TWINLADDER
TwinLadder logoTwinLadder
Back to Newsletter

Issue #50

The Board That Could Not Reconstruct What It Had Approved

In August a Latvian state agency lost the personal data of 1.2 million people and around 200,000 legal entities, drawn from eighteen years of payment records, under a five-year IT contract worth about EUR 9 million that ran through a chain of subcontractors. The supervisory board resigned on 19 August and the entire management board was gone by 20 August, because nobody at the top could say what the contract covered and what it left open. The same week computer use went generally available, seven in ten European large caps claimed board oversight of AI, and five per cent of S&P 500 directors were credited with AI experience.

board oversight
third-party risk
delegation and scope
agentic AI governance
judgment capital
August 22, 202613 min read
The Board That Could Not Reconstruct What It Had Approved

Listen to this article

0:000:00

TwinLadder Weekly

Issue #50 — The Board That Could Not Reconstruct What It Had Approved

22 August 2026 · Weekly intelligence on judgment, governance, and the boards accountable for both


Editor's Note

From Alex —

Seventeen issues ago I said this newsletter tracks one question: where judgment forms inside an organisation, and where it drains away. This issue closes the catch-up run. It closes it on a case that puts the question at the only table entitled to act on it.

This month a Latvian state agency lost the personal data of 1.2 million people and around 200,000 legal entities, drawn from eighteen years of payment records. The work that was meant to protect it ran under a five-year contract worth about €9 million, through a chain of subcontractors. When the loss arrived, the top of the institution could not say what that contract covered. The counterparty could, and said so in public within days.

The supervisory board resigned on 19 August. The entire management board was gone by 20 August.

I have sat on boards, and I have approved contracts of exactly this shape. Infrastructure, monitoring, a supplier with a good name, a paper that arrived at the table with a recommendation on it and a summary of scope on page two. I approved them. I could not today rebuild the seams of most of them from memory. That is why this case belongs in a newsletter about judgment.

Latvia had already transposed the European network-and-information-security directive. The management body was legally required to approve the cyber risk-management measures, to oversee them, and to answer for them. The duty was in force. The duty still failed to produce a board that could say what €9 million had bought and what was left uncovered.

Liga has the analysis. The short version: a duty to approve becomes a capacity to approve only where someone maintains the capacity. Call the difference the approval gap.

— Alex


Eleven Days

Start with the sequence.

CSDD — Latvia's Road Traffic Safety Directorate, a state joint-stock company holding the national vehicle and driver register — runs its IT infrastructure under a five-year contract with SIA Tet, signed in February 2022. The initial value was €8.989 million excluding VAT, raised in spring 2025 to €9.043 million. According to Latvia's Electronic Procurement System, Tet's subcontractors on that contract are SIA Kyndryl Latvia and SIA Corporate Systems. Three layers, one register, one contract.

On the night of 7–8 August an attacker got in. What left the building was personal data on 1.2 million people and approximately 200,000 legal entities: names, personal identification codes, addresses, vehicle registration numbers, payment amounts and payment dates, pulled from eighteen years of payment records. Consider a single line in that file. A driver who paid a registration fee at a CSDD counter in 2008 had, until this month, no reason to think that transaction was still sitting anywhere. It was.

CSDD notified CERT.LV, the national computer emergency response team, on 10 August — the third day. The public was told on 13 August. On 19 August the supervisory board resigned. Transport Minister Rihards Kozlovskis then asked the entire management board to go and ordered an accelerated service inspection, one that must, among other things, assess the Tet contract. By 20 August the management board was gone.

CERT.LV's deputy head, Varis Teivāns, explained why the state itself had seen nothing coming. CSDD had declined CERT.LV's services, so the national responder had no visibility of the infrastructure at all. His phrasing was flat: "Tas tika pamatots ar CSDD spējām, tādēļ tāda agrīna pamanīšana no valsts viedokļa nebija iespējama" — that was justified by CSDD's own capabilities, and so early detection from the state's point of view was not possible. The institution declined the outside eye on the grounds that it had its own.

The investigation has already established that several Cabinet-mandated requirements went unmet. Under Latvia's rules, systems graded Class A require penetration testing and multi-factor authentication. Those requirements were in force. They were not satisfied.

Then, on 21 August, the supplier published its side. Tet's position, reported by LSM and TVNET — whose article bodies we could not retrieve at first hand this week, so treat this as a single-source account — was that it manages CSDD's network resources, connections and infrastructure, and that cybersecurity for the applications CSDD built and runs itself sits outside its remit. One sentence from that statement: "'Tet' esošajā līgumā netika nodota pieeja CSDD 'med.csdd.lv' lietotnes žurnālfailiem" — the existing contract never transferred access to the med.csdd.lv application logs.

