Regulator says compliance alone is not enough as boards take on wider oversight of technology, cyber risks and data governance