What is not on the agenda is not reviewed, does not have an owner and does not receive mitigation budget.
Why it matters when the plan changes
Agenda time is the scarcest thing a board has, and it is allocated by category. Financial risk has a committee, a reporting cycle and a profession behind it, and UK governance codes formally assign audit, risk and internal control to the board as its frame. Organisational risk has none of the three: no committee, no cycle, no discipline of practice. It surfaces as an item under any other business or not at all, and it arrives as a problem rather than as a risk the board chose to examine.
The tension is between attention and interference. A board that starts examining organisational detail is accused of managing, and one that does not is surprised when the plan fails. A board supervises activities and depends on information reaching it to do so, so the line that works is asking about the arrangement rather than about individual performance: which decisions the plan depends on, who holds them, what evidence supports the answer.
In practice
A board reviews a thirty-item risk register covering currency, supply, cyber and regulation. The approved strategy depends on three cross-functional decisions that currently have no owner. Nothing on the agenda would surface that, and it reaches the board eighteen months later as a missed number.
Evidence
Governance codes assign audit, risk and internal control to the board, which is the frame organisational risk would sit in.
Financial Reporting Council, UK Corporate Governance Code (2024)A board supervises the activities of a business and depends on information reaching it to do so.
Board of directors, Wikipedia (2026)
What it cannot tell you
People risk on the board agenda describes whether a category receives standing attention, not whether the board's judgement is accurate once it does. A board can allocate time to organisational exposure and still receive a poor or unverified account of it. Agenda presence is a precondition for oversight, not a guarantee of its quality.
Questions
It usually appears as succession planning and remuneration, both real but distinct from whether the organisation can deliver the approved plan. A board, per Board of directors, Wikipedia (2026), supervises activities and depends on information reaching it; without a standing slot, that question surfaces only after something has failed.
Audit and risk is the natural home; the UK Corporate Governance Code (2024) already assigns audit, risk and internal control to the board, giving this committee the reporting rhythm the question needs. Placing it with remuneration or nomination narrows it to people decisions rather than organisational capacity, a different and smaller question.
A bounded judgement about whether the organisation can carry the current plan, with evidence on both sides, a stated confidence, named owners for the exposures and a review date. That is a governance artefact rather than an operational report, which is what makes it appropriate for a board.
On the risk cycle, and additionally whenever the plan materially changes what the organisation has to do. A change of ownership or operating model invalidates the previous view entirely, and waiting for the scheduled review means seeing the consequence rather than the risk.
Not if the questions stay at the level of the arrangement: which decisions the plan depends on, whether they have owners, what evidence supports the answer. Those are oversight questions with operational answers, which is different from the board examining operations.