AI governance for boards: ask for evidence, not assurances.
For the people who set strategy, approve risk appetite and answer for outcomes: the decisions that are yours, the few numbers to ask for, and what a working governance function can show you.
Who this is for.
You do not need the mechanics. You need to know which decisions only you can take, what to ask for in the board pack, and how to tell a governance function that runs from one that only reports. This route is short on purpose: the argument, the decisions, the oversight.
- Board members
- Chief executives and executive committees
- Chief AI, data and technology officers
- Audit and risk committees
On the learning path, start at What the discipline is or Maturity self-assessment.
New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.
Three questions you bring.
Each one answered in brief here, and in full in the Body of Knowledge.
-
Which decisions are ours to take?
Whether to use AI for a purpose at all, how much risk the organisation will accept, and what it will not do. A committee takes the exceptions and the risk acceptances against that appetite; the gates in the pipeline enforce everything else.
-
What should we see in the board pack?
One page generated by a query, not assembled by hand: registry coverage, gate coverage, open exceptions by age, incidents and time to contain, and realised risk reduction, with anything outside appetite flagged for a decision.
-
What does the law already expect of us?
In the EU, the AI literacy provision (Art. 4) and the prohibited practices (Art. 5) already apply, with two new prohibitions from 2 Dec 2026; the Annex III high-risk obligations apply from 2 Dec 2027 12. Data protection, consumer, equality and product-liability law apply to AI today.
Your route through the site.
In reading order: chapters at the section that matters, then the patterns, tools, templates, datasets and figures that turn them into work.
Understand
Decide
- Strategy, value and whether to use AI at all Chapter 12 · The use-case decision, taken before any model is chosen.
- The committee and its charter Chapter 12 · Authority, membership, escalation, and what stays out of the committee.
- Committee charter template Template · Authority, quorum, inputs and outputs, each decision a signed record.
- AI policy template Template · One source for the policy people approve and the rules a pipeline runs.
- Risk appetite, compiled into gates Chapter 13 · An appetite statement the pipeline can enforce.
Oversee
- KPIs and KRIs for the board Chapter 12 · The indicators to ask for, and the one that matters most.
- The maturity grid Figure · Where a governance function stands, layer by layer.
- Maturity self-check Tool · Ask the team to score the layers and show you the floor.
- Who enforces, and the ceilings Figure · Who enforces, and the fine ceilings.
- Incident cases Reference · What failed elsewhere, and which control would have caught it.
Start this week.
- Ask for the inventory: every AI system in use, with an owner. If it cannot be produced, that is the first finding. AI system register entry
- Name one accountable executive and charter the committee that takes exceptions. Committee charter template
- Approve a risk-appetite statement that can be compiled into gate thresholds. Risk appetite, compiled into gates
- Put six to eight indicators, generated from live systems, on the next board agenda. KPIs and KRIs for the board
- Ask which of the next three EU AI Act dates touch your products and services. What applies now
The obligations that matter most.
The duties that land on the organisation as a whole: literacy, prohibitions, classification, the quality management system, deployer duties, and the policy and accountability controls of the management-system standards.
| Obligation | Applies | Evidence |
|---|---|---|
| EU AI Act Art. 4 AI literacy AIGE-OBL-EUAIA-ART4 | In force · | Literacy programme as code; role-based training records; onboarding gates |
| EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) AIGE-OBL-EUAIA-ART5 | In force · | Policy-as-code blocklist; input/output guardrails; refusal and abuse detection |
| EU AI Act Art. 6 classification of high-risk AI systems (incl. the Annex III route) AIGE-OBL-EUAIA-ART6 | Deferred · | Risk-tiering as code; high-risk classification decision record; register entry flagging Annex III status |
| EU AI Act Art. 17 quality management system AIGE-OBL-EUAIA-ART17 | Deferred · | QMS-as-code; versioned policies; pipeline controls and change management |
| EU AI Act Art. 26 deployer obligations for high-risk systems AIGE-OBL-EUAIA-ART26 | Deferred · | Deployment registry; monitoring hooks; assigned oversight and logging retention |
| ISO 42001 · A.2 Policies related to AI AIGE-OBL-ISO42001-A2 | Voluntary | Policy-as-code library; versioned policy repository |
| ISO 42001 · A.3 Internal organization AIGE-OBL-ISO42001-A3 | Voluntary | Operating model; RACI; ownership in the registry |
| NIST AI RMF · GOVERN AIGE-OBL-NISTRMF-GOVERN | Voluntary | Policy-as-code; operating model; registry ownership |
Sources
- [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Art. 4 AI literacy, Art. 5 prohibited practices, Art. 113 application dates). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
- [2] Regulation (EU) 2026/1744 (Digital Omnibus on AI) (Art. 5(1)(ba) and (bb) prohibitions from 2 December 2026; Annex III high-risk obligations from 2 December 2027). Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)
Other routes.
- For engineers ML, platform, MLOps, application and security engineers who build and run AI systems.
- For CISOs and risk leads CISOs, heads of risk, model risk managers, internal audit and third-party risk managers.
- For legal counsel and DPOs In-house counsel, data protection officers, privacy and compliance leads, and contract managers.
- For the public sector Public bodies and operators of public services: CIOs, service owners, procurement and oversight.
- For SMEs and start-ups Small and medium-sized companies and start-ups, most of them buying more AI than they build.
- AIGP candidates The public AIGP body of knowledge read against this site. Not affiliated with or endorsed by IAPP.
- Certifications Certifications and assessments in AI governance, and what each one evidences.
Start at the top of the route.
Step 01 is The Thesis. Each step after it builds on the one before.