Corporate governance is being stress-tested, not at the margins, but at the level of its underlying architecture.
The modern board model was shaped in the industrial era, when companies were hierarchical, risks were more contained, and change moved more slowly. Governance followed that structure: information flowed up through management, and oversight flowed down from the board.
That model still defines how most boards operate today. But the environment it was built for has changed.
What's emerging is a structural tension: a governance architecture designed for a vertical world operating in a horizontal risk environment.
Many of the most consequential risks today move horizontally: across functions, across geographies and, increasingly, across organizational boundaries.
Cyber incidents rarely remain a technical issue. They quickly become legal, operational and reputational events. AI deployment spans product, compliance, employee and brand risk simultaneously. Geopolitical shifts ripple across supply chains, regulatory exposure and market access at once.
These risks don't move neatly through reporting lines. They spread.
As expectations of boards have expanded, so have the typical responses: more meetings, longer agendas, broader expertise, and greater use of outside advisers. These are rational adaptations. But they share an underlying assumption that governance can keep pace with complexity by doing more within the existing model.
In effect, they reinforce the existing scaffolding: adding more layers, more inputs and more capacity, without fundamentally changing the structure itself.
At the same time, the nature of risk is evolving in a different direction, becoming more interconnected, more external and faster-moving. Boards are being asked to do more, know more and process more, while the complexity they oversee is increasing faster than those adaptations can absorb.
This creates a growing tension. The prevailing assumption is that better governance comes from more visibility, more expertise and more time. That assumption may be reaching its limits.
A deeper shift sits underneath this. Governance assumes the company is the unit of analysis. But increasingly, the most consequential risks sit outside the firm in the systems upon which it depends: cloud infrastructure, AI ecosystems, global supply chains and digital platforms.
This is not limited to technology companies. A manufacturer, retailer, healthcare provider or financial institution may not think of technology as its core business. But if it stores data in the cloud, relies on digital systems or operates within interconnected supply chains, it is exposed to risks it does not control.
Boards are no longer just overseeing what the company does. They are overseeing what the company depends on.
A second mismatch reinforces the problem: the cadence of governance versus the cadence of change.
Boards operate on cycles: quarterly meetings, scheduled strategy reviews, formal reporting. But many risks now evolve continuously. Cyber vulnerabilities emerge overnight. AI systems change through iteration. Geopolitical dynamics shift in weeks, not quarters.
Oversight remains periodic. Risk has become continuous.
As risks become more distributed, boards need better visibility. But governance has a boundary: boards oversee; they don't manage. Too little visibility, and oversight becomes symbolic. Too much, and boards risk stepping into management.
Compounding this is a structural issue. Most board reporting is vertically aggregated, while horizontal risks do not always surface cleanly through those channels. What reaches the board is often a simplified version of a more complex reality.
All of this lands on a practical constraint. Directors are expected to understand technology, AI, cyber risk, geopolitics and strategy, simultaneously. Experience still matters, but its half-life is shrinking. Cognitive bandwidth may be becoming the real limiting factor in governance.
Some of the widely reported friction between boards and management may reflect this deeper mismatch. Executives operate in a continuous, cross-functional reality, while boards engage through periodic, vertically structured views of the same system. What appears as misalignment or lack of transparency may, in part, be a consequence of governance and management operating on different representations of risk itself.
None of this suggests boards are failing. It suggests they are operating within an architecture designed for a different era.
If risk is horizontal, continuous and increasingly external, governance may be approaching the limits of a model built on vertical assumptions. Boards were built to oversee organizations. Today, they are being asked to oversee systems.
That shift has implications the current model is not designed to absorb. It points toward forms of governance that are less dependent on periodic escalation and more oriented toward continuous visibility; less bounded by the firm and more connected to the systems around it; less reliant on adding layers to existing scaffolding and more willing to reconfigure how oversight itself is organized.
This may not mean replacing the board. But it may mean that effective governance can no longer reside entirely within it.
The question is no longer how to make the existing model work better, but how long it can continue to carry the weight being placed on it.
The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not necessarily reflect the opinions and beliefs of Fortune*.*
This story was originally featured on Fortune.com