Build it before you need it. Encourage dissent. Measure what matters. Communicate early. Live your values. Directors and governance experts share five board disciplines that help companies earn and protect stakeholder confidence in a skeptical, hyperconnected world.

TRUST IS ONE OF A COMPANY’S MOST valuable assets—and among its most fragile. A single safety failure, cybersecurity breach, ethics scandal or risk management lapse can cause investors, customers, employees and regulators to challenge not only management’s decision but also whether the board was asking the right questions before the crisis occurred.
Over the past decade, some of the world’s most respected companies learned that lesson the hard way. Boeing’s 737 MAX crisis unveiled ineffective oversight of safety and operational risk. Wells Fargo’s fake accounts scandal exposed the dangers of poorly vetted incentive structures and a corporate culture weak on values. And Silicon Valley Bank’s sudden collapse demonstrated how quickly confidence can evaporate when risk oversight falls short.
But not every problematic practice or risk management lapse plunges the company in question into a downward reputational spiral. Consider JPMorganChase’s share price resilience in the aftermath of the London Whale trading loss debacle or MGM Resorts’ success at rebuilding trust after a colossal cyber breach in 2023.
Why do some crises wreak reputational devastation while others are viewed as forgivable anomalies? The answer sometimes lies in the reservoir of trust accumulated before the event occurred, says Jonathan Foster, a director at Lear and Amcor, managing partner at Current Capital Partners and the author of On Board: The Modern Playbook for Corporate Governance. “Jamie Dimon and JPMorgan built up so much credibility by executing well, delivering consistent performance over a long period, basically doing what they said they were going to do, that they essentially got a mulligan,” he says. “They had developed enough trust to get through without getting terribly wounded.”
Credibility created by a strong track record won’t prevent a crisis, but it can influence how investors, employees, customers and regulators interpret one. Stakeholders are more likely to ask, “This is out of character—what happened?” instead of thinking, “This confirms what we’ve suspected all along.” In an environment where confidence can erode with extraordinary speed, a company’s reputation is a form of governance capital that boards would do well to bank in advance.
From interviews with board members and governance experts, we’ve distilled a handful of ground rules that boards can understand and follow to build credibility with investors, employees, customers and regulators before it’s tested—and protect it when it is.
While boards cannot prevent every crisis, and shouldn’t be expected to, they can influence how resilient their organizations are before adversity strikes through oversight practices that create a currency of confidence over time. “When a crisis comes, companies that have that reservoir of trust will have a little more time and a little more public patience, a willingness to sort of believe the message when it comes out,” says Brooks Holtom, professor of management at Georgetown University. “So it’s in an organization’s best interest to proactively develop that.”
The opposite is equally true. When warning signs accumulate, governance appears weak and employee morale or leadership credibility erodes, the same level of setback is far more likely to trigger a loss of confidence. Stakeholders don’t judge an incident in isolation; they interpret it through the lens of everything they’ve already come to believe about the company—and the resulting narrative can far outlive the crisis at hand.
The issues that arose at Boeing, Wells Fargo and Silicon Valley Bank did more than shake stakeholder confidence—they prompted fundamental questions about whether boards had adequately fulfilled their oversight responsibilities. In each case, the crisis ultimately came to be viewed as the culmination of governance weaknesses developed over time.
For today’s public company directors, that distinction is critical, says Myrna Soto, CEO of Apogee Executive Advisors and a director at Consumers Energy and TriNet, who sees crises as a litmus test of a board’s approach to maintaining institutional trust. “Your trust isn’t determined at the point of crisis,” she says. “The rigor of your governance is revealed.”
Often, that entails ensuring the board has objective evidence that critical risks are being managed effectively. In cybersecurity oversight, for example, such verification might come through independent assessments, third-party audits, external penetration testing or other objective evaluations that help directors determine whether the organization’s controls are as effective in practice as they appear on paper. “On the boards I’m part of, we do a lot of inspection, not in the form of tactical activities, but assurances from third parties,” Soto says. “When a board is presented management’s perspective on all the great things that they’re doing and their capabilities, opportunities or strengths, there’s always that issue of having a third party involved in assuring that. It’s not that we don’t believe management, we just believe that we need to have those assurances in place.”
