For Chairs, Directors, and Senior Decision-Makers
Board Oversight Diagnostic
Five questions across the highest-consequence governance areas. Takes two to three minutes. Your answers are not submitted or stored. Results are displayed in this browser session only.
Shared or managed devices: Results remain visible in this browser session until the page is closed or reset. On shared or managed devices, avoid using this diagnostic for sensitive internal matters.
Important: Please Read
This diagnostic is based on self-reported responses only. It is not an ARC Nexus Defensibility Assessment and does not constitute evidence of defensible Board oversight. ARC Nexus formal assessments require independent evidence review, domain-level traceability, and bounded conclusions governed by the ARC Nexus evidence discipline controls. Results are indicative of potential governance exposure only.
0 of 5
Q1 GD-01
Accountability & Ownership
Is Board-level accountability for cyber oversight clearly defined and documented, including who owns escalation, what gets reported, and at what threshold?
Boards that cannot evidence clear accountability structures face immediate exposure under director duty obligations.
Q2 GD-02
Reporting Integrity
Does the Board receive cyber risk reporting it can rely on, reporting that is decision-relevant, validated, and not primarily sourced from the team it is intended to oversee?
Q3 GD-03
Assurance & Independent Validation
Is there credible independent assurance over material cyber risks and controls, assurance that is independent of the operational team and tested, not just declared?
Q4 GD-04
Crisis Decision Governance
Are escalation pathways and Board decision-making roles clearly defined for a serious cyber event, and has the Board tested these arrangements in the past two years?
Q5 GD-11
Regulatory Monitoring
Does the Board receive clear reporting on relevant cyber regulatory and prudential developments, how they apply to the organisation, and what governance actions are required in response?