Your board asks about AI governance. Usually it goes like this.
“Do we have an AI governance framework?” Yes. “Do we have oversight?” Yes. “Are we compliant with regulations?” As far as we know. “Any board members have concerns?” No. “Great, let’s move on.”
Twelve minutes from start to finish.
This is not a board conversation about AI governance. This is a checkbox conversation. It checks a box and moves on.
The real board conversation about AI governance is much longer, much more uncomfortable, and much more important. And almost nobody is having it.
What Boards Actually Ask (The Checkbox Version)
Boards ask the questions they know to ask because they’ve asked similar questions about other technologies:
“Do we have policies?” Yes. “Are they documented?” Yes. “Who’s accountable?” The CIO. “Is there oversight?” Yes, there’s a committee. “Do we audit?” Once a year.
These are the questions they ask about data governance, about cybersecurity policy, about compliance frameworks. They’re good questions for those domains.
They’re not sufficient for AI.
What Boards Should Actually Ask
Here’s what a rigorous board conversation looks like:
“Walk me through a model that went wrong. How did we catch it? What did we do? What did we learn?”
This question reveals everything. If your board hasn’t actually had this conversation with a real example, they don’t yet understand your AI risk posture.
The right answer to this question looks like: “We had a model that was drifting on customer segment X. Our monitoring caught it after two weeks. We retraining the model. It’s back in production. Here’s what we learned about this class of problems and how we changed our monitoring to catch them faster.”
The wrong answer looks like: “We haven’t had a model go wrong yet,” or “It would take a while to trace back through what happened,” or “We’re not sure.”
“How do you know that all the models in production are actually the models you think are in production?”
This is a question about operational reality. You have one hundred models supposedly deployed. Do you actually know what fifty of them do? Do you know who owns them? Do you know if they’re still running, or if they were shut down months ago and nobody told you?
Many organizations don’t. They have “shadow models” running in production that nobody’s officially monitoring, serving traffic that nobody’s officially tracking.
“What happens when a model makes a decision that seems wrong? Who investigates? How long does it take? What’s the process?”
This is about operational readiness. Do you have the infrastructure and the team to actually investigate a model problem in hours, or does it take days or weeks?
Most organizations don’t have this process. So problems propagate for longer than they should.
“Tell me about the largest financial exposure if a model failed. Walk me through the scenario.”
This is about risk quantification. You need to be able to articulate: “If this model failed silently and we didn’t catch it for three weeks, the financial impact would be $50 million.” Or $5 million. Or $500K. But you should know.
If you don’t know, you don’t understand your risk. And if you don’t understand your risk, you’re not managing it.
“Across all our models, how much are we spending and where does that money go?”
This is about economic visibility. You know your total AI spend. But do you know: $50 million on compute, $30 million on people, $10 million on data, $5 million on monitoring? Do you know which models account for which costs?
If not, you’re making resource decisions without the information you need.
“If a vendor raised prices 50%, what models could we move to an alternative vendor within 60 days?”
This is about strategic flexibility. It’s a stress test for lock-in. This applies to evaluating any vendor partnership, internal or external. The honest answer for most organizations is: “Zero. We’d be stuck.”
The answer you should be able to give is: “We could move models A, C, and F within 60 days because they’re architected for portability. Models B, D, and E are more tightly integrated with the vendor; those would take six months.”
“Walk me through how you’d shut down this organization’s entire AI operation in 60 days and tell me what would be hard.”
This is a scenario planning question. If you had to divest the AI business, or if you lost a key vendor, or if there was a major regulatory change, what would you do?
Most organizations haven’t thought through this scenario. When they do, they discover that their AI operation is fragile in ways they didn’t realize.
Why Boards Don’t Ask These Questions
Most boards don’t ask these questions for a few reasons:
-
Comfortable questions are easier. Asking whether you have policies documented is a comfortable question. Asking whether you actually understand your largest risk is uncomfortable.
-
AI expertise is rare on boards. The board understands cybersecurity because they’ve been dealing with it for ten years. They don’t understand AI, so they default to “do we have a framework.”
-
The executives would rather not be asked. If the CEO or CIO knows they don’t have good answers to these questions, they don’t want the board asking them. So the board doesn’t ask.
-
Boards haven’t calibrated what good governance looks like. They don’t know if “we have a governance committee” is sufficient. So they default to “well, we have a governance committee, so we’re fine.”
What Changes When Boards Start Asking
When boards start asking rigorous questions about AI governance, a few things happen:
-
Problems become visible faster. The conversation forces executives to acknowledge what they don’t know. What you acknowledge, you can fix.
-
Resources get allocated to the right places. Right now, organizations are often underfunding monitoring and ops, because they don’t have visibility into why it matters. Rigorous questions reveal the importance.
-
Executive focus shifts. When the board is asking about largest risk exposure and operational readiness, the executive team starts thinking about largest risk exposure and operational readiness instead of just model accuracy.
-
Accountability becomes real. If the CEO commits to the board that “we have process to catch model failures within 48 hours,” they’ll make sure that process exists. Without that commitment, it doesn’t.
Why This Matters
AI governance is not about having policies. It’s about whether you actually understand your risks and whether you have the operational maturity to manage them.
Boards are the forcing function that creates real governance. Executives will invest in operational maturity if the board is asking about it. Without board pressure, governance remains theater.
The conversation shouldn’t take twelve minutes. It should take an hour. And it should make someone uncomfortable. If it doesn’t, you’re not asking the right questions.