Ghana Has the Sustainability Roadmaps. The Next Step Is to Make Them Work Together.
Ghana Has the Sustainability Roadmaps. The Next Step Is to Make Them Work Together.
Read articleWhy ESG Must Be on Organization's IT Governance Agenda

For years, IT governance has focused on whether technology supports strategy, manages risk, protects information and delivers value. Those questions remain important, but they are no longer enough. The emerging question is broader: Is technology being governed in a way that creates sustainable value without creating unacceptable environmental, social and governance risks?
Technology now sits at the center of ESG. Data centers consume significant energy. Devices eventually become electronic waste. Digital platforms hold large volumes of personal data. AI influences decisions affecting customers and employees. Cloud providers and technology vendors extend organizational risk, while IT systems increasingly generate the data used for sustainability reporting. For Ghanaian organizations, ESG is therefore becoming a practical IT governance issue.
Ghana’s ESG transition makes IT critical
Ghana’s adoption of IFRS S1 and IFRS S2 makes this particularly important. Significant Public Interest Entities are expected to enter mandatory adoption from 1 January 2027, with other mandatory adopters following from 2028. ICAG’s roadmap emphasizes the need for appropriate governance structures, controls and systems capable of producing reliable sustainability information.
This places IT directly within the sustainability reporting architecture. ESG information may come from ERP systems, HR platforms, procurement applications, facilities systems, spreadsheets and external service providers. Organizations must therefore be able to establish who owns the data, where it originated, how it was validated, who changed it and whether it is complete and accurate. Access controls, system interfaces, change management, audit trails, data ownership, cybersecurity and data quality consequently become ESG reporting controls.
The assurance dimension raises the stakes further. Ghana’s ISSA 5000 implementation roadmap provides for progressive mandatory sustainability assurance. Organizations cannot therefore wait until the ESG report is produced before testing whether the underlying systems and information are reliable. Assurance readiness must begin at the point where ESG data is generated.
What ESG means for IT governance
Environmental considerations should influence technology investment and lifecycle decisions. Servers, data centers, cloud platforms and equipment should be assessed not only for cost and capacity, but also for energy efficiency, utilization, emissions, useful life and responsible disposal. This is especially relevant given Ghana’s framework for managing electronic waste under Act 917.
The social dimension includes cybersecurity, privacy, digital inclusion, accessibility, employee monitoring, customer protection and responsible AI. Ghana’s Data Protection Act, 2012 (Act 843), for example, already places obligations on organizations regarding the protection of personal information.
Governance creates perhaps the strongest connection. Cybersecurity, data governance, AI governance, third-party technology risk, regulatory compliance and accountability are all central to both ESG and IT governance. Ghana’s Cybersecurity Act, 2020 (Act 1038) reinforces this through governance and compliance expectations around critical information infrastructure.
ESG should therefore not be treated as something outside technology governance. Much of it is already embedded within existing technology, risk and regulatory responsibilities.
Global practice offers useful lessons
Ghana does not have to design sustainable IT governance from scratch. The United Kingdom’s Greening Government ICT and Digital Services Strategy integrates sustainability into technology procurement, asset management, service design, supply-chain management, reuse, recycling and ICT reporting. Singapore’s Green Data Centre Roadmap links digital growth to energy efficiency and increased use of cleaner energy. Singapore has also developed frameworks for responsible AI, addressing issues such as transparency, fairness, human oversight and accountability.
These examples demonstrate that sustainable IT governance is not merely about reducing electricity consumption. It is about embedding sustainability into technology decisions, controls, procurement, risk management and performance reporting. Existing frameworks can support this transition. ISO/IEC 27001 provides controls around information security and resilience, ISO/IEC 42001 provides a governance framework for responsible AI, while COBIT provides governance and management practices through which sustainability considerations can be integrated into IT decision-making.
Ghanaian organizations should integrate, not duplicate
The solution is not necessarily another committee or governance structure. Sustainability considerations should instead be incorporated into existing IT governance processes. Technology investment proposals can consider environmental and social impacts alongside cost, risk and return. IT procurement can assess vendor cybersecurity, privacy, ethical sourcing, energy efficiency and equipment disposal. AI projects can undergo impact assessments before deployment. ESG datasets can have designated owners, validation controls and clear audit trails.
Boards should also expand technology reporting beyond uptime, projects and cyber incidents. Relevant indicators could include technology-related energy consumption, e-waste disposal, privacy incidents, responsible AI exceptions, critical supplier ESG risks and the reliability of ESG reporting systems.
Internal audit must evolve
Internal audit also has an important role. An IT governance audit that examines cybersecurity, strategy and compliance but ignores ESG data governance, responsible AI, electronic waste, technology-related environmental impacts and sustainability risks within technology suppliers may increasingly provide an incomplete assessment.
Internal auditors should consider whether ESG is incorporated into technology strategy, investment, procurement, data governance, third-party management and lifecycle decisions. They should also assess whether ESG information generated by technology systems is complete, traceable and supported by reliable evidence. This strengthens both governance and future external sustainability assurance.
The next phase of IT governance
Sustainable IT governance is not about inserting ESG language into existing policies. It represents a broader understanding of technology value and risk. The traditional question has been: Is technology delivering value while managing risk? The emerging question is: Is technology delivering sustainable value while responsibly managing its environmental footprint, impact on people, use of data and governance obligations?
For Ghana, the timing is important. IFRS S1 and S2 adoption, sustainability assurance, cybersecurity regulation, data protection, electronic-waste management and emerging AI governance are converging around the same digital environment.
Boards, CIOs, CISOs, risk professionals and internal auditors should begin connecting these agendas now. The future of IT governance is not simply controlled technology. It is responsible, resilient, transparent and sustainable technology that creates value organizations and stakeholders can trust.
This article was authored by Wilfred Neneh Addico, CA, Chartered Dip. ESG (ICAG), Chartered Tax Practitioner, ISO/IEC 27001:2022 Lead Auditor, ISO/IEC 42001:2023 Lead Auditor, Certified Cybersecurity Professional, CFE, CISA, CRISC, MIoD, Certified Compliance Officer, and holder of a Certificate in Machine Learning & Data Science from MIT, USA. Wilfred is a multidisciplinary governance, risk, technology, ESG and business advisory professional, supporting organizations to strengthen governance, manage emerging risks, enhance assurance readiness and build resilient, sustainable businesses. For consulting and business advisory engagements, he can be reached at neaddico@yahoo.com.