ChecklistStrategic Technology Consulting
Board oversight of AI: the questions directors should put to management
Directors do not need to understand how a model works to oversee it well. They need questions that make management show evidence: the problem being solved, what the organisation depends on, who reviews decisions about people, which laws apply and what happens when something fails. This checklist groups those questions by board decision, with the answers that should reassure you and those that should not.
On this page
- Why AI proposals are hard for a board to test
- Before approving an AI investment
- Vendor, model and data dependency
- When AI influences decisions about customers or staff
- Regulatory exposure directors should be able to describe
- Roles change when a deployer modifies a system
- After an AI incident or near miss
- What the frameworks management cites can and cannot show
- Allocating AI oversight between the board and its committees
- Questions and answers
- Sources
Why AI proposals are hard for a board to test
Most board papers on AI share three features that make challenge difficult. The technical claims are hard to verify in a meeting, much of the analysis comes from vendors who want the contract, and there is no agreed standard for evidence that a system works. Directors end up judging the presenter's confidence rather than the strength of the case.
The remedy is a stable set of questions, asked every time, whose good answers are documents and measurements that someone outside the project could check. Over time, management learns to bring that evidence unprompted.
The questions below follow the decisions a board or its committees actually take. They extend the board summary in ColdAI's consulting deliverables, which closes with the questions directors should keep asking after approval1.
Before approving an AI investment
Each label is a question; the detail describes an answer that should reassure you.
Vendor, model and data dependency
When AI influences decisions about customers or staff
Regulatory exposure directors should be able to describe
Exposure depends on the role the organisation plays. Ask management to state it for each significant system.
EU AI Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744
European Union, including providers and deployers outside the EU whose systems or outputs are used thereApplies whenThe organisation develops an AI system and places it on the EU market (provider) or uses one under its authority (deployer)2.
- Prohibited practices in Article 5 apply, as do Article 4 duties to take measures supporting staff AI literacy, which the Digital Omnibus softened from an obligation to ensure literacy3.
- Deployers of high-risk systems must use them according to the provider's instructions, assign human oversight to competent people, monitor operation and keep the logs under their control (Article 26)2.
- Most high-risk obligations now apply from 2 December 2027 for systems listed in Annex III and from 2 August 2028 for AI in products covered by Annex I3.
General Data Protection Regulation (Regulation (EU) 2016/679), Article 22
European Union and EEAApplies whenA decision based solely on automated processing, including profiling, produces legal or similarly significant effects for an individual4.
Roles change when a deployer modifies a system
After an AI incident or near miss
What the frameworks management cites can and cannot show
| Framework | What it is | What it can tell the board | What it does not tell you |
|---|---|---|---|
| NIST AI RMF | A voluntary framework organised around four functions: Govern, Map, Measure and Manage5 | That management uses a recognised structure for identifying and treating AI risk | Nothing is certified; alignment is self-declared and says nothing about legal compliance |
| ISO/IEC 42001 | A certifiable management-system standard for organisations that develop or use AI6 | That an audited AI management system exists within the stated scope | Whether a particular model is accurate or fair, or whether the system you care about is in scope |
| ISO/IEC 27001 | A certifiable standard for information security management systems7 | That security risks are managed systematically within the certificate's scope | How a model behaves, how outputs are reviewed or whether data use is lawful |
| SOC 2 report | An independent auditor's report on a service organisation's controls against the Trust Services Criteria8 | With a Type II report, whether controls operated effectively over a defined period | Anything outside the systems and period examined; it is a report to read, not a certificate |
Read the scope statement of any certificate or report before relying on it, and ask whether the AI service in question was included.
Allocating AI oversight between the board and its committees
- If
The item is a strategic AI investment or a dependency that would be expensive to reverse.
ThenKeep it with the full board, using the investment and dependency questions.
Hard-to-reverse commitments belong to the whole board.
- If
The item concerns controls, model validation or internal audit coverage of AI systems.
ThenRoute it to the audit committee, with internal audit reporting on the AI inventory and control tests.
That committee already oversees the control environment and assurance.
- If
The item concerns risk appetite, incidents or regulatory exposure.
ThenRoute it to the risk committee where one exists, as a standing section of its risk report.
AI risks then sit beside comparable operational and compliance risks.
- If
The board doubts it can challenge management's answers at all.
ThenCommission an independent briefing or review before the next major approval.
Oversight that depends only on the people being overseen is weak by design.
Questions and answers
How often should a board discuss AI?
Tie it to decisions rather than a calendar. Significant investments and dependencies come to the full board when they arise, while the audit or risk committee reviews the AI inventory, incidents and control testing in its normal cycle. A short standing item in the regular risk report usually works better than an occasional deep dive.
Does the board need a director with AI expertise?
It helps, but it does not replace good questions and good evidence. One knowledgeable director can raise the quality of discussion; relying on that person alone concentrates oversight in a single view. Many boards combine a stable question set like this one with occasional independent briefings and consider technology expertise when refreshing the board's skills matrix.
Is ISO/IEC 42001 certification enough assurance for directors?
No single certificate is. ISO/IEC 42001 shows that an audited AI management system exists within a stated scope, which is useful evidence about process. It does not show that a particular model performs well, treats people fairly or meets legal duties, so pair it with testing evidence for the systems that matter most.
Who should present AI matters to the board?
The executive who owns the business outcome should present investment and performance questions, with the technology lead available for detail. Risk, compliance or internal audit should present controls and incidents. When a vendor presents directly, directors hear the strongest version of the case and the weakest version of the risks.
What does ColdAI's board advisory work involve?
Board advisory is an ongoing engagement that supports the board and its committees with briefing papers and independent challenge on management's technology proposals. It sits alongside management's advice rather than replacing it, and is one of the four engagement models on the consulting page, with sprint assessments, strategic engagements and retained advisory.
Sources
- Strategic Technology Consulting: board summary and board advisory — ColdAI
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- AI Risk Management Framework — National Institute of Standards and Technology · checked 10 October 2026
- ISO/IEC 42001:2023 — AI management systems — International Organization for Standardization · checked 10 October 2026
- ISO/IEC 27001 — Information security management systems — International Organization for Standardization · checked 10 October 2026
- SOC 2: SOC for Service Organizations — Trust Services Criteria — AICPA & CIMA · checked 10 October 2026