A decade ago, cybersecurity leaders reported two or three levels below the board. Today, AI governance is similarly scattered across data science teams and business units without a single owner. You don't have a decade to fix this.
This checklist translates lessons from cyber governance maturity into actionable AI oversight steps. Use it to establish board-level AI governance before your organization appears in an 8-K filing naming shadow AI as a material event contributor.
Prerequisites
Before starting this checklist, confirm:
- Your board has designated AI governance as a standing agenda item.
- You've identified which executive owns enterprise-wide AI accountability.
- You have access to procurement records, vendor contracts, and employee productivity tool logs.
If you can't confirm all three, pause and address these gaps first. Governance without ownership produces documentation, not protection.
AI Governance Readiness Checklist
1. Establish Complete AI Asset Visibility
Done when: You maintain a live inventory of every AI application operating in your organization, including sanctioned tools, vendor-embedded AI, and employee-adopted solutions.
Requirement reference: This mirrors the asset management principle in COSO ERM Framework Component 1 (Governance and Culture), which requires organizations to identify all sources of material risk.
What good looks like: Your inventory captures not just the AI tools your procurement team approved, but also the AI features your SaaS vendors added in their latest updates and the generative AI tools your marketing team started using last month. You can answer "where does AI touch customer data?" in under five minutes.
Common failure: Limiting your inventory to IT-approved applications while ignoring shadow AI introduced through vendor updates or departmental workarounds.
2. Map AI Risk to Business Impact
Done when: Every identified AI application links to a specific business process, data classification, and potential failure mode expressed in operational terms (revenue loss, regulatory exposure, reputational damage).
Requirement reference: UK Corporate Governance Code Provision 28 requires boards to establish procedures to manage risk, which necessitates understanding how emerging risks translate to business consequences.
What good looks like: When your CFO asks about AI risk exposure, you present scenarios like "AI-driven credit decisions could misclassify 3% of applications, creating fair lending liability" rather than "our models might have bias issues."
Common failure: Cataloging AI tools without connecting them to the business processes they affect or the decisions they inform.
3. Assign Single-Point Accountability
Done when: One named executive owns enterprise AI governance, reports directly to the CEO or board, and has authority to halt AI deployments that fail control standards.
Requirement reference: This reflects the accountability structure that emerged from cyber governance maturation, where diffused responsibility led to systematic underinvestment until a single executive owned the entire risk portfolio.
What good looks like: Your AI governance owner can answer questions about any AI application in any department, has budget authority for enterprise-wide controls, and sits in strategic planning meetings where new AI initiatives get proposed.
Common failure: Splitting AI governance between your CTO (technical risk), Chief Data Officer (data quality), and business unit leaders (deployment decisions) with no single decision-maker.
4. Translate Technical Risk to Financial Terms
Done when: Your board receives AI risk updates quantified in monetary terms, showing potential loss ranges for identified exposures and the cost-benefit analysis of proposed controls.
Requirement reference: COSO ERM Framework Component 3 (Performance) requires organizations to prioritize risks based on severity, which demands financial translation to enable comparison across risk categories.
What good looks like: Your board paper states "uncontrolled AI in customer service creates £2-8M annual exposure from regulatory fines and customer remediation" rather than "our chatbot lacks sufficient guardrails."
Common failure: Presenting AI risk in technical language (model drift, hallucination rates, training data gaps) that boards cannot weigh against other capital allocation decisions.
5. Conduct Targeted Control Assessments
Done when: You've evaluated each material AI application against defined control standards covering data quality, model validation, human oversight, and incident response.
Requirement reference: This applies the same control assessment discipline that matured in cybersecurity governance, where point-in-time reviews identified gaps before incidents exploited them.
What good looks like: You can demonstrate which AI applications meet your control standards, which carry accepted risk with board approval, and which require remediation before continued operation.
Common failure: Assuming vendor-provided AI comes with adequate controls, or applying generic IT controls to AI-specific risks like model drift and training data poisoning.
6. Establish Board-Level Reporting Cadence
Done when: Your board receives quarterly AI governance updates covering new deployments, control assessment findings, incident trends, and emerging regulatory requirements.
Requirement reference: UK Corporate Governance Code Provision 29 requires the board to monitor the company's risk management and internal control systems, which extends to AI as a material risk source.
What good looks like: Your board can articulate your organization's top three AI risks, knows which business units carry the highest AI exposure, and has approved risk appetite statements for AI deployment in customer-facing and regulated processes.
Common failure: Providing AI updates only when the board asks, or limiting updates to innovation showcases that highlight benefits without corresponding risk disclosure.
Common Mistakes That Delay Maturity
Waiting for regulatory clarity: Organizations that delayed cyber governance until regulations mandated it spent more on remediation than those who built controls proactively. AI regulation is emerging now; your governance shouldn't wait for enforcement.
Treating AI governance as a compliance project: Compliance checklists address minimum standards. Governance addresses strategic risk. If your AI governance program lives in your compliance function rather than enterprise risk, you're solving the wrong problem.
Assuming technical teams will escalate risks: Data scientists and ML engineers optimize for model performance, not enterprise risk. Without explicit escalation protocols and business impact translation, technical teams won't surface board-level concerns until after deployment.
Next Steps
Complete items 1-3 within 30 days. These establish the foundation: you can't govern what you can't see, and you can't manage what nobody owns.
Complete items 4-6 within 90 days. These enable board oversight: quantified risk, evaluated controls, and structured reporting.
The window to establish AI governance before a material event forces the issue is narrower than it was for cyber. A recent SEC 8-K filing from CB Financial Services already named shadow AI as a contributing factor in a material event. Your organization's filing doesn't need to be the second.