Much discussion around stakeholder trust focuses on how boards respond to crises, but reputational risk should be a consideration in virtually every boardroom conversation. “We spend a lot of time considering: What are the things that this organization performs, and how could that potentially fail at a given point and tarnish our reputational risk?” Soto says. “When we do an M&A, part of our due diligence process is to understand: Are there any reputational risk or trust factors to our brand and to our function because of this acquisition? And if so, what can we do to remediate that or be part of the integration plan? These are real embedded conversations in decision-making processes, in risk management, evaluation and establishing the corporate culture.”
Institutional investors increasingly evaluate boards by the coherence and candor of the company’s narrative around oversight and long-term value creation. A trusted board provides management the latitude to communicate transparently about risk, capital priorities and strategic consistency through market cycles. By contrast, a board that is unclear, divided or hesitant to confront difficult tradeoffs leaves management with cautious, qualified messaging that weakens confidence. Board conduct, both what directors do and what they leave undone, is inseparable from the quality of shareholder communication.
Trust is a form of capital. Reputation, therefore, is not abstract. It is reflected in valuation, investor composition and market resilience. Companies perceived as credible tend to experience more constructive shareholder bases and greater investor patience when cycles turn against them. Those qualities come from a pattern of board-supported decisions that allow management and investor relations to communicate openly about strategy, risk appetite and performance.

With AI reshaping companies faster than the board meeting cycle, directors are turning to AI themselves to keep pace with their responsibilities.
AI is evolving faster than the cadence of most board meetings. That’s a governance challenge—not just for management but also for board members themselves. In my conversations with CEOs and boards, one question comes up repeatedly: How can directors use AI to become more effective governors?
It’s not about trivial uses, like improving a board pack. It’s about fulfilling the classic director’s remit: an informed, independent sense-check on the company’s policies, practices and performance. Directors should stick to enterprise-approved tools and keep confidential materials out of public AI systems. And the goal isn’t to build a parallel set of numbers or take an adversarial posture toward management. The goal is walking in with enough context to engage with management’s framing rather than simply absorb it.
Effective oversight of a company’s reputation demands a boardroom environment where directors are comfortable challenging assumptions, posing uncomfortable questions and voicing dissent. “When making a major decision, it is the board’s responsibility to ask how the decision serves the company’s stakeholders—all of them,” says Idie Kesner, a director at Duke Energy and professor of strategic man- agement at the Indiana University Kelley School of Business. “And this includes questions about the reputational impact of those decisions. For the boards I serve on, it’s common for someone—often more than just one person—to probe deeply into management’s recommendations. For example, “If we do x, what’s the likely impact on our company?” Pointed questions are asked about all types of risk, including the impact on the company’s reputation.”
The most effective boards, agrees Holtom, nurture an environment of “psychological safety.” “Essentially people can give dissenting opinions, can ask critical questions, and they’re not viewed as antagonistic,” he says. “That’s a norm that you want to develop.”
A board culture where candid conversations and rigorous debate are welcome helps directors spot and head off emerging risks. “When things spill out in the press, the reality is that there are a lot of warning signs that happen within an organization before any of that hits,” says Jayne Juvan, a director at Mace Security and partner at Tucker Ellis, who says governance practices can determine whether those warning signs make their way to the boardroom. “The board needs to have the right reporting channels, and people need to know that the board will do something if there’s an issue, not just stonewall or, in the worst-case scenario, retaliate. If an issue can rise up within the organization, the board will be able to deal with it before it spills out.”
For Juvan, that starts with board composition and culture. “It’s really a matter of do these directors have the same value structure, the same level of commitment to the board?” she says. “Are they working to build a culture that allows for debate and discussion, so that issues actually rise to the board level?”

Proactive, consistent outreach helps boards anticipate shareholder concerns, strengthen credibility and deliver effective compensation oversight.
For most companies, navigating say-on-pay has become a reassuring exercise. The strong levels of shareholder support companies logged in recent proxy seasons continued in 2026, despite CEO compensation climbing to record levels, suggesting that investors are broadly satisfied with the alignment between pay and performance.
That broad support, however, can break down quickly at the individual company level.
Different stakeholders have different ex- pectations from a company, which by definition means there’s no single metric that can track a company’s success at building confidence among its customers, employees, investors, regulators and the communities in which the company operates. However, companies can identify appropriate metrics that measure how well they are serving each group and then connect the dots between them, says Kesner.
