ChecklistStrategic Technology Consulting

Board oversight of AI: the questions directors should put to management

Directors do not need to understand how a model works to oversee it well. They need questions that make management show evidence: the problem being solved, what the organisation depends on, who reviews decisions about people, which laws apply and what happens when something fails. This checklist groups those questions by board decision, with the answers that should reassure you and those that should not.

Reviewed 8 min read

On this page
  1. Why AI proposals are hard for a board to test
  2. Before approving an AI investment
  3. Vendor, model and data dependency
  4. When AI influences decisions about customers or staff
  5. Regulatory exposure directors should be able to describe
  6. Roles change when a deployer modifies a system
  7. After an AI incident or near miss
  8. What the frameworks management cites can and cannot show
  9. Allocating AI oversight between the board and its committees
  10. Questions and answers
  11. Sources

Why AI proposals are hard for a board to test

Most board papers on AI share three features that make challenge difficult. The technical claims are hard to verify in a meeting, much of the analysis comes from vendors who want the contract, and there is no agreed standard for evidence that a system works. Directors end up judging the presenter's confidence rather than the strength of the case.

The remedy is a stable set of questions, asked every time, whose good answers are documents and measurements that someone outside the project could check. Over time, management learns to bring that evidence unprompted.

The questions below follow the decisions a board or its committees actually take. They extend the board summary in ColdAI's consulting deliverables, which closes with the questions directors should keep asking after approval1.

Before approving an AI investment

Each label is a question; the detail describes an answer that should reassure you.

0 of 5 checked

Vendor, model and data dependency

0 of 5 checked

When AI influences decisions about customers or staff

0 of 5 checked

Regulatory exposure directors should be able to describe

Exposure depends on the role the organisation plays. Ask management to state it for each significant system.

EU AI Act (Regulation (EU) 2024/1689), as amended by Regulation (EU) 2026/1744

European Union, including providers and deployers outside the EU whose systems or outputs are used there

Applies whenThe organisation develops an AI system and places it on the EU market (provider) or uses one under its authority (deployer)2.

  • Prohibited practices in Article 5 apply, as do Article 4 duties to take measures supporting staff AI literacy, which the Digital Omnibus softened from an obligation to ensure literacy3.
  • Deployers of high-risk systems must use them according to the provider's instructions, assign human oversight to competent people, monitor operation and keep the logs under their control (Article 26)2.
  • Most high-risk obligations now apply from 2 December 2027 for systems listed in Annex III and from 2 August 2028 for AI in products covered by Annex I3.

General Data Protection Regulation (Regulation (EU) 2016/679), Article 22

European Union and EEA

Applies whenA decision based solely on automated processing, including profiling, produces legal or similarly significant effects for an individual4.

  • Such decisions are allowed only on the grounds Article 22 sets out, such as contractual necessity, authorisation by law or explicit consent4.
  • Where a decision relies on contract or explicit consent, the person must at least be able to obtain human intervention, express their view and contest it4.

Roles change when a deployer modifies a system

After an AI incident or near miss

0 of 5 checked

What the frameworks management cites can and cannot show

FrameworkWhat it isWhat it can tell the boardWhat it does not tell you
NIST AI RMFA voluntary framework organised around four functions: Govern, Map, Measure and Manage5That management uses a recognised structure for identifying and treating AI riskNothing is certified; alignment is self-declared and says nothing about legal compliance
ISO/IEC 42001A certifiable management-system standard for organisations that develop or use AI6That an audited AI management system exists within the stated scopeWhether a particular model is accurate or fair, or whether the system you care about is in scope
ISO/IEC 27001A certifiable standard for information security management systems7That security risks are managed systematically within the certificate's scopeHow a model behaves, how outputs are reviewed or whether data use is lawful
SOC 2 reportAn independent auditor's report on a service organisation's controls against the Trust Services Criteria8With a Type II report, whether controls operated effectively over a defined periodAnything outside the systems and period examined; it is a report to read, not a certificate

Read the scope statement of any certificate or report before relying on it, and ask whether the AI service in question was included.

Allocating AI oversight between the board and its committees

  • If

    The item is a strategic AI investment or a dependency that would be expensive to reverse.

    Then

    Keep it with the full board, using the investment and dependency questions.

    Hard-to-reverse commitments belong to the whole board.

  • If

    The item concerns controls, model validation or internal audit coverage of AI systems.

    Then

    Route it to the audit committee, with internal audit reporting on the AI inventory and control tests.

    That committee already oversees the control environment and assurance.

  • If

    The item concerns risk appetite, incidents or regulatory exposure.

    Then

    Route it to the risk committee where one exists, as a standing section of its risk report.

    AI risks then sit beside comparable operational and compliance risks.

  • If

    The board doubts it can challenge management's answers at all.

    Then

    Commission an independent briefing or review before the next major approval.

    Oversight that depends only on the people being overseen is weak by design.

Questions and answers

How often should a board discuss AI?

Tie it to decisions rather than a calendar. Significant investments and dependencies come to the full board when they arise, while the audit or risk committee reviews the AI inventory, incidents and control testing in its normal cycle. A short standing item in the regular risk report usually works better than an occasional deep dive.

Does the board need a director with AI expertise?

It helps, but it does not replace good questions and good evidence. One knowledgeable director can raise the quality of discussion; relying on that person alone concentrates oversight in a single view. Many boards combine a stable question set like this one with occasional independent briefings and consider technology expertise when refreshing the board's skills matrix.

Is ISO/IEC 42001 certification enough assurance for directors?

No single certificate is. ISO/IEC 42001 shows that an audited AI management system exists within a stated scope, which is useful evidence about process. It does not show that a particular model performs well, treats people fairly or meets legal duties, so pair it with testing evidence for the systems that matter most.

Who should present AI matters to the board?

The executive who owns the business outcome should present investment and performance questions, with the technology lead available for detail. Risk, compliance or internal audit should present controls and incidents. When a vendor presents directly, directors hear the strongest version of the case and the weakest version of the risks.

What does ColdAI's board advisory work involve?

Board advisory is an ongoing engagement that supports the board and its committees with briefing papers and independent challenge on management's technology proposals. It sits alongside management's advice rather than replacing it, and is one of the four engagement models on the consulting page, with sprint assessments, strategic engagements and retained advisory.

Sources

  1. Strategic Technology Consulting: board summary and board advisory — ColdAI
  2. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  3. Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
  4. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  5. AI Risk Management Framework — National Institute of Standards and Technology · checked 10 October 2026
  6. ISO/IEC 42001:2023 — AI management systems — International Organization for Standardization · checked 10 October 2026
  7. ISO/IEC 27001 — Information security management systems — International Organization for Standardization · checked 10 October 2026
  8. SOC 2: SOC for Service Organizations — Trust Services Criteria — AICPA & CIMA · checked 10 October 2026

More in Strategic Technology Consulting

Back to Strategic Technology Consulting

Next step

Ask for a briefing paper before your next AI approval

Tell us which proposal is coming to the board and when. We will say whether an independent briefing, a sprint assessment of the proposal or ongoing board advisory fits the decision.

Discuss board advisory