St Georges Strategy

Committee Questions

Edition / 23 Aug 2026 Edition date 23 Aug 2026

Questions worth taking into the room

Board-ready questions for turning public signals into challenge, evidence requests, and accountable follow-up.

Three current questions, refreshed with each edition, followed by an evergreen library for the decisions that endure.

This week’s questions

Three questions to take into the room

Each week starts with a small set of live, copy-ready challenges. Use one, ask for the evidence, then assign the follow-up.

Question 02 / Shared infrastructure

If a cloud region or network path degrades, which important services fail together and can the firm show the recovery route actually works?

Why it matters now
This week’s provider incident evidence shows that a disruption can originate below the application layer. A service map that stops at the named provider misses capacity, routing, identity and operational dependencies that shape customer impact.
Ask for
The service-and-dependency map, regional and network assumptions, impact tolerance, recovery design, last exercised test, customer communication plan and accountable owner.

Question 03 / Market disclosure

When a material assumption changes, who re-tests the statement, decides whether escalation is needed and records why the disclosure remains accurate?

Why it matters now
The Rex decision is a useful reminder that forward-looking statements depend on current, supportable information. Data quality, management challenge and the escalation route need to work before a market announcement becomes difficult to defend.
Ask for
The forecast or disclosure, underlying management information, challenge record, escalation threshold, legal and finance sign-off, subsequent changes and retained decision log.

Use in the next meeting

Ask less. Follow through.

The aim is not a larger committee pack. It is one clear challenge that produces a named action and evidence for the next meeting.

  1. 01Choose one live question

    Take the question that most directly affects an important service, decision or customer outcome.

  2. 02Ask for the evidence

    Request the actual map, record, test result or decision trail—not an assurance summary.

  3. 03Record the follow-through

    Name the owner, due date and evidence expected back. Bring the closure record to the next meeting.

Evergreen library

Choose the decision domain, then ask for evidence

These questions are built to last beyond the weekly news cycle. Pick the one or two that are live for your firm, assign an owner and use the evidence request as the follow-up.

Strategy and investment

Where AI, infrastructure, and market exposure change the business case

Use these where the decision is about scaling, funding, dependency, or strategic exposure.

Copy-ready question

Which AI-enabled workflows are moving from productivity case to business-critical dependency, and what investment is needed to control them?

Why it matters
Frontier-AI ICT risk is now part of the supervisory conversation, including governance, cyber prevention, response and critical-provider oversight.
Strong answer contains
A prioritised AI workflow inventory, business-criticality rating, owner, funding need, and control maturity view.
Evidence to request
AI inventory, dependency map, investment backlog, control gaps, and exit or fallback options.

Copy-ready question

Where could AI infrastructure, model-provider concentration, or vendor lock-in create downside exposure that is not yet in our financial scenarios?

Why it matters
AI capability is becoming an important service and critical-provider dependency, so concentration and substitution need to appear in business and resilience scenarios.
Strong answer contains
Exposure sizing, stressed assumptions, substitution options, vendor concentration limits, and monitoring triggers.
Evidence to request
Supplier spend, contract terms, concentration dashboard, scenario assumptions, and exit practicality assessment.

Governance and accountability

Who owns the decision when automation acts

Use these where the live issue is authority, sign-off, accountability, and escalation.

Copy-ready question

Which AI agents or copilots can touch production data, code, email, or tickets today, and are their permissions technically enforced?

Why it matters
Prompt rules are not control evidence when AI tools have access to real systems and privileged workflows.
Strong answer contains
Access list, technical enforcement, least-privilege review, logging, exception process, and emergency-stop proof.
Evidence to request
Access-control export, privileged-action logs, exception approvals, and live stop-path demonstration.

Operational readiness

Whether the firm can operate when the signal becomes real

Use these where the question is whether a process, journey, or service can actually perform under stress.

Copy-ready question

Which critical payment journeys would fail if a processor, tokenisation provider, or telecom route degraded for two hours tonight?

Why it matters
IT resilience evidence increasingly has to account for cyber, geopolitical and third-party dependence across important services and customer journeys.
Strong answer contains
Journey map, dependency map, impact tolerance, fallback route, customer communications, and last test result.
Evidence to request
Processor, tokenisation, telecom, power, and manual-fallback test evidence by customer journey.

Copy-ready question

Do we know which network providers and CDN paths sit behind each top digital service, by user region?

Why it matters
Status pages can stay green while customers experience failure at the edge, especially when internet-routing dependencies degrade.
Strong answer contains
Customer-edge telemetry, route map, region view, alert thresholds, and service-owner response plan.
Evidence to request
External monitoring, CDN/provider map, incident playbook, and customer-impact dashboard.

Control and assurance

Whether the answer is evidenced, not merely asserted

Use these where the firm is relying on policy, attestations, management information, or inherited assurance.

Copy-ready question

Where are we relying on policy, attestation, or status pages instead of telemetry, technical controls, and evidence of recovery under stress?

Why it matters
Regulators are testing whether firms can prove control operation under stress, not just describe the control framework.
Strong answer contains
Operational telemetry, technical enforcement, independent test results, exception tracking, and owner sign-off.
Evidence to request
Control test pack, real-time telemetry, incident evidence, and open-risk remediation plan.

Copy-ready question

Which critical decisions this week relied on data whose source, transformation, quality controls, and accountable sign-off can be reconstructed?

Why it matters
AI adoption, supervisory analytics, cyber evidence, privacy duties, and regulatory reporting all depend on reconstructable data lineage.
Strong answer contains
Source, transformation, quality checks, exception owner, retention, approval, and use-case linkage.
Evidence to request
Lineage map, quality-control report, exception log, sign-off trail, and sample reconstruction.

Copy-ready question

Where could rising scam typologies, known control gaps, or complaint ageing be characterised as systemic inaction?

Why it matters
Fraud, conduct, complaints, restrictions, and restoration speed are converging into one supervisory narrative.
Strong answer contains
Typology movement, control performance, complaint ageing, remediation times, vulnerable-customer impact, and owner actions.
Evidence to request
Fraud dashboard, complaint ageing, control-gap register, reimbursement trend, and remediation evidence.

Resilience and response

Whether the firm can recover, communicate, and learn

Use these where the live issue is fallback, incident response, or the boundary between firm and supplier.

Copy-ready question

Which top customer journeys depend on third parties whose failure would look to customers like our failure, and when did we last test the fallback?

Why it matters
Provider and infrastructure failures can become the firm’s customer and supervisory problem, even where the source of failure sits outside the firm.
Strong answer contains
Important business service mapping, supplier dependency, fallback option, last test, communications route, and tolerance result.
Evidence to request
Fallback test evidence, supplier SLA performance, incident communications pack, and customer-impact assessment.

Copy-ready question

Which weak signals already have owners, dates, and executive visibility?

Why it matters
Weak signals matter only when they have an owner, action date, escalation threshold and a route into executive visibility.
Strong answer contains
Signal owner, action date, escalation threshold, management-information view, and closure evidence.
Evidence to request
Open-signals register, accountable owner list, due dates, risk acceptance, and committee reporting extract.

Have a question a committee actually asked that belongs here? Send it across — ben@stgeorgesstrategy.com — and it may be added to the next edition of this page.