AI Governance Board Questions: What Boards Should Be Asking

Short Answer

Boards are expected to oversee AI risk as part of their technology risk responsibilities, but most boards do not yet have the information they need to do so. The starting point is asking the right questions. Boards that cannot get clear answers to the questions set out here have identified their first governance gap.

Board oversight of AI is not a technology question; it is a governance question. Boards do not need to understand how large language models work. They need to understand what AI systems the organisation is using, what decisions those systems are making or informing, what risks they carry, and whether those risks are being appropriately managed. These are the same governance questions that apply to any material business risk, and the same governance standards apply.

The first question is: what AI systems are we using? Boards should be able to receive a summary of the material AI systems in operation, including AI embedded in vendor platforms, and understand for each one what the system does, what decisions it influences, and what data it accesses. Organisations that cannot answer this question have not inventoried their AI use and are governing a risk they do not fully understand.

The second question is: who is accountable for each AI system and its outcomes? AI systems that produce decisions or outputs that affect customers, employees, or business operations carry accountability. That accountability should attach to a named individual or function, not rest diffusely with the technology department. When an AI system produces a harmful or inaccurate output, it should be clear who is accountable for addressing it and who is accountable for ensuring it does not recur.

The third question is: how do we know if an AI system is performing as intended? AI systems can produce outputs that are accurate on average but systematically biased against particular groups, inconsistent under specific conditions, or vulnerable to manipulation. The board should understand what monitoring is in place for material AI systems and how problems with AI performance would be identified and escalated. AI systems that are not monitored post-deployment carry risks that the organisation is not positioned to detect.

The fourth question is: what AI uses are prohibited or require approval? An AI policy that does not specify what uses are prohibited or what assessment is required before a new AI system is deployed leaves individual business units and employees making those judgements independently. This produces an inconsistent approach to AI risk and a governance gap that will be visible to regulators and auditors as AI oversight standards develop.

The fifth question is: what is our exposure to AI regulation? Australian and international AI regulation is developing rapidly. Financial services, health, and government sectors face the most immediate regulatory attention. Any organisation that makes automated decisions affecting individuals needs to understand its current and emerging regulatory obligations. The board should receive a periodic assessment of the regulatory landscape and the organisation's position relative to its obligations.

Frequently Asked Questions

Related Reading

Ready to discuss?

No sales script. Initial discussion is obligation-free.