
Board risk oversight is fragmenting, and CFOs absorb the load
Boards are spreading risk oversight beyond the audit committee, leaving finance to reconcile the same numbers for several committees just as the SEC moves toward charging individuals.
Board risk oversight used to have a clear address: the audit committee, once a quarter, with a risk appetite slide near the back. That address is breaking up. A new Ernst & Young study reported by CFO.com on Sept. 16, 2026 finds boards broadening risk focus past the traditional risk and audit committee structure as risk profiles get more complex, and the unglamorous consequence lands in the office of the CFO. The same underlying risk data now has to be packaged for three or four audiences on different cadences, with no added headcount.
Why the audit committee stopped being the only destination
The logic behind the shift is defensible. Cyber, AI, third-party concentration, sanctions exposure and climate reporting do not share a common vocabulary, and a single committee working through a two-hour agenda cannot give each of them real scrutiny. So boards create a technology committee, hand sanctions and trade to a compliance committee, or stand up an ad hoc risk working group. Oversight gets deeper on each topic.
What it also does is multiply the number of forums that need numbers. Finance is usually the only function with an enterprise view of exposure, loss history, reserves and the controls that sit behind them. When oversight fragments, the finance function becomes the de facto aggregator by default rather than by decision, and the aggregation work shows up in the controller's calendar long before it shows up in anyone's budget.
Inconsistent committee decks are now a legal problem
The enforcement backdrop makes the data-consistency question concrete. Cooley's review of fiscal 2025 SEC activity, published Dec. 23, 2025, expects the Commission to prioritize charging responsible individuals over levying corporate penalties. The settled order against Archer-Daniels-Midland and two former executives on Jan. 27, 2026 is the clearest marker. As Morrison Foerster's roundup noted, the accounting and disclosure charges reached the former CFO of the company's Nutrition segment. Not the group CFO. A segment-level finance chief.
Morgan Lewis, writing on Jan. 14, 2026, catalogued the conduct at issue in recent executive cases: falsifying records, misleading auditors and false certifications. Those are the three failure modes that sit closest to a CFO's signature. In that environment, a cyber committee deck that reports a different incident count than the audit committee deck is not merely untidy governance. It is a set of documents that a regulator or plaintiff's counsel will line up side by side and ask someone to explain under oath.
The personnel consequences of control failure have also become visible. CFO Dive reported Beyond Meat terminating its controller after a material weakness was identified, and Super Micro placing a co-founder on leave and terminating a contractor following charges. Control breakdowns are no longer absorbed quietly at the entity level.
Three decisions that cannot be deferred
First, ownership of the single source of risk data. One system, one taxonomy, one reconciliation owner, so that the technology committee and the audit committee receive the same figures with different commentary rather than different figures entirely. This is a data governance decision dressed as a reporting decision.
Second, escalation routing. Draw the line between what goes to the disclosure committee, which exists to decide whether something is material and reportable, and what goes to a board committee for oversight. Those paths serve different purposes and should not be run through the same email thread. Write the criteria down while nothing is on fire.
Third, budget location for real-time risk tooling. DFIN's 2026 CFO Guide, released Aug. 7, 2026, found 76% of CFOs plan to increase cybersecurity investment and 68% are prioritizing automated risk tools for real-time visibility. Whether that spend sits in finance or IT determines who is accountable for data quality when a committee asks where a number came from.
Fraud and sanctions arrive as separate reporting streams
Two exposures increasingly get their own oversight lane. A fraud-risk roundup in The CFO on Sept. 22, 2026 argued that most CFO control sets were designed before AI-generated deepfakes and cloud ERP role creep, and it flagged a narrow 24-to-48-hour window to freeze funds after a fraudulent payment goes out. A control environment that depends on someone recognizing a voice on a call is no longer a control environment.
Sanctions is the second lane. Moody's global sanctions outlook of Feb. 11, 2026 points to more sophisticated evasion tactics and a shifting enforcement posture, echoing OFAC's advisory on sham evasion transactions. The UK's new end-user export controls took effect May 13, 2026, as Osborne Clarke has noted, adding screening obligations that touch order intake and revenue recognition, not just trade compliance. Boards increasingly want this reported separately, which means another cadence, another deck and another set of numbers that must tie back to the same source.
Build the aggregation function deliberately
The practical response is not to resist fragmented oversight, which reflects a real increase in risk complexity, but to stop absorbing it informally. Name a risk reporting owner inside finance. Maintain one register that feeds every committee pack. Version-control the packs so the chain of what was told to whom, and when, can be reconstructed without a forensic exercise.
CFOs who treat this as a reporting chore will spend 2027 explaining discrepancies. Those who treat it as a control, with an owner, a cadence and an audit trail, get something useful in return: a defensible account of what the company knew about its own risks and when it knew it.
Key takeaways
- EY research reported in September 2026 shows boards spreading risk oversight beyond audit and risk committees, multiplying the forums that need finance-sourced data.
- The SEC's January 2026 ADM order reached a segment-level CFO, and Cooley expects continued prioritization of charges against responsible individuals.
- Inconsistent numbers across committee decks create discovery exposure, not just governance untidiness.
- Decide now who owns the single risk register, what escalates to the disclosure committee versus a board committee, and whether risk tooling budget sits in finance or IT.
- Fraud and sanctions are becoming separate reporting streams, with a 24-to-48-hour window to freeze funds after a fraudulent payment.