“Too often people think that you can’t satisfy all constituents simultaneously since constituents want different things,” she says. Investor confidence is shaped by consistent financial performance and disciplined execution of strategy. Customers are likely to judge the company by the quality, reliability and safety of its products and services. Employees look for competitive pay, opportunities for growth and a workplace where they feel valued and respected. Communities may evaluate a company’s commitment through its local engagement and corporate citizenship.
Jason Schloetzer, an associate professor at McDonough School of Business at Georgetown University, suggests boards track confidence indicators for each constituency. “For employees, directors could monitor the volume, tone and resolution speed of internal whistleblower hotlines,” he says. “For investors and regulators, boards could track trends in proxy voting, as well as the frequency and nature of regulatory inquiries. For customers, tracking online sentiment trends and net promoter score volatility can flag reputational issues before they impact the bottom line.”
When employee engagement scores dip, turnover spikes or the company struggles to fill key spots, directors should dig more deeply, says Foster. “Why have our scores gone flat? What’s causing high turnover on our factory floor? Why did it take so long to find a CFO? Those are the kinds of questions you want to ask.”
For Kesner, the key is to look at the various measurements collectively to assess whether the organization is acting in a manner that is reliable, ethical, transparent, as well as for the benefit of all of its stakeholders. “If a company doesn’t see the connective tissue across these groups, then it can seem difficult or impossible to serve all these constituents simultaneously,” she says. “But if you connect the dots for your constituents, you can show how each metric supports the others. For example, producing quality, reliable, safe products and services, which customers value, is a necessary step to achieving strong financial performance, which is necessary to provide long-term value to investors. And, of course, measuring the support you offer local communities by being a good ‘citizen’ is important in building relationships with regulators who support that citizenry. An organization will likely have many metrics, and if handled properly, they will reinforce each other and offer a balanced approach to serving stakeholders.”

Your shareholders may be losing billions a year from the way you run your equity plans.
Boards and compensation committees typically consider equity plans as part of compensation strategy: how to recruit, retain and align interests with shareholders. Yet their design can create two recurring costs for shareholders: stock-based compensation expense and dilution. For some companies, the potential shareholder value associated with reducing those costs can reach billions, depending on the plan structure and the valuation multiple the market applies.
That makes equity-plan design a fiduciary issue for the board and, specifically, the compensation committee. It raises a fundamental question for the board: Is the company costing its shareholders billions every year with the way it runs its employee equity plans?
ALONG WITH VAST POTENTIAL gains in everything from productivity to innovation, the development, adoption and deployment of AI may also be the fastest way to lose stakeholder trust. Whether it’s employees inadvertently exposing confidential information to public AI platforms, chatbots providing inaccurate information or vulnerabilities emerging from third-party AI tools, companies are likely to be judged not only by how they adapt to AI, but also how responsibly they govern it.
“The soup du jour is AI,” says Myrna Soto, who referenced the Hugging Face security incidents as highlighting an uncomfortable governance reality: AI risks extend beyond the technology a company builds and uses to the code and tools in use at any third-party partner within its ecosystem. As adoption accelerates, it’s up to boards to develop a framework for governing AI with the same discipline applied to every other area of risk.
START WITH PURPOSE—NOT TECHNOLOGY.
For Soto, that begins with ensuring the company’s approach to AI aligns with strategy, manages risk and maintains stakeholder confidence. She suggests asking: What are the credible use cases that we’re going after? What is the true business intent? Are we developing or deploying AI for the sake of saying that we’re doing it? Do we have strong metrics around objectives and KPIs that we’re looking to accomplish?
Directors should seek to understand what decisions AI models will inform, the risks it will introduce, whether the organization is relying on proprietary or third-party models and how management guards against pitfalls like hallucinations and bias. Accountability is key. “When something goes wrong, the response can’t be, ‘Well, the technology was at fault,’” Soto says. “No, it’s our fault. What did we not know? What did we not see? What did we not detect?”
TREAT AI AS ENTERPRISE RISK.
Rather than as a siloed area of oversight, boards should make AI a standing agenda item across its existing committee framework and for the full board. “AI risk is not a separate thing,” Soto says. “It’s something that needs to be incorporated into our entire enterprise risk management framework because the downstream effects from any consequences may not necessarily be what we’re thinking.” Customer trust, privacy, regulatory scrutiny, workforce disruption, operational resilience, corporate reputation—AI has implications across the entire spectrum of corporate constituencies. Boards should approach AI as they do other major risks: through intentional governance, employee education and clear reporting structures, says Jayne Juvan, who sees employee use of AI as a point of vulnerability where boards can make a difference.
