The AI Governance Brief

What Boards Should Ask About AI—and What Good Answers Look Like

Directors don't need to understand transformers. They need clear accountability, the right metrics and confidence that management has a plan.

Illustration for What Boards Should Ask About AI—and What Good Answers Look Like

Oversight, not operation

The board's role is to ensure a sound system of governance exists and works—not to approve individual models. That means understanding strategy, risk appetite, accountability and assurance. Directors who try to evaluate model architectures will quickly drown in detail; directors who ask whether accountability is clear, metrics are consistent and incidents are handled well will get to the truth quickly.

This mirrors how boards already oversee other risk domains. No director reads firewall configurations, but every board asks whether cyber risk is owned, measured and within appetite. AI deserves the same discipline: a defined governance system, a named accountable executive, and reporting that lets the board see trends and challenge management.

The stakes are rising. Regulators increasingly expect board-level oversight of AI, investors ask about it in diligence, and plaintiffs' attorneys look for evidence that directors engaged. A board that can show structured, recurring oversight is in a fundamentally different position from one that cannot.

Five questions worth asking

These questions quickly reveal program maturity. They are deliberately simple—their power is in whether management can answer them specifically and consistently, quarter after quarter:

The first question is the keystone. If accountability is diffused across a committee with no chair, a working group with no budget, or 'everyone,' the program does not have an owner, and the board has found its first action item. Everything else flows from a named executive with authority and resources.

  • Who is accountable for AI governance, and do they have authority and resources?
  • Do we have a current inventory of AI systems, including those from vendors?
  • Which uses are high-risk, and how are they approved and monitored?
  • What is our stated risk appetite for AI, and where are we outside it?
  • How would we know if an AI system caused harm, and what would we do next?
The accountability chain
  1. 01BoardSets appetite, oversees
  2. 02Executive ownerAccountable for the program
  3. 03Governance committeeApproves high-risk uses
  4. 04System ownersOperate controls day to day

What good answers look like

Strong answers are specific: a named executive, an inventory with coverage and freshness figures, a defined tiering model, documented approvals for high-risk systems, and an incident process that has been tested. Weak answers rely on intent—'we're being careful'—rather than evidence. The difference is easy to hear once you listen for it: specifics versus adjectives.

Good answers also include bad news. A management team that reports zero incidents, zero findings and zero systems outside appetite is either not looking or not telling. Mature programs surface problems early and show them being fixed; the board should worry more about a spotless report than about one with a well-managed remediation queue.

Consistency matters as much as content. The same metrics, defined the same way, reported every quarter, let directors see direction of travel. A constantly changing report format is often a sign that the underlying program is constantly changing too—or that the numbers are being shaped to the audience.

A quarterly reporting pack

Keep board reporting short and consistent so trends are visible. A useful pack fits on a few pages: number of AI systems by tier, high-risk systems approved and pending, control implementation status, open findings and remediation age, incidents and near misses, and notable regulatory developments.

Each metric should have an owner and a definition. 'Open findings' means nothing unless the board knows what counts as a finding and what 'on time' remediation looks like. Agree the definitions once, then hold them steady.

Resist the temptation to expand the pack every quarter. Depth belongs in the annual deep dive or the audit committee's working session; the board pack's job is to make the trend lines impossible to miss.

Building board fluency

A short annual education session, paired with occasional deep dives on a specific high-risk system, builds the literacy directors need to challenge management constructively. Walking through one real system—what it does, what data it uses, how it was assessed, what could go wrong, how it is monitored—teaches more than any slide deck about AI in general.

Fluency is not expertise. The goal is directors who can ask the second question: not just 'do we have an inventory?' but 'how do you know it is complete?' That level of engagement is achievable for any board, and it is what regulators, investors and courts increasingly mean by oversight.

Preparing for your next board conversation?

We help you define the reporting pack, name the accountable executive and run the education session that turns AI oversight from a topic into a discipline.

Know where AI is. Find where it can go.

Start with an AI Governance & Opportunity Assessment.

Get your assessment