Board-level interest in AI governance has grown sharply over the past eighteen months. Some of that is genuine concern about risk and accountability. Some of it is pressure from regulators, investors, customers, and insurers, who are starting to ask questions boards need credible answers to.
The problem is that a lot of board-level AI governance discussion happens at the wrong level. Boards talk about AI strategy, AI opportunity, and AI ethics in broad terms. The more useful conversation – whether AI governance for boards is actually working, where the real risks sit, and what evidence shows controls are functioning – happens far less often.
Here are the questions that cut through to what matters.
Do we know what AI is in use across the organisation?
This is the foundation question. Most organisations answer it less confidently than they should. The honest version is usually: “we know what has been formally approved, and we have some visibility of the main tools people use, but we probably do not have the full picture”.
That honest answer is not a governance failure on its own. It reflects how AI adoption has actually happened. But it tells you where the work needs to start. An organisation that cannot answer this question with confidence cannot meaningfully answer any question that follows it – a point covered in more depth in why most organisations have no real visibility of AI usage.
The board’s job here is not to build the inventory themselves. It is to make sure someone credible owns it, that the process for maintaining it is solid, and that the inventory actually drives risk assessment and control rather than sitting unused in a document.
Who is accountable for AI governance decisions?
Accountability for AI governance is genuinely unclear in most organisations. It often falls into a gap between the CISO, the CTO, legal, compliance, and the business units actually using AI. Everyone has a view. Nobody has clear ownership.
Diffuse accountability behaves like no accountability when something goes wrong. The question for boards is not “who is involved in AI governance?” It is “who is accountable for making sure governance works, and what does that accountability mean in practice?”
This covers operational accountability – who approves AI tools, who reviews supplier relationships, who owns the risk register – and strategic accountability – who is responsible for the overall programme being adequate and current.
What evidence do we have that controls are working?
This question reveals the gap between governance on paper and governance that actually functions, faster than any other.
Boards are often told AI governance is in place. The policy exists. The process is documented. The risk register has been created. Whether those controls actually produce the right outcomes day to day is a different question, and it needs different evidence.
What does the AI tool approval process look like in practice? How many requests come through it, how are they assessed, and how long does it take? Do staff know about the AI acceptable use policy, and do they understand what it requires? When was the risk register last updated based on what is actually happening, not just a scheduled review? Is there any monitoring that would catch an AI-related incident before it became a real problem?
These are operational questions. The answers tell you whether governance is real. A board that only hears policy-level assurance is not getting what it needs to do its job.
What are our most significant AI-related risks right now?
Most board-level AI risk discussions focus on the wrong categories. The conversation drifts toward speculative future risks – regulatory change, competitive disruption, AI safety in the abstract – while the immediate, manageable operational risks get too little attention.
The risks most organisations should focus on right now are far more ordinary. Data reaching AI systems under supplier terms nobody reviewed. AI-generated content used in decisions or customer communications without human review. Governance structures that exist on paper but get bypassed in practice. Supplier relationships with AI providers whose terms have changed significantly since they were agreed – exactly the kind of risk an AI risk assessment is designed to surface.
Boards should ask for a clear, prioritised view of AI risk grounded in actual usage, not generic AI risk frameworks. The most useful picture tells you what is exposed today, not what could theoretically go wrong with AI in general.
Are we asking these questions often enough?
AI governance is not static. The tools in use change. Supplier terms change. Staff workflows evolve. The regulatory picture shifts. A risk that was acceptable six months ago may not be acceptable now.
A board that received a governance update eighteen months ago and considers it settled is not exercising oversight. It is holding historical assurance about a moving situation. These questions need asking on a cadence that matches how fast AI usage and AI risk are changing in your organisation – for most organisations, that is more often than other technology governance topics get reviewed.
Independent external review, rather than relying only on internal assurance, is increasingly valuable here. The same logic applies as it does to financial audit: the people implementing governance are not the best judges of whether it is working.
Black Chili’s Continuous AI Assurance service gives boards ongoing independent oversight of AI governance – evidence, not just assurance.
If you are not sure what AI tools are in use inside your organisation, an AI Exposure Review gives you a clear, independent picture - what is being used, what data it touches, and where the real risks are.