Governance Risk July 28, 2026 12 min read

AI Governance for the Board of Directors: A Practical Guide

By Arjun Jaggi  ·  Enterprise AI Strategy
AI for C-Suite Leaders Series
  1. Part 1: AI for CEOs: What You Actually Need to Know
  2. Part 2: How to Build an AI Business Case Executives Will Approve
  3. Part 3: AI Governance for the Board of Directors
  4. Part 4: AI Vendor Selection Framework for Executives
  5. Part 5: Do I Need a Chief AI Officer?
  6. Part 6: The 18-Month Enterprise AI Roadmap

Boards of directors are now expected to oversee AI risk alongside financial, operational, and reputational risk. The frameworks exist. The question is whether your board has integrated them into its governance practice.

AI Governance for the Board of Directors: Where Oversight Starts

Three forces have pushed AI governance from an IT function to a board-level responsibility. The first is regulatory: the EU AI Act (Regulation 2024/1689) establishes fines of up to 7% of global annual turnover for violations related to prohibited AI practices and up to 3% for provider and deployer obligation breaches. These are not hypothetical exposures. They are material financial risks that belong on the board's risk register alongside foreign exchange exposure and litigation contingencies.

The second force is operational: as organizations deploy AI in consequential processes, including hiring, credit decisioning, and customer communications, the risk of AI-driven errors at scale becomes a governance matter. A single misconfigured AI system can affect thousands of decisions before a human reviewer notices the pattern. The board's oversight responsibility covers the processes that deploy AI, not just the technology itself.

The third force is reputational: public and regulatory trust in an organization's AI practices is now a component of brand and stakeholder confidence. Boards that cannot explain how their AI systems are governed face the same scrutiny they face on environmental or data privacy questions.

The Three-Layer Governance Model

Effective AI governance operates at three levels. Getting the boundaries between them right determines whether the board is doing governance or doing management.

The board layer sets AI risk appetite, approves the governance policy, receives regular AI risk reports, and holds the CEO accountable for AI risk management. The board does not evaluate individual AI systems or approve specific deployments. It ensures that a functioning governance structure exists, reviews aggregate risk exposure, and asks the six questions covered below.

The executive layer implements the governance policy, owns accountability for specific AI systems or use case portfolios, ensures risk assessments are conducted before deployment, and escalates material issues to the board. The Chief Technology Officer, Chief Risk Officer, or a designated Chief AI Officer typically owns this layer. The key accountability question is: can you name a specific executive whose annual review includes AI system performance?

The operational layer handles day-to-day monitoring of AI system performance, maintains documentation, runs incident response, and conducts ongoing evaluation. This layer is closest to the AI systems and produces the data that flows up to executive and board reviews.

What the EU AI Act Requires

The EU AI Act (2024/1689) classifies AI systems into four risk tiers: Unacceptable (prohibited), High, Limited, and Minimal. For most enterprise boards, the High Risk tier is the relevant classification threshold.

AI systems classified as High Risk under the Act include those used in employment decisions and worker management, access to financial services including credit scoring, medical devices, and law enforcement applications. Annex III of the Act specifies the full list. High Risk systems require a conformity assessment before deployment, detailed technical documentation, ongoing monitoring, and registration in an EU database of High Risk AI systems.

The provider and deployer distinction matters for compliance planning. An organization that deploys a vendor's AI system for hiring decisions is a deployer under the Act and carries obligations including conducting a fundamental rights impact assessment, implementing human oversight measures, and maintaining deployment logs. These obligations do not transfer to the vendor simply because the vendor built the underlying model.

Violation of provider and deployer obligations carries fines of up to 3% of global annual turnover. Deployment of a prohibited AI system carries fines of up to 7%. Boards with global operations that include EU markets should confirm that legal counsel has mapped the organization's AI portfolio against the Act's classification criteria and established a compliance timeline.

The NIST AI RMF and ISO/IEC 42001

Two voluntary frameworks provide the governance architecture that makes EU AI Act compliance operationally feasible. The NIST AI RMF 1.0 (DOI: 10.6028/NIST.AI.100-1), published January 2023, organizes AI governance around four functions: GOVERN, MAP, MEASURE, and MANAGE. GOVERN is the board-level function: setting policy, assigning accountability, and establishing culture. The other three functions operate at the executive and operational layers.

ISO/IEC 42001:2023 is the international standard for AI management systems. Where the NIST framework is descriptive and voluntary, ISO/IEC 42001 specifies certifiable requirements for an AI management system. Organizations with supply chain governance requirements, international procurement relationships, or audit-driven compliance environments may find ISO/IEC 42001 certification useful as a demonstrable signal of governance maturity.

The Six Questions Every Board Should Ask

Boards do not need to understand model architecture or evaluation benchmarks. They do need six clear, regular answers from management.

  1. What AI systems are we operating? The board cannot govern what it cannot inventory. A regularly updated AI system register, organized by risk tier, is the foundation of board-level AI oversight.
  2. Which of those systems fall in the EU AI Act High Risk tier or sector-specific regulated categories? This is the compliance question. The answer should be specific and documented.
  3. Who is personally accountable for each High Risk AI system? Named individual accountability, not committee accountability. Someone's annual review should include AI system performance.
  4. How are we monitoring performance and detecting drift? AI systems change behavior over time as the data they process changes. The board should receive a summary of monitoring cadence and any material incidents in the period.
  5. What is our incident response plan? If an AI system causes material harm, who takes it offline, who communicates with affected parties, and who reports to regulators? The plan should exist before an incident, not be created during one.
  6. Are we prepared for a regulatory examination? For High Risk systems under the EU AI Act, this means completed conformity assessments, documentation, and EU database registration. The board should confirm these are complete, not in progress.

For the complete three-layer governance framework and an interactive EU AI Act risk tier diagram, see Module 3 of the AI for C-Suite Leaders course.

Advising your board on AI governance?

I work with boards and executive teams on AI governance frameworks, EU AI Act compliance planning, and risk oversight design. Schedule a direct conversation.

Book a call →
AI for C-Suite Leaders Series, Part 3 of 6

References

  1. European Parliament and Council. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.
  2. National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). DOI: 10.6028/NIST.AI.100-1
  3. International Organization for Standardization. (2023). ISO/IEC 42001:2023: Information technology, Artificial intelligence, Management system.