Blog

AI Governance Questions Every Board Should Ask Management

Subscribe now to join the Risk Register community:

If you sit on a board today, artificial intelligence is already on your agenda, whether or not it's appeared there formally. It's shaping decisions and quietly entering your organization through the tools you already rely on. The pace has outrun most governance frameworks, and that gap is where risk lives.

You don't need to become a technologist to govern it. You need to know who owns the risk, whether the organization is using AI responsibly, and whether someone independent has confirmed the safeguards are real. What follows are the AI governance questions we'd ask if we were in your seat, grouped into six areas of oversight, each paired with what a reassuring answer sounds like and what should give you pause. The goal isn't to put management on the defensive. It's to tell the difference between assurance that's earned and comfort that's merely assumed. The first area is the one everything else hangs on.

AI governance starts with a named owner and a way to hear bad news

Good governance starts with knowing who's answerable. The board's first task isn't to understand the technology. It's to confirm that a named leader owns AI risk, that clear rules are in place, and that the board would hear about a serious problem in time to act. If no one clearly owns AI, oversight has nothing to attach to.

Three questions do the work here. Who is accountable to us for how AI is used across the organization? Do we have a board-approved position on how AI may and may not be used? And would we hear about a serious AI problem quickly, and from management first?

A good answer names a single senior leader who owns AI risk and reports to the board, points to a current policy the board has actually seen, and describes an escalation path with a timeline attached. What should concern you: AI described as a shared responsibility with nobody in charge, a policy the board has never revisited, or the sense that you'd learn about a problem from a headline before you learned about it from management.

In our experience, this is where most organizations are weakest. AI tends to spread through the business before anyone is formally put in charge of it. When we ask boards who owns AI risk, the pause that follows is usually the most honest answer we get. Settling ownership early makes every other conversation in this guide easier, starting with the next question: where is the AI, exactly?

The board can't oversee AI that management can't see

The board cannot oversee what management cannot see. This area is about confirming the organization knows where AI is being used, including the AI built into software it already buys, and that the most consequential uses get the most attention.

Ask: do we have a clear picture of where AI is used in our business? Are the highest-stakes uses of AI getting the most oversight? And is AI making or influencing decisions that carry legal or reputational weight?

Good looks like a current inventory that includes AI built into purchased tools, with uses that affect people or money managed more closely than routine ones, and management able to say which decisions AI touches. The concern signals are the mirror image: nobody can confidently say where AI is in use, or everything is treated the same.

The AI that worries us most is the AI no one chose. It arrives inside tools the organization already trusts, switched on by a vendor update. The first time we run this exercise with a client, the inventory is almost always longer than management expected. That gap between perception and reality is exactly what the board needs to see, which brings us to whether any of it can be trusted.

AI is only as trustworthy as its data and the people checking it

AI is only as trustworthy as the information behind it and the judgment applied to its results. An AI mistake in a consequential decision can harm a customer or employee and expose the organization to claims it can't easily undo.

Four questions here. Are we confident the data behind our AI is appropriate to use? How do we keep confidential information out of public AI tools? Could our AI produce unfair or simply wrong results, and would we catch it? And do people still hold the final say on decisions that affect lives or livelihoods?

A well-governed organization knows what data feeds its AI and has the right to use it that way, keeps sensitive data from leaving the building, checks AI results over time, and puts a person with real authority in a position to overturn the AI on consequential matters. Worry when the data sources or the rights to them are unclear, when the guardrail is individual judgment, or when human review is a formality.

Boards rightly focus on whether AI is fair, but the quieter risk is confident, well-formatted, and wrong. AI can be persuasive in error. The protection isn't perfect technology. It's keeping capable people in the decisions that carry real consequences, with the authority and the time to disagree with the machine. A human who can step in is also the next question, applied to the day something breaks.

AI resilience means a fallback and a way to stop it

AI creates new dependencies and new risks. An organization that leans on AI without a fallback, or lets AI act without limits, is exposed when something breaks.

Ask: if an important AI system failed, could we keep operating? Where AI can take action on its own, what keeps it within bounds? And is AI treated as part of our security, not an exception to it?

Good looks like critical processes with a fallback if AI is unavailable, autonomous AI with clear limits, a record of what it does, and a way to stop it, and AI systems protected and tested like the rest of the organization's technology. Be concerned if key operations depend on AI with no backup plan, or if AI sits outside the security program.

The capability moving fastest right now is AI that acts on its own, not just AI that advises. The reasonable questions are simple ones: what can it do without a human, what's the limit, and how do we stop it. An organization that can't answer the last question has given away more control than it realizes. And increasingly, the people asking sit outside the organization, which is where we turn to next.

AI regulation, vendors, and public claims all create outside exposure

AI rules are expanding, and much of the organization's AI risk now sits with its vendors and in its public statements. New rules, a vendor's hidden use of AI, or an overstated public claim can each create exposure the board didn't see coming.

Ask: are we keeping up with the AI rules that apply to us? Do we understand the AI risk we take on through our vendors? And can we stand behind what we tell customers and regulators about our AI?

Good looks like someone tracking relevant AI regulation, vendor oversight that includes how partners use AI on the organization's behalf, and public claims about AI that match what the organization can actually demonstrate. Worry when nobody is watching the rules, when vendor AI is treated as someone else's problem, or when public statements run ahead of reality.

Regulation is arriving unevenly across jurisdictions, which makes a single owner for tracking it more valuable than any one rule. The exposure that catches boards off guard, though, is self-inflicted: claims about AI made in marketing, contracts, or filings that the organization can't stand behind. Govern what you say about AI as carefully as what you do with it. Then get someone independent to check both, which brings us to the final area and the one we care about most.

Independent assurance is where board confidence is earned

The board's confidence should rest on more than management's word. Without independent challenge, the board can't tell controls that work from assurances that only sound good. This area confirms that an independent party, such as internal audit working alongside a co-sourced specialist, has examined AI governance, and that the board can see whether AI risk is improving or worsening over time.

Ask: has anyone independent checked that our AI controls actually work? Does internal audit have AI on its agenda? And how will we know if our AI risk is getting better or worse?

Good looks like an independent party having reviewed AI governance and reported findings, AI and its highest-risk uses appearing in the audit plan, and the board receiving a few clear measures tracked over time. Concern signals: the board's comfort rests entirely on management saying things are fine, AI is absent from the audit plan because it's seen as too technical, or reporting is anecdotal.

Management's assurance that AI is well governed is a starting point, not a conclusion. Full stop. Independent assurance converts a comfortable narrative into something the board can actually rely on, in language a director can act on. Which leaves one practical question: where do you start?

Where boards should focus first on AI governance

If your board can confidently answer only a few of these questions today, that isn't unusual. AI governance is maturing across nearly every organization. A practical starting point: confirm who owns AI risk, confirm the board would hear about a serious problem in time, and confirm someone independent has looked at the safeguards. Those three answers tell you whether the rest of the picture can be trusted.

The next disruption won't wait for the agenda to catch up, and the boards that handle it well will be the ones that already know what a trustworthy answer sounds like. If this raised a question you couldn't confidently answer, that's the conversation worth having. Our board-level AI governance assessment benchmarks your organization against these six areas and gives you an independent read on where assurance is real and where it needs work. For the sharper version of this list, prompted by a specific event, read what audit committees should be asking about Claude Mythos. Or reach out to Cherry Hill Advisory and start with a conversation.

Until next time.

Subscribe now to join the Risk Register community: