King IV
King IV ICT Governance
Technology now underpins every public service, payment and record — so a governing body that treats ICT as an operational afterthought is leaving its largest single risk ungoverned.
Why ICT Governance Matters
King IV Principle 12 requires the governing body to govern technology and information in a way that supports the entity's objectives, manages associated risk, and complies with relevant law including POPIA. In the public sector this also intersects with the Corporate Governance of ICT Policy Framework that applies to departments and municipalities. AuditPro Core measures the application of Principle 12 across the entity so the board can evidence that technology and information are governed at the leadership level, not delegated and forgotten.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
ICT governance maturity
Level 3
▲ 1 level
Board ICT reports
4 / 4
Open ICT risks
17
Critical cyber gaps
3
ICT governance maturity trend
ICT governance dimensions
| Dimension | Maturity | Open gaps |
|---|---|---|
| Cybersecurity | Level 3 | 3 |
| Data governance | Level 2 | 6 |
| IT investment | Level 3 | 4 |
| Continuity / DR | Level 2 | 4 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Board-level responsibility
Principle 12 places technology governance with the governing body, not solely the IT manager. The board must set direction and oversee ICT risk even where it lacks deep technical expertise.
Information as an asset and a liability
Information governance covers both leveraging data as an asset and protecting it under POPIA. A breach of personal information carries regulatory and reputational consequences the board owns.
ICT risk and resilience
Technology risk spans cyber threats, system availability and project failure. Governance means ensuring these are identified, owned and reported, not discovered only after an incident.
Alignment with the public-sector framework
Departments and municipalities apply the Corporate Governance of ICT Policy Framework. King IV Principle 12 and that framework reinforce each other and should be evidenced together.
How AuditPro Core Bridges the Gap
- Principle coverage: ICT governance activity is mapped against Principle 12 expectations so gaps in board-level oversight surface.
- Risk visibility: technology and information risks are tracked with ownership and reporting to the board.
- POPIA linkage: personal-information protection status connects to the information-governance view.
- Audit-ready evidence: the coverage record exports as proof that Principle 12 was applied across the entity.
Key Takeaways
- King IV Principle 12 makes the governing body, not just IT, responsible for technology governance.
- Information governance includes protecting personal data under POPIA, a board-owned risk.
- ICT risk and resilience must be identified and reported before incidents, not after.
- Principle 12 reinforces the public-sector Corporate Governance of ICT framework and should be evidenced with it.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
