"url\": \"https:\/\/itlawco.com\/wp-content\/uploads\/it-governance-under-king-v-digital-governance-south-africa-itlawco.jpeg\",\n        \"width\": 2400,\n        \"height\": 1350,\n        \"caption\": \"A modern South African boardroom where governance meets technology \u2014 illustrating the strategic role of data, cybersecurity and AI oversight under King V.\"\n      },\n      \"articleSection\": [\n        \"Corporate Governance\",\n        \"IT Governance\",\n        \"Data and Information Governance\",\n        \"Cybersecurity\",\n        \"AI Governance\",\n        \"King V\"\n      ],\n      \"keywords\": [\n        \"King V\",\n        \"IT governance\",\n        \"technology governance\",\n        \"data governance\",\n        \"information governance\",\n        \"AI governance\",\n        \"cybersecurity\",\n        \"corporate governance South Africa\",\n        \"Principle 10\",\n        \"ITLawCo\"\n      ],\n      \"about\": [\n        {\n          \"@type\": \"Thing\",\n          \"name\": \"King V Code on Corporate Governance for South Africa\"\n        },\n        {\n          \"@type\": \"Thing\",\n          \"name\": \"Principle 10 \u2013 Data, Information and Technology\"\n        },\n        {\n          \"@type\": \"Thing\",\n          \"name\": \"Corporate Governance\"\n        },\n        {\n          \"@type\": \"Thing\",\n          \"name\": \"Digital Governance\"\n        }\n      ],\n      \"contentLocation\": {\n        \"@type\": \"Place\",\n        \"name\": \"South Africa\"\n      }\n    },\n    {\n      \"@type\": \"FAQPage\",\n      \"@id\": \"https:\/\/itlawco.com\/insights\/it-governance-under-king-v#faq\",\n      \"mainEntity\": [\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Does King V make IT governance a mandatory board responsibility?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Yes. Principle 10 explicitly requires the governing body, not management, to govern data, information, technology and AI, including policy approval, oversight, risk management, ethical stewardship and assurance.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How does King V\\u2019s IT governance expectation differ from King IV?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"King V broadens IT governance to include data lifecycle governance, cybersecurity, emerging technologies, AI oversight and stronger disclosure requirements. IT is treated as a strategic governance pillar rather than a technical sub-issue.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What must the board disclose about technology under King V?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Boards must disclose whether data, information and technology are managed effectively, ethically and in compliance with applicable laws, and explain how significant incidents, cyber-attacks, privacy breaches, disruptive technologies and AI risks were handled.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Are smaller organisations required to implement the same level of IT governance?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"No. King V allows proportionality, so smaller organisations may scale practices according to their size, complexity and impact. However, the governing body must still achieve the objective of Principle 10 and cannot ignore IT governance altogether.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Does King V require organisations to have a dedicated Technology Committee?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Not in all cases. Large, complex or high-impact organisations may benefit from a dedicated Technology Committee, while smaller entities may allocate responsibilities to the Risk Committee or a specific director, provided the governing body retains accountability.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How does King V expect organisations to manage emerging technologies like AI?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Boards must ensure that AI and other emerging technologies are governed with human oversight and override mechanisms, transparency, fairness, privacy, security and accountability, so that automated decisions align with the organisation\\u2019s ethics and risk appetite.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Does King V require organisations to manage cloud and outsourced IT risks differently?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Yes. King V emphasises that accountability cannot be outsourced. Boards must ensure due diligence, minimum assurance requirements, contract controls, jurisdictional and cross-border safeguards, and exit strategies for cloud and other outsourced technologies.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How does cybersecurity fit into IT governance under King V?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Cybersecurity is a governance obligation that intersects with risk, assurance and resilience. Boards must oversee readiness, prevention, detection, incident response and recovery, and ensure cyber risk exposure remains within the organisation\\u2019s risk appetite.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What is expected from boards regarding data and information governance?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Boards are expected to approve and oversee frameworks for the acquisition, creation, use, dissemination and disposal of data and information, including classification of sensitive data, quality controls, privacy protection, compliance oversight and periodic assurance on effectiveness.