What should boards know and ask about quantum risk?
Boards do not need to understand the mathematics. They need to know which data and systems could be exposed as cryptography changes, who owns the response, what evidence supports progress, which suppliers the organization depends on, what it costs and when it should be revisited. The board oversees and decides; management plans and carries out the work. Good questions test evidence, not activity.
New to this? Read Pillar 1: Governance and accountability first. After this, continue with What should a quantum-risk board report contain?.
In one sentence: The board's job is to oversee, approve risk appetite and fund decisions; management's job is to execute and evidence them.
Why it matters
Moving off vulnerable cryptography takes years and touches many systems and suppliers. Without oversight, progress can be reported as plans and pilots while real exposure stays the same.
QCI-QS1 requires the governing body to receive reporting at least quarterly, approve risk appetite and escalation authority, and review delivery capacity and funding decisions (QCI-4.1-02).
Oversight versus execution
These are QCI-QS1 requirements for organizations that adopt the standard. They are not legal duties of directors. Directors' legal duties depend on the organization's jurisdiction and sector.
| Role | Responsibility |
|---|---|
| Governing body (board or committee) | Receives reporting at least quarterly; approves risk appetite and escalation authority; reviews capacity and funding (QCI-4.1-02); records decisions with owner, rationale, due date and follow-up (QCI-8.2-01) |
| Executive sponsor | Accountable for quantum readiness; maintains a resourced roadmap (QCI-4.1-01, QCI-4.1-02) |
| Quantum Risk Owner | Accountable for program execution (QCI-4.1-01) |
| Engineering, system owners, procurement, legal, assurance | Documented responsibilities for their parts of the work (QCI-4.1-01) |
Questions to ask
- Exposure: Which of our data must stay confidential, or our signatures stay trustworthy, for many years? Which is exposed today?
- Ownership: Who is the executive sponsor, and who owns day-to-day execution?
- Evidence: What share of critical systems and data flows has a validated inventory record? What is unknown or out of date?
- Suppliers: Which critical suppliers have current, adequate evidence, and which do not?
- Spending: Is the roadmap funded and staffed, and which shortfalls are recorded as delivery risks?
- Review triggers: What events will bring this back to us before the next quarterly report?
Acknowledging is not accepting
Noting a report is not the same as accepting a risk. Under QCI-QS1, acknowledgement is recorded as risk acceptance only when the authorized body explicitly approves the identified risk (QCI-8.2-01).
What organizations should do
- Confirm an executive sponsor and a Quantum Risk Owner are named.
- Put quantum risk on the agenda at least quarterly.
- Approve risk appetite and who may escalate and accept risk.
- Ask for evidence counts, not activity counts.
- Record each decision with an owner and due date.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Role appointments | Sponsor, Quantum Risk Owner and functional roles | Executive sponsor | On change | Check names and documented responsibilities | QCI requirement (QCI-4.1-01) |
| Board minutes and decision log | Each quarterly review | Company secretary or equivalent | At least quarterly | Check owner, rationale, due date and follow-up per decision | QCI requirement (QCI-8.2-01) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
QCI-QS1 sets roles, reporting cadence and decision recording for adopting organizations. It does not create legal obligations for directors.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-4.1-01 | 4.1 | explicit requirement | P1 | — |
| QCI-4.1-02 | 4.1 | explicit requirement | P1 | — |
| QCI-8.2-01 | 8.2 | explicit requirement | P1 | — |
Common mistakes
- Treating the program as an IT project that never reaches the board.
- Measuring progress by the number of plans or vendor letters.
- Recording that a report was noted as if the risk were accepted.
Questions for the board
- What would change our current priorities, and who tells us when it happens?
- Where is our evidence weakest, and what will it take to fix?
Questions
Does QCI-QS1 make directors legally responsible for quantum risk?
No. QCI-QS1 sets requirements for organizations that adopt it. Legal duties of directors come from the law and regulation that apply in each jurisdiction.
How often should the board review quantum risk?
At least quarterly under QCI-QS1, and sooner when urgent escalation thresholds are met (QCI-4.1-02, QCI-8.1-02).
Does the board need technical training?
Not in cryptography. It needs reporting that shows exposure, evidence and decisions in plain terms.
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.1. Supports: Roles and governing-body responsibilities.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 8. Supports: Governing-body reporting and decisions.
Related learning
Before this
Back to Governance and assurance · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What should boards know and ask about quantum risk?. https://quantumcoreinstitute.com/learn/governance/board-quantum-risk
Link: https://quantumcoreinstitute.com/learn/governance/board-quantum-risk