Cloud Computing as a Board-Level Risk Decision

A manufacturing company’s IT manager walks into a board meeting to present a cloud migration proposal and gets stopped by a single question: ‘Where exactly will our data be stored?’ Unable to give a clear answer, the project is shelved. This scene is playing out in mid-sized Turkish companies with increasing frequency. Cloud computing has moved beyond the pages of technology magazines and onto board agendas — yet companies that treat this transition as a purely technical decision are missing the point entirely.

Cloud computing means a company rents software, storage and processing capacity from a service provider over the internet, rather than building and maintaining its own server infrastructure. The cost argument is straightforward: capital expenditure is replaced by a monthly or annual subscription, and the burden of maintenance and upgrades shifts to the provider. But behind this attractive surface lie several layers of risk that the board needs to own directly. Leaving these risks entirely to the technical team is a habit that weakens the company’s strategic decision-making.

The first risk layer is data location. Where does the cloud provider physically store your data — Turkey, Europe or the United States? This is not a technical footnote; it determines which country’s legal framework governs your data. For a Turkish manufacturer, having customer and supplier data held in a foreign data centre can create serious complications in the event of legal disputes or regulatory data access requests. Getting clear, contractual answers to these questions before signing is the board’s responsibility, not the IT department’s.

The second risk layer is vendor lock-in. Once you migrate to a cloud provider, your data, business processes and staff workflows are reshaped around that platform. What happens when the provider raises its prices, service quality drops or the company changes ownership? How long does switching to an alternative provider take, and at what cost? Can you retrieve your data, and is the procedure clearly defined in the contract? These are strategic questions that belong on the board table, not in a technical specification document. Vendor dependency exists in traditional software licensing models too, but cloud arrangements create a far deeper operational dependency that is harder to unwind.

The third risk layer covers compliance and audit requirements. Companies operating in Turkey must meet the Revenue Administration’s electronic filing obligations, including e-Beyanname submissions, as well as sector-specific record-keeping and audit requirements. If your accounting records, inventory movements and supply chain data are held in a cloud environment, how will auditors access them? What happens if the provider takes the system offline for maintenance during a period when you have a statutory filing deadline? These scenarios need to be addressed explicitly during contract negotiations, not discovered after go-live.

The board does not need technical expertise to evaluate these risks — it needs to ask the right questions. What is expected from the IT team or consultant is to translate risks from technical language into the language of corporate governance. Which data will move to the cloud and which will stay on-premise? What is the business continuity plan in the event of a service outage? What do the contract termination clauses and data return procedures actually say? The answers to these questions should appear in the clauses of the contract being signed, not in a presentation slide.

For a SME executive evaluating a cloud migration, the decision criterion should be simple: if the provider avoids answering these questions or gives vague responses, do not proceed with that provider. The cost advantage may be real and attractive, but operational dependency and data security risks can easily outweigh it. The board’s role is not to understand the technology — it is to own the risks and translate that ownership into contractual guarantees before any migration begins.

This article was originally written in Turkish by Gökhan MERCANOĞLU on July 6, 2009 and has been automatically translated into English and other languages using machine translation.


Success in routing and work center design projects depends less on initial excitement and more on sustainable usage discipline. Go-live is not the end; it is where real learning begins. When the organization measures, corrects, and owns the process, technology becomes management capacity rather than a mere investment.


Gökhan Mercanoğlu
MRP, Üretim ve Tedarik Zinciri