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Does King V apply to public entities, municipalities, retirement funds and NPOs?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Yes. King V\\u2019s principles, including Principle 10 on data, information and technology, apply across sectors and forms of incorporation. Proportionality guides how recommended practices are implemented in different organisational contexts.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What happens if an organisation experiences a major cyber or privacy incident?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"The governing body must ensure that significant incidents are appropriately responded to, that consequences are managed, root causes are addressed, and lessons are integrated into future resilience, as this impacts ethical culture, conformance and legitimacy.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What must organisations do now to become King V-ready in IT governance?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Organisations should update IT governance frameworks, strengthen data and information governance, uplift cybersecurity capabilities, establish AI governance and oversight mechanisms, improve board-level digital literacy, and integrate IT, cyber and data risks into enterprise risk and assurance programmes.\"\n          }\n        }\n      ]\n    }\n  ]\n}\n<\/script>\n\n\t\t<\/div>\n\t<\/div>\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"The release of the King V Code on Corporate Governance for South Africa (2025) marks the most decisive shift in local governance practice since the introduction of integrated reporting. For...","protected":false},"author":1,"featured_media":3312,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[20],"tags":[116],"class_list":["post-1516","post","type-post","status-publish","format-standard","has-post-thumbnail","category-it-grc","tag-king-v"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>IT governance under King V (South Africa, 2025 Update) - ITLawCo<\/title>\n<meta name=\"description\" content=\"IT governance under King V in South Africa. Learn what boards must do to oversee data, technology, cybersecurity and AI effectively with practical steps for aligning organisational governance to Principle 10.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itlawco.com\/fr\/it-governance-under-king-v\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"IT governance under King V (South Africa, 2025 Update) - ITLawCo\" \/>\n<meta property=\"og:description\" content=\"IT governance under King V in South Africa. Learn what boards must do to oversee data, technology, cybersecurity and AI effectively with practical steps for aligning organisational governance to Principle 10.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itlawco.com\/fr\/it-governance-under-king-v\/\" \/>\n<meta property=\"og:site_name\" content=\"ITLawCo\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-12T01:05:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-13T19:42:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/09\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"577\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nathan-Ross Adams\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nathan-Ross Adams\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/\"},\"author\":{\"name\":\"Nathan-Ross Adams\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/180a104e03a6d73faeb2de9137a2a995\"},\"headline\":\"IT governance under King V (South Africa, 2025 Update)\",\"datePublished\":\"2025-11-12T01:05:11+00:00\",\"dateModified\":\"2025-11-13T19:42:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/\"},\"wordCount\":2631,\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg\",\"keywords\":[\"King V\"],\"articleSection\":[\"IT GRC\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/\",\"name\":\"IT governance under King V (South Africa, 2025 Update) - ITLawCo\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg\",\"datePublished\":\"2025-11-12T01:05:11+00:00\",\"dateModified\":\"2025-11-13T19:42:52+00:00\",\"description\":\"IT governance under King V in South Africa. Learn what boards must do to oversee data, technology, cybersecurity and AI effectively with practical steps for aligning organisational governance to Principle 10.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/#primaryimage\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg\",\"width\":1024,\"height\":577,\"caption\":\"A modern South African boardroom where governance meets technology \u2014 illustrating the strategic role of data, cybersecurity and AI oversight under King V.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/it-governance-under-king-v\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/itlawco.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"IT governance under King V (South Africa, 2025 Update)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"name\":\"ITLawCo\",\"description\":\"Fast, fearless legal\",\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/itlawco.