
Five questions a board should ask before approving enterprise AI.
Boards do not need to become model engineers. They do need decision-grade evidence about value, accountability, information, risk, and adoption.
The decision
Responsible AI governance is a system of owned decisions—not a policy document waiting for someone to read it.
What outcome earns the investment?
Tie the use case to a material decision, workflow, customer outcome, risk, or capability. Activity, licenses, and demonstrations are not benefits.
Who remains accountable?
Name the human owner, approval point, monitoring responsibility, fallback path, and authority to stop the system.
- Decision owner
- Information owner
- Risk and control owner
- Adoption owner
Is the information fit for this use?
Identify the information the system will use, who owns it, whether it is accurate and permitted, and how access, retention, lineage, privacy, and security will be controlled. A capable model cannot repair weak information governance.
How will people adopt, challenge, and override it?
Define the roles affected, the capability they need, how users will question outputs, when human review is mandatory, and how exceptions or harm will be escalated. Adoption and oversight are operating requirements, not communications tasks.
What evidence permits scale?
Require a baseline, success and stop criteria, evaluation results, control evidence, user adoption, and an explicit scale decision. A pilot should reduce uncertainty—not manufacture enthusiasm.
- Measured benefit against the baseline
- Evaluation across normal and adverse conditions
- Control performance and unresolved risk
- A named scale, change, pause, or stop decision