We have not read the contract. Nobody outside the parties has. The service inspection reports in early September; the Data State Inspectorate and the Prosecutor General's Office have proceedings open. Every conclusion below is drawn from the structure of what was contracted and disclosed, and from the order in which it became public.


The Approval Gap

Here is what can be said with confidence from the public record, without waiting for the inspection.

The top of the institution did not hold an accurate map of what it had bought. That is established by the sequence alone: the buyer made a public claim about how the contract allocated responsibility, and the seller corrected it in public, with the document in hand, within days.

The gap was structural. The contract covered the infrastructure layer. The breach happened at the application layer, in a system the institution built and operated itself. A board holding that split would have known that €9 million of infrastructure monitoring left the application layer uncovered, and would have asked the one question that follows: then who covers it?

A silence is a contract term

Take the log-access point at its stated value, as a single-source account, and it still teaches the general lesson. Access to those application logs was never transferred. Someone would have to search hard for a meeting at which anyone weighed the proposition we will withhold from our monitoring supplier the logs of an internet-facing portal, and therefore nobody will watch it. It simply sat outside scope.

Scope silence is the most dangerous class of contract term. A clause you disagree with gets argued, minuted and escalated. A clause that was never written generates no owner, no report, no alarm and no line on any register. It produces the quietest possible file. Every quarter it stays quiet is read as evidence that things are fine.

Delegation here ran three deep: agency to supplier to subcontractors. Each layer understood its own scope precisely. The failure sat between the layers, and the only party positioned to see between them was the party that had stopped being able to read the whole.

Why the buyer's copy decays and the seller's does not

There is a mechanism underneath this, and it is nobody's misconduct.

A supplier's understanding of a contract is operational. It is the document by which their people are tasked, their scope defended and their margin set. It is read continuously, by people paid to read it.

A buyer's understanding of the same contract is episodic. It is read hard at signature, by people who then move on to the next thing. Over five years the supplier's map stays accurate through daily use. The buyer's map decays through disuse. Both parties end up with the map their working life gave them.

That asymmetry predicts precisely what happened in Riga: a confident public claim by the buyer about its own contract, corrected by the seller within days. It is a draw-down of judgment capital with an entirely conventional cause. Nobody decided to stop understanding the contract. The understanding was simply never anyone's job to maintain.

There is a corollary the case makes vivid. The natural moment to rediscover a seam is re-procurement, when someone is forced to read the document line by line and write the next one. This contract was in its final year. The seam surfaced in a breach instead, months before the re-tender that would have made someone read it.

Where the defect sits

If the supplier did what it was contracted to do, and the outcome was the largest personal-data loss in the country's history, then the defect sits in what was asked for. A specification is a governance artefact. Someone approved a scope, and the scope had a hole in it that nobody was assigned to see.

This has a close cousin in the record. The Dutch childcare-benefits affair is remembered as an algorithm scandal, and the official reconstruction says something more precise. A risk model scored applications; high scores went to a civil servant who could brand a family fraudulent. That civil servant was given no information about why the system had scored the case high. The oversight the law imagined could not happen, because the person had been handed a verdict without its grounds and asked to ratify it. Tens of thousands of families were wronged. The trigger, in file after file, was a signature in the wrong place.

Change the object and the shape repeats at the board table. A board handed a contract summary without its seams is a board handed a verdict without its grounds. It can approve. It cannot check. The approval enters the minutes either way, and the minute looks the same in both cases.

The duty was already there

This case does something awkward to the usual reform story. That story runs: a loss happens, a regulator publishes a discussion paper, consultations follow, rules arrive, and eventually a board has to sign something. British operational resilience took that route after a retail bank moved 5.2 million customer records over a single weekend in 2018 and did not restore normal service until December. Seven years from the failure to the final compliance date. The moral is usually that a board can adopt the endpoint voluntarily and years cheaper, ahead of the rung.

Latvia is the counter-shaped case. The rung had already arrived. NIS2 was transposed; the management body was already required to approve the cyber risk-management measures, to oversee implementation, and to be answerable for it. The Commission spent this summer pushing four more member states toward the same obligation through the Court of Justice, having found that few met the original October 2024 deadline.

And the duty still failed to produce a board that could answer what did we buy, and what is left uncovered?

The regulatory arc delivers the duty. It does not deliver the capacity. Signing off a measure you cannot interrogate is the compliance artefact of a judgment you no longer hold.

The resilience regime that came out of the 2018 failure understood the difference. It required the board to approve and regularly review the written self-assessment. Approve, not receive. And then it went one step further and scheduled the board's own capability maintenance: members of the management body keeping their knowledge current, by training, on a clock. A financial regulator, writing rules about machine resilience, conceded that an obligation to oversee decays unless the capacity to oversee is itself maintained.


