AI Oversight for Boards
What a board should require before approving AI systems that can take consequential actions: an oversight map, escalation questions, and evidence expectations.
Direct answer
Direct answer: AI oversight
Board oversight of AI should follow authority, not technology. For each system, the board needs to know what it is allowed to do without a person, which actions need approval, who can stop it, what evidence is kept, and how the board will hear when something goes wrong. I help boards build that oversight map for their own systems and agree the evidence they will expect at each review.
The question
“What evidence and ownership should a board require before approving AI systems with consequential actions?”
Who it is for
Boards, risk and audit committees, and executive teams responsible for AI systems that read sensitive data or take actions.
What you leave with
A board oversight map, escalation questions, and evidence expectations for each material AI system.
- 01 An inventory of material AI systems classified by the authority they hold
- 02 An oversight map: owner, approval points, stop path, and evidence for each system
- 03 Escalation questions the board or committee will ask at each review
- 04 A reporting template the executive team can complete before each meeting
How it runs
Format, method, and preparation
- Duration
- Preparation interviews, a half-day working session, and a written oversight map
- Delivery
- In person in the UK or remote
- Participants
- Board or committee members, the executive owner of AI, risk, and technology leads
Inventory by authority
List the systems that read, recommend, draft, decide, or act, and classify each by the effect it can cause.
Map control points
For each material system, record who approves high-impact actions, who can stop it, and what is logged.
Agree evidence expectations
Decide what the board expects to see: evaluation results, incidents, overrides, drift, and changes in authority.
Set escalation triggers
Define which events reach the committee or board between scheduled reviews.
Useful to have ready
- →A list, even incomplete, of AI systems in use or planned
- →Existing risk, delegation, and incident-reporting frameworks
- →Access to the executives who own the systems
Evidence
What this draws on
Regulated banking AI at Aveni
Architected enterprise banking AI with conduct-risk workflows, evidence generation, human review, escalation, evaluation, versioning, and release controls. Part of the Aveni team in the first FCA Supercharged Sandbox cohort; the FCA lists Aveni as an accepted firm, which is not an FCA endorsement or certification.
Inspect the source ↗Regulus
A runtime-governance architecture covering agent identity and purpose, policy, PII, residency, model-risk tiers, kill switches, human oversight, and evidence export. Controls are mapped to NIST AI RMF and ISO/IEC 42001; mapping is not certification.
Inspect the source ↗CloseGate
A Python and MCP policy layer with action tiers, segregation of duties, materiality routing, mandatory approval for irreversible actions, and hash-chained replayable audit. No published independent certification or customer deployment.
Inspect the source ↗Scope and limits
What this is not
- —The oversight map supports the board’s own governance; it is not a regulatory compliance opinion or an assurance report.
- —Mapping controls to frameworks such as NIST AI RMF or ISO/IEC 42001 does not constitute certification.
- —The work reviews the organisation’s own systems and records; it does not audit vendors’ internal controls.
If the need is different
Common questions
Answers before you commission
What should a board ask about AI systems?+
What each system is allowed to do without a person, who approves high-impact actions, who can stop it, what evidence is retained, how performance and incidents are reported, and who is accountable when it fails.
Should the board oversee every AI tool?+
No. Oversight should be proportionate to authority and consequence. Drafting assistants and internal search usually need policy and training; systems that decide or act on customers, money, or safety need board-level visibility.
Which committee should own AI oversight?+
That depends on the organisation. The map makes it explicit which committee receives which evidence, so ownership does not fall between risk, audit, and technology.
Does this replace an AI governance framework?+
No. It applies whatever framework the organisation uses to its actual systems and gives the board a practical way to see whether it is working.
Related