Board advisory

AI Oversight for Boards

What a board should require before approving AI systems that can take consequential actions: an oversight map, escalation questions, and evidence expectations.

Direct answer

Direct answer: AI oversight

Board oversight of AI should follow authority, not technology. For each system, the board needs to know what it is allowed to do without a person, which actions need approval, who can stop it, what evidence is kept, and how the board will hear when something goes wrong. I help boards build that oversight map for their own systems and agree the evidence they will expect at each review.

The question

“What evidence and ownership should a board require before approving AI systems with consequential actions?”

Who it is for

Boards, risk and audit committees, and executive teams responsible for AI systems that read sensitive data or take actions.

What you leave with

A board oversight map, escalation questions, and evidence expectations for each material AI system.

  • 01 An inventory of material AI systems classified by the authority they hold
  • 02 An oversight map: owner, approval points, stop path, and evidence for each system
  • 03 Escalation questions the board or committee will ask at each review
  • 04 A reporting template the executive team can complete before each meeting

How it runs

Format, method, and preparation

Duration
Preparation interviews, a half-day working session, and a written oversight map
Delivery
In person in the UK or remote
Participants
Board or committee members, the executive owner of AI, risk, and technology leads
01

Inventory by authority

List the systems that read, recommend, draft, decide, or act, and classify each by the effect it can cause.

02

Map control points

For each material system, record who approves high-impact actions, who can stop it, and what is logged.

03

Agree evidence expectations

Decide what the board expects to see: evaluation results, incidents, overrides, drift, and changes in authority.

04

Set escalation triggers

Define which events reach the committee or board between scheduled reviews.

Useful to have ready

  • →A list, even incomplete, of AI systems in use or planned
  • →Existing risk, delegation, and incident-reporting frameworks
  • →Access to the executives who own the systems

Evidence

What this draws on

Delivery experience

Regulated banking AI at Aveni

Architected enterprise banking AI with conduct-risk workflows, evidence generation, human review, escalation, evaluation, versioning, and release controls. Part of the Aveni team in the first FCA Supercharged Sandbox cohort; the FCA lists Aveni as an accepted firm, which is not an FCA endorsement or certification.

Inspect the source ↗
Public reference system

Regulus

A runtime-governance architecture covering agent identity and purpose, policy, PII, residency, model-risk tiers, kill switches, human oversight, and evidence export. Controls are mapped to NIST AI RMF and ISO/IEC 42001; mapping is not certification.

Inspect the source ↗
Public reference system

CloseGate

A Python and MCP policy layer with action tiers, segregation of duties, materiality routing, mandatory approval for irreversible actions, and hash-chained replayable audit. No published independent certification or customer deployment.

Inspect the source ↗

Scope and limits

What this is not

  • —The oversight map supports the board’s own governance; it is not a regulatory compliance opinion or an assurance report.
  • —Mapping controls to frameworks such as NIST AI RMF or ISO/IEC 42001 does not constitute certification.
  • —The work reviews the organisation’s own systems and records; it does not audit vendors’ internal controls.

If the need is different

Common questions

Answers before you commission

What should a board ask about AI systems?+

What each system is allowed to do without a person, who approves high-impact actions, who can stop it, what evidence is retained, how performance and incidents are reported, and who is accountable when it fails.

Should the board oversee every AI tool?+

No. Oversight should be proportionate to authority and consequence. Drafting assistants and internal search usually need policy and training; systems that decide or act on customers, money, or safety need board-level visibility.

Which committee should own AI oversight?+

That depends on the organisation. The map makes it explicit which committee receives which evidence, so ownership does not fall between risk, audit, and technology.

Does this replace an AI governance framework?+

No. It applies whatever framework the organisation uses to its actual systems and gives the board a practical way to see whether it is working.

Related

Next step

Describe your audience and decision

A short written brief is enough to establish fit. I reply personally, and say plainly when the work belongs elsewhere or is not worth commissioning.

Board or leadership decision: what to include

  • →Sponsor and role
  • →The decision to be made, and by when
  • →Who will be in the room
  • →What has been proposed or purchased so far
  • →Evidence already available (papers, vendor material, pilots)
  • →Preferred format, date, and location or remote
  • →Budget range or approval route
  • →Known conflicts or sensitivities