Quentin CasaresData and AI leadership for regulated growth

Free board resource · August 2026 edition

AI governance board checklist

Twelve tests for whether accountability, evidence, human control, suppliers, monitoring, and board oversight work in operating reality. Complete it with the accountable executive and record the evidence beside each answer.

Score each item: Yes = 2, Partial = 1, No = 0. A high total never overrides a material uncontrolled use case.

Current context

The regulatory clock has moved.

The EU AI Act entered general application on 2 August 2026. Transparency obligations now apply; high-risk rules for Annex III use cases apply from 2 December 2027 and rules for systems embedded in regulated products apply from 2 August 2028.

The FCA continues to use an outcomes- and principles-based approach through existing frameworks, including accountability and governance, Consumer Duty, and the Senior Managers and Certification Regime.

The joint Bank of England and FCA survey found 75% of respondent firms using AI and 84% with a person accountable for AI, but only 34% reporting complete understanding of the AI they use.

  1. 01

    One AI inventory

    Internally built, third-party, embedded, experimental, and retired use cases are held in one register.

    Evidence: Owner, provider, purpose, users, data, status, and review date.

    Score for One AI inventory

    Evidence reference / owner / action: ______________________________________________

  2. 02

    Named executive accountability

    A senior executive is accountable for AI governance outcomes through an explicit board reporting route.

    Evidence: Role mandate, committee charter, delegated authority, and reporting line.

    Score for Named executive accountability

    Evidence reference / owner / action: ______________________________________________

  3. 03

    Consistent materiality

    Use cases are classified using customer, regulatory, autonomy, data, and reversibility criteria.

    Evidence: Classification standard, completed assessment, and rationale.

    Score for Consistent materiality

    Evidence reference / owner / action: ______________________________________________

  4. 04

    Usable decision rights

    The organisation knows who may approve, challenge, deploy, change, pause, and retire each class of use case.

    Evidence: Decision-rights matrix linked to materiality thresholds.

    Score for Usable decision rights

    Evidence reference / owner / action: ______________________________________________

  5. 05

    Data and supplier evidence

    Material use cases document data provenance, permissions, quality limits, supplier dependencies, and exit options.

    Evidence: Lineage, impact assessment, supplier review, contract controls, and exit plan.

    Score for Data and supplier evidence

    Evidence reference / owner / action: ______________________________________________

  6. 06

    Evaluation before release

    Acceptance criteria test business performance, reliability, fairness, and foreseeable failure modes before deployment.

    Evidence: Evaluation plan, results, approval record, and residual-risk decision.

    Score for Evaluation before release

    Evidence reference / owner / action: ______________________________________________

  7. 07

    Meaningful human control

    Human reviewers have the authority, information, competence, and time needed to challenge material outputs.

    Evidence: Operating procedure, override data, training, and escalation route.

    Score for Meaningful human control

    Evidence reference / owner / action: ______________________________________________

  8. 08

    Transparency and redress

    People are told when AI materially affects them and can reach a competent human to challenge an outcome.

    Evidence: Notices, explanation template, appeals process, and complaints MI.

    Score for Transparency and redress

    Evidence reference / owner / action: ______________________________________________

  9. 09

    Monitoring and traceability

    Material use cases are monitored and the organisation can reconstruct versions, outputs, interventions, and decisions.

    Evidence: Dashboard, thresholds, logs, retention standard, and review minutes.

    Score for Monitoring and traceability

    Evidence reference / owner / action: ______________________________________________

  10. 10

    Resilience and incidents

    Continuity, recovery, escalation, notification, and lessons learned cover material AI use cases.

    Evidence: Fallback process, incident playbook, exercise results, and lessons log.

    Score for Resilience and incidents

    Evidence reference / owner / action: ______________________________________________

  11. 11

    Role-based AI literacy

    Directors, senior managers, developers, reviewers, procurement, risk teams, and users receive proportionate training.

    Evidence: Curriculum, completion records, competence checks, and refresh cycle.

    Score for Role-based AI literacy

    Evidence reference / owner / action: ______________________________________________

  12. 12

    Board-level AI MI

    The board sees material use cases, ownership, risk, exceptions, incidents, benefits, control health, and decisions required.

    Evidence: Board pack, thresholds, trends, decisions, and recorded challenge.

    Score for Board-level AI MI

    Evidence reference / owner / action: ______________________________________________

Interpret the total

19-24
Established
Controls are broadly present. Test evidence quality, exceptions, and whether the board sees leading indicators.
12-18
Inconsistent
The model exists in parts but may not behave consistently under pressure. Prioritise the weakest controls.
0-11
Exposed
Start with inventory, accountable ownership, materiality, decision rights, human control, and minimum evidence.

Red-flag overrides

  • No inventory of material AI use cases.
  • No named executive accountable for AI governance outcomes.
  • High-impact decisions lack meaningful human control.
  • Third-party models lack proportionate due diligence and exit planning.
  • No tested AI incident and escalation process.