“There’s a lot going on at the moment that people haven’t quite grasped is a security risk.” – Adam Pilton, Heimdal Security
“It’s about having the board identify AI as a priority similar to cybersecurity and approaching that in a very intentional way,” she says. “Asking what training and education is being done, what the reporting structure is, being thoughtful about how we’re bringing workforce members on who are aligned with the company’s mission—it’s the same compliance framework you would have for other risks.”
Gaps in training can lead to employees unwittingly sharing confidential information with public models or connecting AI tools to a business application, says Heimdal Security’s Adam Pilton. “They’re simplifying processes—but they’re also creating a back door,” Pilton says of some AI integrations. “They’re just seeing that connection to simplify their work. There’s a lot going on at the moment that people haven’t quite grasped is a security risk.”
IDENTIFY YOUR AI METRICS.
AI governance should be supported by measurable evidence, says Soto. “I like to put it in the frame of the same type of audit practices that we do on financial statements,” she says. “We should have these type of practices for this as well.”
Boards should review metrics on data quality and prototype-to-deployment learning metrics, and extend those measurements to third-party providers, whose AI use organizations remain accountable for but often have less direct control over. Independent certifications that validate AI systems and governance processes should also be considered, says Soto. “There are companies coming to the forefront to help organizations certify AI agents and frameworks. I am asking for this from management on the boards that I serve, to bring these layers of assurances and then, ultimately, they will be shared, populated into the external atmosphere for that type of trust consumption.”
COMMUNICATE RESPONSIBLE AI PRACTICES.
As with cybersecurity practices, stakeholder confidence in AI practices may ultimately depend less on whether incidents occur than on whether companies have taken proactive measures to act responsibly, detect issues quickly and
respond and recover rapidly. “We have to be sharing how we are being responsible adopters or responsible developers or responsible deployers,” Soto says. “If we don’t tell people we’re doing this, no one will ever know.”
Ideally, establishing a reputation for engaging with and listening to stakeholders starts well before an incident demanding it occurs. Boards should proactively help stakeholders understand the practices and risk management processes across areas of governance, from cybersecurity to supply chain management, already in place to protect them.
Serving on the board of an energy company, Soto points to safety as an example. “Part of our trust model and our trust framework is centered around safety,” she says. Because employees work around high-voltage equipment and customers depend on reliable operations, safety is paramount. The board reinforces that message by reviewing and supporting communications that consistently highlight the company’s commitment to safety, whether executives are speaking with analysts, employees or community groups. “At every opportunity, they talk about their safety culture,” she says. “It’s a battle cry.”
When a crisis does hit, that messaging framework will be an asset, as will having a solid protocol in place for clear, authentic communication. “If you’re known as being a board that is engagement-oriented, then when something does hit, you’re given more of the benefit of the doubt,” says Juvan. “Nobody wants to feel like they’re being stonewalled or that their concerns aren’t being addressed… Where that crisis is concerned, you have to get out immediately on it, because if you’re not out there to the marketplace with a good communication strategy, someone else is building that or filling that void for you. And that’s where boards start to lose control of the narrative.”
Importantly, an effective response during a crisis is rarely improvised. It reflects governance decisions made months or even years earlier—investments in crisis planning, clearly defined communications protocols and a commitment to keeping stakeholders informed.
MGM Resorts’ response to its 2023 cyberattack is an example, says Adam Pilton, a cybersecurity advisor at Heimdal Security. “They were clearly prepared when they were hit. Their communication was fantastic.” As the incident unfolded, the company established dedicated call centers to assist affected customers and launched a website devoted to providing updates and information about the attack. In a cyberattack, “the best thing you can do is preparation and then communication during the incident,” says Pilton. “Showing everyone that you’re not trying to hide anything, being open and honest—as much as you can, considering it is an active cyberattack—that comes from preparation.”

The proxy environment is growing more complex and less predictable, making it all the more critical to engage shareholders on a consistent basis by meeting them where they are.
Corporate boards devote substantial attention to the views of their largest shareholders, and understandably so. Those investors have traditionally made up the most active and engaged segment of the corporate shareholder base, with established stewardship teams, formal voting policies and reliable processes for casting ballots. But companies face emerging governance questions that are becoming increasingly hard to ignore:
It’s equally important to recognize that today’s companies operate in an environment characterized by relentless scrutiny and skepticism and amid a disturbing degree of political divisiveness. “In general, there’s just more suspicion of leadership, whether it’s political leadership, corporate leadership or academic leadership,” says Foster. “It’s a particularly challenging time where views, whether politics or otherwise, are quite polarized. And there’s a big suspicion of wealth.”