The Same Week, the Agents Got Hands

Now put the calendar side by side. The second half of this week belongs to a different subject that turns out to be the same one.

On 19 August, computer use came out of beta on the Claude API, and a browser-use tool shipped alongside it. In plain terms: an agent can now operate any system a human can reach through a screen — click, type, fill a form, manage tabs, move a file. The control that governs that capability is the access review: what the agent is permitted to reach, and what it may do once it is there. A model card answers a different question. This one gets answered inside contracts and entitlements, in exactly the register the Riga case was decided in.

Wellington Management reported the same week that nearly three in four companies plan to deploy agentic AI within two years, while about one in five has a mature governance model for autonomous agents. Wellington's framing of the shift: "The risk with agentic AI moves beyond producing a 'wrong answer' to taking a 'wrong action.'" Those figures come from a 2025 survey published without a sample size, so hold them as a direction of travel.

Set that against what boards say about themselves. Glass Lewis, reviewing the 2026 proxy season, found defined board oversight of AI at around seven in ten large-cap companies in Continental Europe and the UK, a sharp year-on-year rise. More than half of Continental European large caps now have an AI policy, up from about one in five in 2025. On paper, European boards have arrived.

Then look at who is in the room. Only 10% of STOXX Europe 600 boards run a formal innovation-and-technology committee, with a further 24% covering the topic through another committee or at full board. Digital experience sits on 64% of those boards. It reaches 16.8% of their members.

Seven in ten boards claim defined oversight of AI. Digital experience reaches one director in six. That distance is the approval gap expressed as a survey statistic, and CSDD is the same distance expressed as an incident.

Frank Elderson of the ECB put the point in one line in Zurich in June: the challenges posed by new generations of AI models "should not be viewed solely as a cybersecurity issue – they are a firm-wide strategic challenge." The warning is about where the question gets filed. Europe's three financial supervisory authorities followed on 31 July, telling firms they "should have robust governance and risk management frameworks in place" for the cyber risks of frontier models. A board that files agentic deployment with the CISO has repeated the move CSDD made when it declined the outside eye on the grounds that it had its own capabilities.


What This Means for Boards Right Now

One. Ask what you handed over, and what nobody took. For your most important outsourced service: which layers sit in the supplier's scope, which sit in yours, and who has read the seam between them in the last twelve months? A good answer is a layer map with a named owner against every line, and a date. A weak answer gives you the contract value and the uptime figure — an answer about the supplier's health, to a question about your own coverage.

Two. Treat the buyer's copy of a long contract as a maintained asset. The supplier re-reads it every week because their margin depends on it. Nobody on your side has that incentive, so somebody has to be given the job explicitly: a named officer, a re-read on a cadence, a short written statement of what the contract covers and what it leaves open, tabled where the board can question it. Read a five-year contract again in year three, while there is still time to write the next one differently.

Three. Approve, do not receive. The distinction was written into European resilience rules, and it is testable at your own table this quarter. Take the last three technology approvals in your minutes. For each, can any director now state which layers were covered and which were left open? If the answer takes a phone call to management, the board approved a recommendation and recorded it as a decision.

Four. Agent permissions are a board matter from this quarter. Computer and browser control is generally available now, which means the binding question is what an agent is allowed to touch and what irreversible action it may take without a human approving it. That is a scope question. Your institution has just watched what a scope question looks like when nobody owns it.


Reading List


What We Are Watching Next

This issue closes the catch-up run. Weekly publication resumes from here, and these are the threads we carry forward.

  • The Latvian service inspection, due to report in early September, and whether it publishes a layer map of the contract or a narrative about the incident. Those are different documents, and only one of them is transferable to other boards.
  • The Data State Inspectorate's proceedings, including whether eighteen years of retained payment records can be justified against the data-minimisation principle. That question reaches every institution keeping records because deleting them was never anybody's project.
  • Whether any board anywhere publishes a seam map for a major outsourced service voluntarily, ahead of an incident. The first one to do it sets the format for everyone.
  • Whether the gap between claimed board oversight of AI and credited director experience narrows in the 2027 proxy season, or whether the oversight statistic keeps rising on its own.
  • FERMA's Global Risk Manager Survey 2026, published at the FERMA Forum in Rotterdam on 4–6 October, and whether risk managers name judgment capacity as a category or leave it inside cyber.
  • What agent permissions look like once computer and browser control has been in production for two quarters, and which function ends up owning the access review.

The next issue goes deeper into one of these. If you want a specific function or sector covered, reply to this email.

And the question this run has been building toward, for the table you sit at: could this board reconstruct, today, what it approved and what it delegated?

— Liga


TwinLadder Weekly is a weekly intelligence report on judgment, governance, and the boards accountable for both. Subscribe at twinladder.ai/newsletter. Forward this issue freely.