If your board approved the AI budget, could it also explain the risk?
23 questions across six areas of board-level AI oversight, broken into the 69follow-up probes that decide whether a yes would hold up under scrutiny: ownership, decision rights, human accountability, incident history, regulatory exposure, and whether the board itself is equipped to do this job. Tick every probe you can answer yes to, no email required to see your result.
Listen to this briefing
Stop Confusing AI Paperwork With Governance
Why AI oversight is a board question
Most AI governance material is written for the people building or running the system: the CIO, the data team, the risk function. That is the wrong altitude for a board. A director does not need to understand model architecture. A director needs to know whether the organisation can prove, on request, that a specific person is accountable for a specific AI system's behaviour, and whether that person has been asked the hard question before something goes wrong in public.
The gap this checklist is built to surface is a specific one: the difference between an AI policy existing and AI oversight happening. A signed policy, a governance framework on file, and a slide in the last board pack are not evidence of oversight. Evidence of oversight is a named reviewer, a tested escalation path, and a board that has already asked what the system is not allowed to do, before it did it.
This checklist does not test your organisation's AI maturity. It tests something narrower and more useful to a director: whether this board, specifically, would be able to answer for an AI incident if a regulator, a journalist, or a shareholder asked about it tomorrow.
Not started
Probes answered yes. Questions fully answered, meaning every probe underneath them holds:0 of 23.
Start checking off items below to see where board oversight stands.
This tool produces a self-assessment against your own understanding of board practice. It does not constitute an independent governance audit or legal opinion, and it is not legal, regulatory or compliance advice. The recommended steps below are the starting point for board discussion and do not replace a facilitated review or your own counsel's advice. Your answers stay in your browser and are neither sent to Terence Kok nor reviewed by anyone.
Who Actually Owns AI Risk
0 / 15If no single named executive reports AI risk directly to this committee, nothing else in this checklist has an owner yet.
Does a designated executive (CIO, CAIO, or equivalent) own AI risk and report directly to this committee, rather than through an intermediary layer?
0 / 3What answering yes requires
Has the board agreed how often AI risk is reported, at minimum quarterly, and what that report must contain?
0 / 3What answering yes requires
Does at least one board member have enough AI literacy to ask a substantive follow-up question, not just receive the report?
0 / 3What answering yes requires
Does a documented escalation path exist for AI incidents that names who is notified, and within what timeframe?
0 / 3What answering yes requires
Has a named AI governance committee been formally constituted, with defined membership and a charter, rather than general AI awareness spread across the full board?
0 / 3What answering yes requires
Opens a full report with every question and follow-up probe, your answers, recommended next steps, and your calculated score. Print or save it as a PDF from there.
What boards usually get wrong about AI oversight.
A Policy Is Not Oversight
An AI policy sets direction. It does not prove anyone is checking that the direction is being followed. Boards routinely accept the existence of a policy, a framework, or a certification as evidence that oversight is happening, when none of those things describe what is reviewed, by whom, or how often.
- The organisations that get caught out are rarely the ones with no AI policy. They are the ones whose policy was never tested against a real incident
- "We have a governance framework" and "a named person reviews this system's output every week" are different claims. Only the second is oversight
- A board that cannot name its three largest AI risks has not been shown a risk register. It has been shown a summary
- NACD's 2026 governance research found the share of boards assigning AI to a named committee, rather than leaving it as a standing full-board topic, has roughly quadrupled year over year. A committee with a charter is a different structure from a shared agenda item, and it changes who is accountable when something goes wrong
- Oversight built for conventional AI tools does not automatically transfer to agentic systems that act autonomously across multiple steps. NACD has flagged this as a distinct governance question in its own right
- Treat any unchecked item in Sections 1 or 3 as the priority. Ownership and human oversight are the load-bearing sections
- Ask for evidence, not descriptions, when reviewing management's next AI update
- Re-run this checklist after any AI incident, near-miss, or major vendor change, not just once a year
The Question That Tests It
"What can this AI system do that we would not want it to do?" is a single question that separates real oversight from paperwork. If management can answer it specifically and without hedging, oversight exists. If the answer is reassurance rather than specifics, it likely does not yet.
- A vague answer ("we have guardrails in place") is not a boundary. A specific answer ("it cannot approve a payout above $X without a named reviewer") is
- Boards that ask this question before an incident tend to catch the gap while it is still cheap to close
- Boards that only ask it after an incident are, by definition, asking too late for that particular case
- Put this exact question on the agenda for the next AI update, before the item covering incident history
- Expect a specific boundary as the answer, and treat a general principle as a non-answer
- If no one in the room can answer it precisely, that gap belongs on the risk register today
From Checklist to Standing Agenda Item
This checklist tells you where the gaps are today. It does not replace a facilitated board briefing, an independent review of your specific AI systems, or ongoing oversight as your AI programme evolves. Treat a high score as a good baseline instead of a finished job.
- Boards that treat AI oversight as a one-time review rather than a standing item are routinely surprised by drift: the system in production is no longer the system that was approved
- A single strong score today says nothing about six months from now, once the vendor has shipped a model update or the use case has expanded
- The highest-leverage change most boards can make is simply putting AI oversight on a fixed cadence
- Once you cross roughly 85%, the priority shifts from closing gaps to maintaining cadence
- Assign the unchecked items to a named owner
- If your board wants this run as a facilitated session, that is a conversation worth having directly
About This Checklist
This checklist was built by Terence Kok, a certified ISO/IEC 42001 Lead Auditor (BSI) who has unified AI governance frameworks across three national regulatory environments (Singapore's IMDA among them) under a single standard for an infrastructure group operating across all three. That work sits at exactly the altitude this checklist is written for: not the technical detail of how a model works, but the evidence a board, a regulator, or an auditor asks to see when they test whether oversight is real. The items above are drawn from where that evidence most often turns out to be missing.
See the full certification list →This checklist tests whether the board could answer for an AI incident. To test whether the underlying management system would survive an audit, see theISO 42001 AIMS Readiness Checklist. For a live read on whether specific bias, privacy, and security thresholds are being met day to day, see theAI Trust, Risk & Governance Dashboard. All three cover adjacent ground from a different altitude, and most organisations need more than one.
Want this run as a facilitated board briefing instead?
This checklist tells you where the gaps are. Closing them, or walking your board through the findings directly, is a conversation worth having with me.
Book a private session
Boards keep confusing having an AI policy with overseeing AI, and I built this to test the difference. The one question I've seen do the most work is simple: what can this system do that we would not want it to do. If your board can answer that specifically, you are ahead of most. If not, better to find out here than after an incident makes the answer for you.

