Decision

    What should boards know and ask about quantum risk?

    Boards do not need to understand the mathematics. They need to know which data and systems could be exposed as cryptography changes, who owns the response, what evidence supports progress, which suppliers the organization depends on, what it costs and when it should be revisited. The board oversees and decides; management plans and carries out the work. Good questions test evidence, not activity.

    New to this? Read Pillar 1: Governance and accountability first. After this, continue with What should a quantum-risk board report contain?.

    In one sentence: The board's job is to oversee, approve risk appetite and fund decisions; management's job is to execute and evidence them.

    Why it matters

    Moving off vulnerable cryptography takes years and touches many systems and suppliers. Without oversight, progress can be reported as plans and pilots while real exposure stays the same.

    QCI-QS1 requires the governing body to receive reporting at least quarterly, approve risk appetite and escalation authority, and review delivery capacity and funding decisions (QCI-4.1-02).

    Oversight versus execution

    These are QCI-QS1 requirements for organizations that adopt the standard. They are not legal duties of directors. Directors' legal duties depend on the organization's jurisdiction and sector.

    Who does what under QCI-QS1
    RoleResponsibility
    Governing body (board or committee)Receives reporting at least quarterly; approves risk appetite and escalation authority; reviews capacity and funding (QCI-4.1-02); records decisions with owner, rationale, due date and follow-up (QCI-8.2-01)
    Executive sponsorAccountable for quantum readiness; maintains a resourced roadmap (QCI-4.1-01, QCI-4.1-02)
    Quantum Risk OwnerAccountable for program execution (QCI-4.1-01)
    Engineering, system owners, procurement, legal, assuranceDocumented responsibilities for their parts of the work (QCI-4.1-01)

    Questions to ask

    • Exposure: Which of our data must stay confidential, or our signatures stay trustworthy, for many years? Which is exposed today?
    • Ownership: Who is the executive sponsor, and who owns day-to-day execution?
    • Evidence: What share of critical systems and data flows has a validated inventory record? What is unknown or out of date?
    • Suppliers: Which critical suppliers have current, adequate evidence, and which do not?
    • Spending: Is the roadmap funded and staffed, and which shortfalls are recorded as delivery risks?
    • Review triggers: What events will bring this back to us before the next quarterly report?

    Acknowledging is not accepting

    Noting a report is not the same as accepting a risk. Under QCI-QS1, acknowledgement is recorded as risk acceptance only when the authorized body explicitly approves the identified risk (QCI-8.2-01).

    What organizations should do

    1. Confirm an executive sponsor and a Quantum Risk Owner are named.
    2. Put quantum risk on the agenda at least quarterly.
    3. Approve risk appetite and who may escalate and accept risk.
    4. Ask for evidence counts, not activity counts.
    5. Record each decision with an owner and due date.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Role appointmentsSponsor, Quantum Risk Owner and functional rolesExecutive sponsorOn changeCheck names and documented responsibilitiesQCI requirement (QCI-4.1-01)
    Board minutes and decision logEach quarterly reviewCompany secretary or equivalentAt least quarterlyCheck owner, rationale, due date and follow-up per decisionQCI requirement (QCI-8.2-01)

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    QCI-QS1 sets roles, reporting cadence and decision recording for adopting organizations. It does not create legal obligations for directors.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-4.1-014.1explicit requirementP1—
    QCI-4.1-024.1explicit requirementP1—
    QCI-8.2-018.2explicit requirementP1—

    Common mistakes

    • Treating the program as an IT project that never reaches the board.
    • Measuring progress by the number of plans or vendor letters.
    • Recording that a report was noted as if the risk were accepted.

    Questions for the board

    • What would change our current priorities, and who tells us when it happens?
    • Where is our evidence weakest, and what will it take to fix?

    Questions

    Does QCI-QS1 make directors legally responsible for quantum risk?

    No. QCI-QS1 sets requirements for organizations that adopt it. Legal duties of directors come from the law and regulation that apply in each jurisdiction.

    How often should the board review quantum risk?

    At least quarterly under QCI-QS1, and sooner when urgent escalation thresholds are met (QCI-4.1-02, QCI-8.1-02).

    Does the board need technical training?

    Not in cryptography. It needs reporting that shows exposure, evidence and decisions in plain terms.

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.1. Supports: Roles and governing-body responsibilities.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 8. Supports: Governing-body reporting and decisions.

    Back to Governance and assurance · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What should boards know and ask about quantum risk?. https://quantumcoreinstitute.com/learn/governance/board-quantum-risk

    Link: https://quantumcoreinstitute.com/learn/governance/board-quantum-risk