Back to Explore
👑

King IV

King IV ICT Governance

Technology now underpins every public service, payment and record — so a governing body that treats ICT as an operational afterthought is leaving its largest single risk ungoverned.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why ICT Governance Matters

King IV Principle 12 requires the governing body to govern technology and information in a way that supports the entity's objectives, manages associated risk, and complies with relevant law including POPIA. In the public sector this also intersects with the Corporate Governance of ICT Policy Framework that applies to departments and municipalities. AuditPro Core measures the application of Principle 12 across the entity so the board can evidence that technology and information are governed at the leadership level, not delegated and forgotten.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

ICT governance maturity

Level 3

▲ 1 level

Board ICT reports

4 / 4

Open ICT risks

17

Critical cyber gaps

3

ICT governance maturity trend

ICT governance dimensions

DimensionMaturityOpen gaps
CybersecurityLevel 33
Data governanceLevel 26
IT investmentLevel 34
Continuity / DRLevel 24

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Board-level responsibility

Principle 12 places technology governance with the governing body, not solely the IT manager. The board must set direction and oversee ICT risk even where it lacks deep technical expertise.

Information as an asset and a liability

Information governance covers both leveraging data as an asset and protecting it under POPIA. A breach of personal information carries regulatory and reputational consequences the board owns.

ICT risk and resilience

Technology risk spans cyber threats, system availability and project failure. Governance means ensuring these are identified, owned and reported, not discovered only after an incident.

Alignment with the public-sector framework

Departments and municipalities apply the Corporate Governance of ICT Policy Framework. King IV Principle 12 and that framework reinforce each other and should be evidenced together.

How AuditPro Core Bridges the Gap

  • Principle coverage: ICT governance activity is mapped against Principle 12 expectations so gaps in board-level oversight surface.
  • Risk visibility: technology and information risks are tracked with ownership and reporting to the board.
  • POPIA linkage: personal-information protection status connects to the information-governance view.
  • Audit-ready evidence: the coverage record exports as proof that Principle 12 was applied across the entity.

Key Takeaways

  • King IV Principle 12 makes the governing body, not just IT, responsible for technology governance.
  • Information governance includes protecting personal data under POPIA, a board-owned risk.
  • ICT risk and resilience must be identified and reported before incidents, not after.
  • Principle 12 reinforces the public-sector Corporate Governance of ICT framework and should be evidenced with it.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.