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\",\"name\":\"ITLawCo\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"width\":2854,\"height\":2883,\"caption\":\"ITLawCo\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/itlawco\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/180a104e03a6d73faeb2de9137a2a995\",\"name\":\"Nathan-Ross Adams\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"caption\":\"Nathan-Ross Adams\"},\"sameAs\":[\"https:\\\/\\\/itlawco.com\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nathan-ross-adams-a5760b9a\\\/\"],\"url\":\"https:\\\/\\\/itlawco.com\\\/fr\\\/author\\\/itadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"IT governance under King V (South Africa, 2025 Update) - ITLawCo","description":"IT governance under King V in South Africa. Learn what boards must do to oversee data, technology, cybersecurity and AI effectively with practical steps for aligning organisational governance to Principle 10.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itlawco.com\/fr\/it-governance-under-king-v\/","og_locale":"fr_FR","og_type":"article","og_title":"IT governance under King V (South Africa, 2025 Update) - ITLawCo","og_description":"IT governance under King V in South Africa. Learn what boards must do to oversee data, technology, cybersecurity and AI effectively with practical steps for aligning organisational governance to Principle 10.","og_url":"https:\/\/itlawco.com\/fr\/it-governance-under-king-v\/","og_site_name":"ITLawCo","article_published_time":"2025-11-12T01:05:11+00:00","article_modified_time":"2025-11-13T19:42:52+00:00","og_image":[{"width":1024,"height":577,"url":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/09\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg","type":"image\/jpeg"}],"author":"Nathan-Ross Adams","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Nathan-Ross Adams","Dur\u00e9e de lecture estim\u00e9e":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/#article","isPartOf":{"@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/"},"author":{"name":"Nathan-Ross Adams","@id":"https:\/\/itlawco.com\/#\/schema\/person\/180a104e03a6d73faeb2de9137a2a995"},"headline":"IT governance under King V (South Africa, 2025 Update)","datePublished":"2025-11-12T01:05:11+00:00","dateModified":"2025-11-13T19:42:52+00:00","mainEntityOfPage":{"@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/"},"wordCount":2631,"publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"image":{"@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/09\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg","keywords":["King V"],"articleSection":["IT GRC"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/","url":"https:\/\/itlawco.com\/it-governance-under-king-v\/","name":"IT governance under King V (South Africa, 2025 Update) - ITLawCo","isPartOf":{"@id":"https:\/\/itlawco.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/#primaryimage"},"image":{"@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/09\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg","datePublished":"2025-11-12T01:05:11+00:00","dateModified":"2025-11-13T19:42:52+00:00","description":"IT governance under King V in South Africa. Learn what boards must do to oversee data, technology, cybersecurity and AI effectively with practical steps for aligning organisational governance to Principle 10.","breadcrumb":{"@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itlawco.com\/it-governance-under-king-v\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/#primaryimage","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/09\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/09\/it-governance-under-king-v-digital-governance-south-africa-itlawco-e1763050150371.jpg","width":1024,"height":577,"caption":"A modern South African boardroom where governance meets technology \u2014 illustrating the strategic role of data, cybersecurity and AI oversight under King V."},{"@type":"BreadcrumbList","@id":"https:\/\/itlawco.com\/it-governance-under-king-v\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itlawco.com\/"},{"@type":"ListItem","position":2,"name":"IT governance under King V (South Africa, 2025 Update)"}]},{"@type":"WebSite","@id":"https:\/\/itlawco.com\/#website","url":"https:\/\/itlawco.com\/","name":"ITLawCo","description":"Rapide, sans peur, juridique","publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itlawco.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/itlawco.com\/#organization","name":"ITLawCo","url":"https:\/\/itlawco.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","width":2854,"height":2883,"caption":"ITLawCo"},"image":{"@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/itlawco\/"]},{"@type":"Person","@id":"https:\/\/itlawco.com\/#\/schema\/person\/180a104e03a6d73faeb2de9137a2a995","name":"Nathan-Ross Adams","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","caption":"Nathan-Ross Adams"},"sameAs":["https:\/\/itlawco.com","https:\/\/www.linkedin.com\/in\/nathan-ross-adams-a5760b9a\/"],"url":"https:\/\/itlawco.com\/fr\/author\/itadmin\/"}]}},"_links":{"self":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/1516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/comments?post=1516"}],"version-history":[{"count":4,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/1516\/revisions"}],"predecessor-version":[{"id":3315,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/1516\/revisions\/3315"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media\/3312"}],"wp:attachment":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media?parent=1516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/categories?post=1516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/tags?post=1516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}