# What should a board ask about AI? Questions for directors.

> In this field note, veridive sets out what a board should ask about AI. Directors need a register of systems in production with named owners, the decisions each can influence, quality and cost against thresholds, and the last incident. It offers eight questions, a one-page report outline, escalation triggers and what to leave with management.

Boards don’t need model details. They need a register of AI systems in production with named owners, the decisions each one can influence, how quality and cost are measured, and what happened in the last incident.

## Key takeaways

- Ask for a register of AI systems in production, each with a named owner and the decisions it can influence.
- Report quality against thresholds, cost against a ceiling and every incident on one page each quarter.
- Keep experimentation budgets separate from systems in production, so each is judged by the right standard.
- Directors ask the questions and set the appetite for risk; model choices stay with management, and legal duties are for counsel.

The board pack has a slide on AI: a list of pilots, a vendor logo or two, and a line about “exploring generative AI responsibly”. A director asks which of these systems decides anything about customers. Nobody in the room is sure.

Boards don’t need model details. They need a register of AI systems in production with named owners, the decisions each one can influence, how quality and cost are measured, and what happened in the last incident. What directors’ legal duties require is a matter for counsel; what follows are questions, not legal advice.

## Why should a board look at AI differently from other IT?

Because an AI system can change without anyone releasing anything. A provider updates a model, a policy document is replaced, the mix of cases shifts, and quality moves while the software stays the same. AI systems also act at scale, so one flaw can repeat across thousands of cases before anyone notices, and their costs grow with use. Staff may also use unapproved tools that no register shows, so ask how management knows what is actually in use.

The board’s interest is therefore not the technology. It is which decisions these systems touch, who answers for them, and how management would know if one went wrong. Directors don’t need to become technologists, but someone on the board should be comfortable asking the follow-up question: measured how? A short [glossary of the terms that matter](https://veridive.com/insights/ai-glossary-for-business-teams/) helps.

## What should management report, and how often?

One page each quarter, plus an alert between meetings when an agreed trigger fires. The page covers the register of systems in production, their owners, quality against thresholds, cost against a ceiling, incidents and planned changes.

Experiments go on a separate line with their own budget. They should be free to fail cheaply, while production systems are held to thresholds; mixed together, the page hides both.

Take an illustrative report for a company with three systems in production:

| System · owner | Decisions it can influence | Quality vs threshold | Cost vs ceiling |
|---|---|---|---|
| Returns recommendations · head of service | Refund or replace, confirmed by a person | Above; one case type under review | Within |
| Invoice drafting · financial controller | ERP entries, approved by accountants | Above | Within; month-end near the alert |
| Policy assistant · HR director | None directly; answers staff with sources | Above, after a fix | Within |

Beneath it: one incident, in which the policy assistant cited a superseded overtime rule, the source was withdrawn, affected answers were reviewed and a test was added. Planned: a provider model update for invoice drafting, tested on the evaluation set first. Experiments: two, within budget.

## Which questions should directors ask?

Eight questions cover most of it. Each comes with what a good answer sounds like.

1. **Which AI systems influence decisions about customers, money or people, and who owns each one?** A good answer is a register with names; “IT owns it” is not.
2. **Where does a person approve, and what happens without one?** Approval points listed per system, and any unattended action reversible and limited, as in [guardrails agreed before launch](https://veridive.com/approach/#guardrails).
3. **How do we know each system still works?** Thresholds agreed at acceptance, re-checked after every model or data change, with a sample reviewed by people.
4. **What does each cost to run, against what ceiling?** Cost per task, a monthly ceiling and alerts before it.
5. **What happened in the last incident, and what changed?** A specific account rebuilt from the [audit trail](https://veridive.com/insights/ai-audit-trail/), a fix and a new test. “No incidents”, with no way to know, is a worrying answer.
6. **What data does each system use, and where is it processed?** Mapped, and reviewed by the data protection officer.
7. **Which suppliers and models sit underneath, and what if one changes or leaves?** Notice terms, an evaluation set to test alternatives and an exit plan.
8. **What has each system delivered against its baseline?** Measured results that separate capacity from cash, as in [measuring AI ROI](https://veridive.com/insights/how-to-measure-ai-roi/).

## How should a board judge value claims?

Ask three things of any claim: compared with what baseline, measured how, and turned into what? Hours saved are capacity until a budget line moves. Be skeptical of usage figures, vendor benchmarks and averages across all cases. And ask what was stopped: a portfolio in which nothing has ever been stopped is not being judged. A good value report fits on the same page as the register: each system’s result against its baseline, in the business’s own units, with its running cost beside it.

> Boards don’t need model details. They need owners, thresholds and the story of the last incident.

## What should trigger escalation to the board?

Agree the triggers in advance, so escalation is automatic rather than a judgment made under pressure:

- an incident that reached customers, money or people at scale;
- a system below its quality threshold for longer than agreed;
- spend above the ceiling;
- a regulator’s inquiry or a formal complaint;
- a plan to let a system decide about customers, money or people without a person;
- a key supplier leaving, or changing the terms under which it processes your data.

Which events the law requires you to report, and to whom, is a question for counsel.

## What should stay with management?

Model and vendor choices within policy, prompts, architecture, daily monitoring and experiments within their budget. The board sets the appetite for risk and asks the questions; management runs the systems and answers them. Those choices still reach the board, but as effects on the one-page report rather than as decisions to approve. Monitoring, cost control and runbooks are the work of [AI reliability](https://veridive.com/services/ai-reliability/), and deciding which systems belong in production at all starts with [AI strategy and discovery](https://veridive.com/services/ai-strategy/).

## Frequently asked questions

### What questions should a board ask about AI?

Start with which AI systems influence decisions about customers, money or people, and who owns each one. Then ask where a person approves, how quality and cost are measured against agreed thresholds, what happened in the last incident, where the data goes, what happens if a supplier changes its model, and what value each system has delivered against its baseline.

### What should an AI report to the board include?

One page each quarter: a register of AI systems in production with their owners and the decisions each can influence, quality against agreed thresholds, running cost against a ceiling, incidents and what changed afterwards, and planned changes such as new systems or model updates. Experiments are reported separately, against their own budget.

## Sources

1. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. National Institute of Standards and Technology (NIST). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
2. ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system. International Organization for Standardization (ISO). https://www.iso.org/standard/42001
3. OECD AI Principles. OECD. https://oecd.ai/en/ai-principles
