The board’s job

The board should know where AI is material to strategy or risk, what management is trying to achieve, who owns each outcome, and how exceptions reach the board. It should be able to see both value and exposure in one reporting frame.

Evidence before assurance

A policy states intent. Assurance requires records: approved use cases, risk classifications, named owners, testing evidence, monitoring results, incidents, exceptions, and decisions. If those records cannot be produced, the oversight claim is not yet defensible.

Board questions

What should the board be able to evidence?

The board should be able to show its oversight expectations, the cadence and content of management reporting, how material AI risk enters existing committee work, and how exceptions or incidents are escalated.

Is an AI policy enough?

No. A policy is one control. Defensible governance also requires named owners, decision rights, risk classification, testing, monitoring, incident handling, evidence retention, and a repeatable reporting cadence.

How often should the board review AI?

The cadence should follow materiality. A quarterly review may fit a stable portfolio, while a major deployment, regulatory change, incident, or acquisition can require event-driven review between meetings.

What is the difference between NIST AI RMF and ISO/IEC 42001?

NIST AI RMF is a voluntary risk-management framework organized around govern, map, measure, and manage. ISO/IEC 42001 specifies requirements for an AI management system that an organization can implement and certify.

Does the board need an AI expert?

Not every director must be an expert. The board does need enough fluency to challenge management, understand material tradeoffs, and know when independent technical or governance advice is required.

Who owns AI risk in management?

Ownership should be explicit and shared by role, not blurred across a committee. Business owners own outcomes, technology owns system integrity, legal and risk own their disciplines, and one executive must own the portfolio.