For NEDs and audit committees — before the paper is approved

What boards should ask
before AI expands.
Before, not after.

Wider AI adoption usually reaches the board as a confident paper with a compelling upside slide. These six groups of questions test whether it has earned approval.

6
Question groups, asked before the paper is approved
In the meeting
Asked by directors who are not technologists
On the record
Answered for the minutes, not assumed
Pounds
The unit the exposure questions are answered in

Most boards will be asked, at some point this year, to approve a wider AI programme — more systems, more autonomy, more customer-facing exposure. The paper that arrives is usually well made. It describes the opportunity thoroughly, the vendor landscape adequately, and the risk position briefly. What it rarely offers non-executive directors is a structured way to test it.

The moment before sign-off is the one point in the lifecycle where the board holds full leverage. After approval, governance tends to follow the deployment rather than lead it: controls are retrofitted, inventories are reconstructed, and accountability is assigned after the first incident rather than before it. The six question groups below are designed to be asked in the meeting, by directors who are not technologists, and answered on the record.

Inventory — do we know what we are expanding from?

An expansion approval implicitly assumes the baseline is known. In our experience it usually is not. Shadow AI — tools adopted by teams without IT approval — is routinely absent from the register the board is shown. A board that approves expansion against an incomplete inventory is approving an unknown quantity.

  • How was our AI inventory compiled — by self-declaration, or by independent discovery across the cloud estate, SSO directory and SaaS footprint?
  • Does it capture vendor-embedded AI and shadow AI, and when was it last verified?
  • Who is accountable for keeping it current once the expansion is live?

If executives cannot answer the first question precisely, the honest response to the paper is not yet. Our Lab’s shadow AI research explains why self-declared inventories consistently undercount.

Accountability — who answers for each system?

For FCA- and PRA-regulated firms, the Senior Managers and Certification Regime already sets the expectation: material risks map to named individuals, not committees. AI should be treated no differently. The test is not whether an AI policy exists, but whether a specific senior person would stand behind each material system in front of a regulator.

  • Is there a named senior owner for every material AI system, and do they understand it well enough to explain its failure modes?
  • How does accountability transfer when a vendor retrains or replaces the underlying model?
  • Where does responsibility sit for systems we deploy but did not build?

Exposure — what is the downside in pounds?

Risk registers coloured red, amber and green do not support a capital allocation decision. Before approving expansion, the board should see downside quantified in monetary terms — regulatory penalty ranges, remediation cost, operational disruption, customer redress — alongside the projected benefit, on stated assumptions that someone independent has tested. If the upside is modelled in pounds and the risk is modelled in adjectives, the paper is not balanced.

  • What is the quantified monetary exposure of the current estate, and how does the proposed expansion change it?
  • What assumptions drive the benefit case, and who validated them independently of the team proposing the spend?
  • Which single system carries the largest exposure — and would we still approve if that figure doubled?

This is the discipline the Sentinel engagement was built around: translating every risk score into a monetary figure a CFO can take to an investment committee.

Classification — where does each system sit in the rulebooks?

The regulatory position of an AI system is not a matter of opinion. The EU AI Act — which reaches UK firms with EU clients, EU operations or EU-built systems — assigns explicit risk tiers, with the heaviest obligations falling on high-risk uses such as credit scoring and employment decisions. The ICO’s expectations on automated decision-making under UK data protection law apply regardless of Brussels. And sector regulators — FCA, PRA, SRA, CQC — each read AI through their existing rulebooks rather than waiting for a new one.

  • Which of our systems would be classified high-risk under the EU AI Act, and who made that determination?
  • Are we anchoring to ISO 42001 or the NIST AI RMF — and how far along are we in practice, rather than in intention?
  • Who monitors reclassification risk as guidance evolves?

Oversight — how will we know it is working after we say yes?

Approval is the beginning of the board’s exposure, not the end of its involvement. Oversight design should be settled before deployment: what management information reaches the board, at what frequency, and who acts when a system drifts. The phrase human in the loop deserves particular scrutiny — a reviewer who approves hundreds of outputs a day is a formality, not a control, and agentic systems that act autonomously stretch the assumption further still.

  • What AI-specific management information will this board see, how often, and who owns its accuracy?
  • Is human oversight genuinely capable of intervening — with the time, expertise and authority to overrule the system?
  • How is performance drift detected and escalated between reporting cycles?

Point-in-time assurance decays. Continuous monitoring — the role Citadel plays after a Sentinel engagement closes — exists because the answer to these questions changes month by month.

Exit criteria — what would make us stop?

The least-asked question is the most revealing. A well-governed expansion defines, before deployment, the conditions under which a system is paused, rolled back or retired — and confirms that stopping is actually possible. Vendor lock-in, data entanglement and customer dependency can make an exit theoretical. If nobody in the room can describe the off switch, the board is approving a commitment, not an experiment.

  • What predefined thresholds — error rates, complaint volumes, regulatory contact — trigger suspension?
  • Who holds the authority to halt a system without waiting for a board cycle?
  • Can we demonstrably switch off or substitute each material system, and at what cost?

How to use these questions

None of this is adversarial. A management team that can answer these questions has done the work, and the paper deserves approval. A management team that cannot has been given a precise, non-confrontational description of what remains to be done before it returns. Either way, the minutes will show that expansion was approved on evidence rather than enthusiasm.

EAIC runs board and executive briefings built around exactly this conversation, and the Sentinel engagement produces the inventory, monetary exposure model and classification evidence the questions assume — fixed fee, starting with a one-day diagnostic. A board that asks these questions before approval rarely has to answer harder ones afterwards.

Bring us the question you can’t get answered.

Thirty minutes with a founder. No sales deck, no obligation.

Price agreed before we start · Founder-led