At the same time, the flow of news has fundamentally changed. A social media post, employee video or customer complaint can spread globally within hours, influencing markets and shaping public opinion as much as, if not more so, than the headlines traditionally selected by a handful of mainstream media outlets. “Everybody can be a citizen journalist today,” says Juvan. “Anyone can put up a post that goes viral. That creates a different risk profile for boards because it’s no longer a matter of having good relationships with certain journalists. Now it’s a matter of how you present yourself in the marketplace as a whole so that you’re less likely to fall victim to one of those incidents.”
Even a seemingly innocuous decision can go sideways in a fraught political climate, unintentionally thrusting a company into the limelight. Witness the difficult position Olive Garden recently found itself in when the chain’s requirement that customers present photo identification to redeem its promotional “Never-Ending Pasta Pass” was unexpectedly invoked by lawmakers during the national debate over voter identification laws.
A vigilant board can help management avoid landing in the crosshairs, says Eric Yaverbaum, CEO of Ericho Communications, who notes that Darden—Olive Garden’s parent company—almost certainly wasn’t thinking about voter ID laws when it brought back the promotion. “Boards should treat political and cultural exposure the same way they treat financial or opera- tional risk, as something to be monitored for regularly, not reacted to after the fact,” he says. “That means building a standing practice of scenario-mapping any promotion, partnership or public-facing decision against the current political landscape and asking how the court of public opinion could potentially react to the situation and why.”
Boards might, for example, ask management: What stories are likely to be dominating the news at campaign launch? Who is likely to make a connection between this promotion and a live political issue, even one we’re not thinking about? Is there any language, timing or requirement in this campaign that echoes a current news cycle?
“In this case, a routine photo ID requirement for pasta pass holders happened to launch the same week President Trump was pushing a stalled voter ID bill, and the public wasted no time linking the two,” says Yaverbaum, who adds that boards should ensure that companies have a playbook for responding when thrust into the spotlight. “If a promotion went viral for the wrong reason, what would a response look like, and do we already have one? Directors don’t need to predict the exact controversy. They need to be asking whether the company has proactively pressure-tested any potential promotion against the world as it exists right now.”
Stakeholder trust can’t be generated through marketing campaigns or carefully crafted mission statements. It gets forged when stakeholders see a consistent connection between a company’s stated values and its day-to-day decisions.
Credibility is an outgrowth of alignment between a company’s stated values and its operational reality. “Firms often have lofty corporate values, but when management engages key stakeholders, those values are nowhere to be found,” says Schloetzer. “Instead, the discussion is about cost control, reorganization or digital transformation.”
Executive incentives, capital allocation decisions, risk management systems and corporate communications should be designed to communicate and reflect corporate values. Oversight also requires demanding accountability “for losing the gap between what you say and what you do,” says Holtom. If a company claims to be an employer of choice, for example, boards should expect to see evidence through workforce metrics, employee feedback, retention trends and investments in development. If sustainability, customer service or innovation are presented as core values, directors should ensure management can demonstrate how those priorities are reflected in decision-making, incentives and performance measures.
Sometimes that alignment requires difficult tradeoffs. CVS Health’s 2014 decision to stop selling tobacco products offers a powerful example. By voluntarily walking away from roughly $2 billion in annual tobacco sales, the company eliminated what many viewed as a contradiction between its stated mission of improving health and a product that undermined that purpose. The company took a financial hit but strengthened its credibility with customers, healthcare providers and investors and laid the groundwork for a strategic transformation that positioned CVS as a broader healthcare company rather than simply a retail pharmacy.
The decision underscores that, ultimately, stakeholder trust is the cumulative result of thousands of decisions made in the boardroom and throughout the organization. “Trust is high when stakeholders have confidence that the organization will act in a manner that is reliable, ethical, transparent and for their benefit,” says Kesner. “In terms of practices that foster trust, that definition says it all. Maintain strong ethical practices. Demand employees at all levels demonstrate the highest integrity, and address situations quickly and decisively when this is not the case. Be available, visible and transparent with all constituents—investors, employees, customers, regulators and the community. Fulfill promises.”