Boards are now expected to oversee AI risk alongside financial, operational, and reputational risk. This module gives you the three-layer governance model, the EU AI Act risk tiers that determine your compliance obligations, and the NIST AI RMF framework that ties them together.
Why AI Governance Has Become a Board-Level Responsibility
Three forces have moved AI governance from an IT function to a board responsibility. The first is regulatory: the EU AI Act (Regulation 2024/1689) establishes fines of up to 7% of global annual turnover for violations related to prohibited AI practices and up to 3% for provider and deployer obligation breaches. These are material financial risks that belong on the board's risk register.
The second force is operational: as organizations deploy AI in consequential processes, including hiring, lending, medical screening, and customer communications, the risk of AI-driven errors at scale becomes a governance matter. A single misconfigured AI system can affect thousands of decisions before a human reviewer notices.
The third force is reputational: public trust in an organization's AI practices is now a component of brand and stakeholder confidence. Boards that cannot explain how their AI systems are governed face the same reputational exposure they face on environmental or data privacy questions.
The board's accountability
Boards do not need to understand how AI models work. They do need to be able to answer: what AI systems are we deploying, what risk tier do they fall in, who is accountable for their performance, and how will we know if something goes wrong?
The Three-Layer Governance Model
Effective AI governance operates at three levels, each with different responsibilities and decision-making authority.
The board layer is responsible for setting AI risk appetite, approving the governance policy, receiving regular AI risk reports, and ensuring that executive accountability is clear. The board does not evaluate individual AI systems. It ensures the organization has a functioning governance structure, reviews aggregate risk exposure, and holds the CEO accountable for AI risk management.
The executive layer is responsible for implementing the governance policy, owning specific AI systems or use case portfolios, ensuring that risk assessments are conducted before deployment, and escalating material issues to the board. The Chief Technology Officer, Chief Risk Officer, or a designated Chief AI Officer typically owns this layer.
The operational layer is responsible for day-to-day monitoring of AI system performance, maintaining documentation, running incident response, and conducting ongoing evaluation. This layer is closest to the AI systems and produces the data that flows up to executive and board reviews.
EU AI Act Risk Tiers
The EU AI Act (2024/1689) classifies AI systems into four risk tiers. Understanding which tier your AI deployments fall into determines your compliance obligations and, by extension, your governance requirements.
The High Risk tier is where most enterprise AI governance attention should focus. AI systems used in hiring decisions, employee performance evaluation, access to financial services, and medical device functionality are classified as High Risk under the EU AI Act. High Risk systems require a conformity assessment before deployment, ongoing monitoring, detailed technical documentation, and registration in an EU database.
Organizations that deploy AI for recruitment screening, automated credit decisioning, or employee monitoring need to confirm whether those systems fall within the High Risk classification and plan their compliance accordingly. The provider/deployer obligations apply up to 3% of global annual turnover for violations in this tier.
The NIST AI Risk Management Framework
The NIST AI RMF 1.0 (published January 2023, DOI: 10.6028/NIST.AI.100-1) provides a voluntary governance framework organized around four functions. It is the most widely adopted AI governance reference in the United States and is increasingly used globally alongside ISO/IEC 42001:2023.
Function 1
GOVERN
Establish and maintain policies, accountability structures, and culture. This is the board-level function: setting risk appetite, assigning ownership, and ensuring governance exists.
Function 2
MAP
Identify the context and risks of specific AI systems. Who are the affected stakeholders? What could go wrong? What is the potential impact? Conducted before deployment.
Function 3
MEASURE
Quantify and track AI risks using defined metrics. Accuracy, fairness metrics, drift detection, and incident rates are measured and reported against defined thresholds.
Function 4
MANAGE
Prioritize and address identified risks. Includes incident response plans, escalation protocols, and decisions to accept, mitigate, transfer, or avoid specific risks.
ISO/IEC 42001:2023 is the international standard for AI management systems. Where the NIST AI RMF provides a flexible framework, ISO/IEC 42001 specifies requirements for an AI management system that can be certified by an external auditor. Organizations with international operations or supply chain governance requirements may find the ISO standard more useful as a contractual or procurement reference.
Six Board-Level Questions for AI Governance
The board does not need to review every AI system. It does need to ask these six questions regularly and receive clear answers from management.
1. What AI systems are we operating? Boards cannot govern what they cannot inventory. The executive team should maintain a register of AI systems in operation, organized by risk tier.
2. Which of those systems are High Risk under applicable regulation? For organizations operating in or selling to EU markets, the EU AI Act High Risk classification is the relevant threshold. For US-regulated industries, sector-specific guidance from financial regulators, the FDA, or the EEOC may apply.
3. Who is accountable for each High Risk AI system? Named executive accountability, not committee accountability. Someone's annual review should include AI system performance.
4. How are we monitoring performance and detecting drift? AI systems change behavior over time as the data they process changes. The board should receive a report on monitoring cadence and any material incidents.
5. What is our incident response plan? If an AI system causes material harm, who decides to take it offline, who communicates with affected parties, and who reports to regulators?
6. Are we prepared for a regulatory examination? For High Risk AI systems under the EU AI Act, this means documentation, conformity assessments, and EU database registration. The board should confirm that these are complete, not just in progress.