MEMO · TO directors and board committees · RE 23 checks on AI oversight

Free tool · For boards

Could this board answer for an AI incident tomorrow?

23 checks across six areas of board-level oversight: who owns AI risk, what requires sign-off, who checks the output, what you would actually be told, what you are exposed to, and whether the board is equipped to do the job. The score updates as you go. No email required, and nothing you enter leaves your browser.

The question is disclosure, not perfection

Boards rarely fail this because nobody cares about AI risk. They fail it because oversight was never converted into named ownership, an agreed reporting cadence and a threshold for what gets escalated, so the first real test arrives during an incident rather than before one.

The checks below are written to be answerable, not aspirational. Each one is either evidenced today or it is not, and every unchecked item is a specific thing a regulator, an auditor or a journalist could ask about.

Exhibit · The gap this checklist measures

Most boards are being asked to govern something they have not used.

  • 66%

    of boards report minimal hands-on AI experience

  • 55%

    of board members think a fellow board member should be replaced for not knowing enough about AI

Deloitte, Governance of AI: A Critical Imperative for Today's Boards · PwC, Annual Corporate Directors Survey (2025)

  1. Section 1 of 6

    Who Actually Owns AI Risk

    0 / 5

    Decision rule

    If no single named executive reports AI risk directly to this committee, nothing else in this checklist has an owner yet.

  2. Section 2 of 6

    What Requires Sign-Off, and From Whom

    0 / 4

    Decision rule

    This is where accountability turns into money. If vendor contracts never required board sign- off, oversight is advisory rather than real.

  3. Section 3 of 6

    Who Checks the Output, and What Happens When It’s Wrong

    0 / 4

    Decision rule

    This is the section a regulator or journalist tests first. A generic 'human in the loop' policy is not the same as a named reviewer.

  4. Section 4 of 6

    What You Would Actually Be Told

    0 / 3

    Decision rule

    The test here is disclosure, not perfection. A board that has to ask about incidents first does not have real oversight of them.

  5. Section 5 of 6

    What You Are Actually Exposed To

    0 / 3

    Decision rule

    Know which frameworks apply before a regulator tells you. This section maps exposure; it does not replace a compliance review.

  6. Section 6 of 6

    Whether the Board Can Actually Do Its Job

    0 / 4

    Decision rule

    This section tests the board itself, not management. If AI oversight is not a standing agenda item, it is not yet oversight.

Where this leads

The half-day course runs this in the room, on your own use case

AI Governance & Board Readiness takes the same questions and works them through a real use case your team brings in, ending with a scored readiness baseline, a three-level delegation map and a governance checklist built for that organisation rather than for organisations in general.

Dr. Jayarethanam Pillai

Before you go

I insisted on the no-email condition, over some internal objection, because a lead-generation form dressed up as a diagnostic is a small dishonesty I did not want attached to a practice with my name on it. These tools score you honestly and tell you where the gap sits, whether or not you ever speak to us afterward. That is closer to how I think a genuine assessment should behave, in a classroom or a boardroom. If the result tells you your organisation is not ready, believe it before you believe anything a vendor tells you next.

Signature, Jayarethanam Pillai