The chief information officer role explained through the three questions every board eventually asks: are we investing in the right technology, is it safe, and what happens when it stops. What the seat answers for, how it differs from the CTO and the chief digital officer, and where it goes wrong.
In short
- A chief information officer is the executive who answers, at the top table, for the institution’s technology estate as a whole: what it costs, what it can do, what it risks, and what happens on the day it stops.
- The seat is defined by three board questions rather than by a department: are we investing in the right technology, is it safe, and what happens when it stops. Everything the CIO does is an answer to one of them.
- The CTO and the chief digital officer own parts of the estate; the CIO owns the whole of it as a board matter — investment, risk and capability rather than systems.
- Cyber accountability sits with the CIO at executive level and cannot be delegated to the CISO; the CISO runs the defence, the CIO answers for the exposure.
- The seat fails in one of three ways: the estate is reported as systems rather than as investment and risk, the legacy question is deferred politely rather than costed honestly, or the board is shown a demo instead of told the truth.
On this page
What a chief information officer is#
A chief information officer is the executive who answers, at the top table, for the institution’s technology estate as a whole: what it costs, what it can do, what it risks, and what happens on the day it stops. The definition matters because it is a definition of accountability, not of expertise. The CIO does not need to be the institution’s best engineer. The CIO needs to be the person the board can hold to account for the estate, and who has made that accountability real by owning the decisions behind it.
Technology stopped being a department the day the institution could not open without it. That is the moment the seat changed. Before it, the head of technology ran a function that served the business. After it, the chief information officer runs the institution’s nervous system, and the board knows it — which is why the board asks the seat questions it asks no other.
The three questions boards fear#
Strip away the vocabulary and every board conversation about technology reduces to three questions. Are we investing in the right technology? Is it safe? And what happens when it stops? Boards fear these questions because they cannot answer them alone, because the answers are expensive whichever way they fall, and because the person who can answer them has historically spoken a language the board does not.
The CIO’s mandate is the set of answers to those three questions, held and refreshed continuously. Everything else the seat does — the portfolio, the sourcing, the data, the cyber posture, the resilience plan — is an input to one of them.
The anatomy of the mandate#
The mandate has three parts, each answering one of the board’s questions.
- The estate as strategy. A portfolio view of what the institution spends to run, to grow and to transform, and what the mix says about the institution; build, buy or rent decisions — including where the estate is concentrated in a few providers — read as balance-sheet commitments rather than procurement events; and the legacy question, costed honestly and sequenced deliberately rather than deferred politely.
- AI and data, governed. Adoption with owners, controls and audit trails, so that what is deployed is a capability rather than theatre; data treated as an asset with a profit and loss of its own — quality, access, accountability; and a habit of volunteering to the board what it should be asking before it asks.
- Risk, resilience and the board. Cyber accountability carried at executive level, with the division of labour between the CIO, the CISO and the board made explicit; technology resilience — concentration, vendors, and the day the institution stops; and the craft of briefing a board at its altitude, with honesty, and never with a demo.
CIO, CTO and chief digital officer#
The titles overlap and institutions use them differently, but the distinction that matters is one of scope. A chief technology officer typically owns the engineering and the platforms; a chief digital officer typically owns the products and channels through which customers meet the institution. Both own parts of the estate. The chief information officer, whatever the institution calls the seat, is the one who owns the whole of it as a board matter — investment, risk and capability rather than systems — and who can therefore answer the three questions in full.
Where a CTO and a chief digital officer both sit at the top table, the CIO seat is the one the board turns to when the questions are asked together. If no one holds that seat in substance, the board will find that it has three partial answers and no whole one.
Where the seat goes wrong#
The seat fails in one of three ways, and each is a failure of altitude rather than of technology. The first is reporting the estate as systems: a list of platforms, projects and uptime figures that the board cannot convert into investment, risk or capability. The second is the legacy question deferred politely — the estate the institution cannot afford to keep and cannot afford to replace, left out of the plan year after year because costing it honestly means asking for money. The third is the demo: the board shown something that works instead of told what does not.
Behind all three sits the same avoidance. Cyber accountability is the clearest case: an executive who hides behind the chief information security officer has not delegated the risk, only the conversation. The CISO runs the defence. The CIO answers for the exposure, and the board will hold the CIO to it on the day it matters.
The CISO runs the defence. The CIO answers for the exposure, and the board will hold the CIO to it on the day it matters.
What good looks like#
A CIO who holds the seat well can answer the three questions without notice and in the board’s own terms. The investment question is answered as a portfolio: this much to run, this much to grow, this much to transform, and here is what that mix says about us. The safety question is answered as accountability: here is what I answer for, here is what the CISO answers for, here is what the board is being asked to accept. The continuity question is answered as resilience: here is where we are concentrated, here is what happens on the day we stop, and here is what we have rehearsed.
Such a CIO also volunteers. The question the board should have asked and did not is raised by the CIO first, because a board that learns of a risk from its CIO trusts the seat, and a board that learns of it from elsewhere does not.
What to do next#
Write the three answers as they stand today, in one page each, in the board’s language and without a single system name. Where an answer will not fit on the page, or cannot be written without a demo, the seat has found its next piece of work. This is the ground The CIO Mandate works with technology leaders who answer for outcomes, in a cross-industry cohort of peers who carry the same three questions.
Frequently asked
What is the role of a chief information officer?
The chief information officer is the executive who answers for the institution’s technology estate as a whole: what it costs, what it can do, what it risks, and what happens on the day it stops. In practice the role is the set of answers to three board questions — are we investing in the right technology, is it safe, and what happens when it stops — held and refreshed continuously.
What is the difference between a CIO and a CTO?
Scope. A chief technology officer typically owns the engineering and the platforms, and a chief digital officer the customer-facing products and channels; both own parts of the estate. The chief information officer owns the whole of it as a board matter — investment, risk and capability rather than systems — and is the seat the board turns to when its questions are asked together.
Who is accountable for cyber risk — the CIO or the CISO?
Both, at different levels. The chief information security officer runs the defence and answers for its quality. The chief information officer carries cyber accountability at executive level and answers to the board for the institution’s exposure. An executive who hides behind the CISO has delegated the conversation, not the risk.
Does a CIO need a technical background?
A working command of the estate, yes; being the institution’s best engineer, no. The seat is defined by accountability rather than expertise: the CIO is the person the board can hold to account for the estate, and who has made that accountability real by owning the decisions behind it — the portfolio, the sourcing, the legacy question, the cyber posture and the resilience plan.
The programme behind this article
Work through this material with the practitioners who wrote it.
The CIO Mandate: Technology as Institutional Strategy
For CIOs, CTOs and chief digital officers — the technology estate as a board matter: investment, AI, cyber accountability and the legacy question.
View the programme →The COO: Operations at Scale
The widest seat in the house — running today’s operations while building tomorrow’s, for COOs and operations executives with an enterprise remit.
View the programme →Leading Through Crisis: The Executive Command Masterclass
Decision-making, communication and command when the institution is on fire — simulation-led, for executive teams and their deputies.
View the programme →