Summary

Boards now sign off on AI risk months before they can evaluate the stack underneath it. A typical mid-cap board hears a 40-slide update once a quarter, approves a budget that jumped from 2 to 9 percent of tech spend, and cannot tell whether that money is compounding into capability or evaporating into stranded pilots. Under-governance invites the incidents that reach regulators, over-governance freezes programs that only pay back when they ship. This brief gives directors twelve questions across portfolio, risk, people, and compounding. Asked quarterly, they raise the quality of answers without forcing the board to legislate technical detail.

Context

Why boards struggle to govern AI

Directors carry accountability for AI risk that lands months before they can evaluate the stack underneath it. A typical mid-cap board hears a 40-slide AI update once a quarter, approves a budget line that grew from 2 percent to 9 percent of technology spend in two years, and has no reliable way to tell whether that money is compounding into capability or evaporating into stranded pilots. The failure modes sit on both sides. Under-governance invites the incidents that reach regulators and headlines. Over-governance freezes programs that only pay back when they ship and iterate. Most boards oscillate between the two, tightening after a scare and loosening once the noise fades, which leaves the program governed by mood rather than by method.

The way out is not more oversight. It is a small, fixed set of questions asked on a standing cadence. When a board commits to the same twelve questions every quarter, management reshapes the program to answer them, and the quality of the answers rises within two cycles. The discipline of preparation does the governing. A director does not need to understand retrieval architecture to ask who owns the platform, what a workload costs per task, or what was reused this quarter. Those questions are answerable in plain business language, and the act of preparing honest answers forces the organization toward measurable, owned, and reusable AI work. That is the entire mechanism: the questions are the control.

The framework

Twelve questions in four groups

Group the twelve questions into portfolio, risk, people, and compounding. Each group fits one segment of a board meeting and maps to a specific set of evidence management should already hold. Portfolio asks what the program is doing and where the value is. Risk asks how the program is bounded. People asks who is accountable. Compounding asks whether the program is building an asset or funding a habit. If management cannot produce the underlying artifact for a question, that gap is itself the finding, and it is usually more informative than any answer would have been. The table below pairs each group with its lead question, the artifact that proves the answer is real rather than aspirational, and the red flag a director should listen for.

GroupLead questionEvidence that proves itRed flag
PortfolioWhich three use cases create the most enterprise value this quarter?Ranked value case with baseline and measured liftRanking by enthusiasm, no baseline
PortfolioWhat is the honest unit cost of the most-used workloads?Cost per task across inference, retrieval, evaluation, overrideOnly vendor invoice totals
RiskWhich workloads touch regulated data, and what controls apply?Data-flow map plus control registerNo inventory of regulated flows
RiskWhen was the AI incident runbook last exercised?Dated tabletop with named ownersRunbook exists only as a document
PeopleWho owns the AI platform end to end with budget authority?Named owner, platform KPIs, funded mandateOwnership split across three functions
CompoundingWhat did the team reuse this quarter that was built earlier?Component catalog with reuse countEvery pilot rebuilds its own plumbing

The remaining six questions extend each group. Portfolio adds which pilots were retired and what triggered the decision. Risk adds where a model failure would cause material customer or financial harm and what mitigation stands behind it. People adds where AI has changed how decisions get made and who owns the quality of those decisions, plus which skills gap is being closed this year. Compounding adds which capabilities will be standard across the firm in twelve months, and what a 25 percent increase or decrease in AI investment would buy or cost. Together the twelve give a board a full read on value, boundaries, accountability, and durability in under an hour.

Worked example. A board applied this to a services firm reporting 14 live AI initiatives and a 9 million dollar annual run rate. Management could rank only 4 initiatives by measured value, could name a platform owner for none, and reported that just 2 initiatives reused shared components. The unit-cost question produced only the vendor invoice, with no view of retrieval, evaluation, or override cost. The board retired 5 pilots at the next meeting, appointed a single platform owner with a 3 million dollar mandate, and set a target that 70 percent of new build reuse the shared layer. It also required a dated incident tabletop before any new workload reached production. Two quarters later, reported build cost per use case had fallen by roughly half, the run rate held flat, and live measured value doubled. Nothing in that turnaround required the board to understand a single model; it required them to keep asking the same twelve questions and refuse vague answers.

Recommended actions

Install the brief as standing practice

  • Publish the twelve questions as the board's fixed AI agenda and repeat them verbatim every quarter so trends are comparable across cycles.
  • Require management to arrive with evidence artifacts, not slides: value cases with baselines, cost per task, data-flow maps, and a component catalog.
  • Force a retire-or-scale decision on every pilot each quarter, and record which were killed and why so the portfolio stays honest.
  • Insist on one named platform owner with budget authority and platform-level KPIs before approving further use-case spend.
  • Ask the two compounding questions last, because the honest answers reveal whether the program is an asset or a recurring cost.
Common pitfalls

Where boards lose the thread

  • Accepting spend as a proxy for progress. Fix: tie every budget increase to measured value lift, not activity or headcount.
  • Letting the question set drift each quarter. Fix: freeze the twelve questions so answers form a trend line the board can read.
  • Governing technical detail the board cannot evaluate. Fix: ask for owners, evidence, and decisions, not model architectures.
  • Tolerating orphaned platform ownership. Fix: refuse further scaling approval until one accountable owner is named and funded.
  • Skipping the incident runbook because nothing has failed yet. Fix: require a dated tabletop exercise before the next AI system reaches production.
Quick-win checklist

Before your next board meeting

  • Circulate the twelve questions to management three weeks ahead with a request for evidence, not narrative.
  • Confirm a named platform owner exists with a funded mandate and published KPIs.
  • Obtain cost per task for the three most-used workloads, measured across inference, retrieval, evaluation, and override.
  • Review the list of pilots retired this quarter and the trigger for each decision.
  • Check the date of the last AI incident tabletop and schedule the next one if it is stale.