Auditen
Home / Frameworks / NIS2 / Governance and management accountability
NIS2 · Art. 20

Governance and management accountability

Governance and management accountability requires that the organization's leadership—specifically its "management bodies"—take ultimate responsibility for cybersecurity. They must formally approve the risk-management measures implemented by the entity and ensure they receive specific training to manage those risks.

What it means

Under NIS2, cybersecurity is no longer treated as a purely technical issue delegated to IT; it is a legal requirement of corporate governance. The intent is to bridge the gap between operational security teams and executive decision-makers, ensuring that resources are allocated and strategic priorities are aligned with risk levels.

In practice, this means the board or senior management cannot claim ignorance of cybersecurity failures. They are required to oversee the implementation of the measures mandated by the directive and may be held personally liable in some jurisdictions for non-compliance.

How to meet it

Evidence an auditor asks for

  • Board meeting minutes showing documented discussions, challenges, and formal approval of security measures and budgets.
  • Training logs or certificates proving that all members of the management body have completed their required cybersecurity training.
  • A signed organizational chart or governance charter clearly outlining who is accountable for risk-management decisions.
  • Copies of executive-level reports (dashboards/KPIs) presented to leadership throughout the year.

Common pitfalls

  • "Rubber-stamping," where management signs documents without evidence of review or critical inquiry, which auditors may view as a failure of oversight.
  • Providing executives with overly technical training that is irrelevant to their governance role, failing to meet the requirement for "appropriate" training.
  • Assuming that having a CISO automatically satisfies management accountability; the responsibility remains with the board regardless of who manages the day-to-day operations.