AI investment should be assessed through tangible business outcomes rather than adoption statistics. The guide distinguishes between activity—such as pilots, licences, training or experimentation—and value, including improved workflows, time saved, customer experience and operational impact.
This gives boards a more useful set of questions:
A high number of experiments may show interest, but it does not by itself show a return on investment.
Employees often discover useful AI applications before formal programmes are established. The guide encourages boards and management to harness that knowledge while bringing experimentation into the organisation’s control environment.
That means documenting AI-built tools, clarifying who may use them and for what purposes, and checking that they meet applicable safety and governance requirements. The objective is not to eliminate experimentation; it is to prevent useful prototypes from becoming invisible, unsupported systems that affect customers, employees or company data without adequate controls.
AI governance should cover more than model performance. Directors are urged to examine ethical, cyber, data, safety, privacy and talent risks, as well as the effect of AI on resilience and long-term value creation.
The board should therefore know where AI is being used, what data and third parties are involved, who owns each system, how incidents are reported and when a deployment must be paused or reviewed. Risk oversight should be proportionate to the consequences of failure: a low-impact internal productivity tool does not require the same controls as a system influencing employment, customer access or safety.
The guide calls for explicit decision boundaries. Boards should establish where human review is required and identify “hard red lines” where automated decisions are not permitted—particularly when decisions affect customers, employees, safety or privacy.
Human oversight is meaningful only when the reviewer has enough information, authority and time to question or overturn an AI-supported recommendation. A nominal approval step should not become a rubber stamp for an automated outcome.
AI used in hiring, promotion or performance assessment can affect people’s opportunities and livelihoods. The guide recommends human review, bias testing and data-quality checks for these uses, alongside a clear process through which affected individuals can challenge or seek review of a decision.
For boards, this turns fairness from a general principle into an oversight question: what evidence shows that the system is working as intended, what groups may be disadvantaged, and how can a person contest an outcome?
The guide places AI within the broader responsibility of maintaining organisational and digital resilience. Its recommendations reflect growing expectations that boards actively oversee AI-related risks, including cyber threats, rather than assuming that technical teams alone can manage them.
Directors should ask management how AI changes the organisation’s attack surface, how sensitive data is protected, how vendors are assessed and how the company would respond if an AI system were compromised or produced harmful output. The exact controls will vary by organisation, but responsibility for asking the questions remains with the board.
A practical first review can begin with five questions:
The guide’s broader lesson is that responsible AI governance is not a one-time policy exercise. Boards need enough literacy to oversee strategy, enough evidence to judge value and enough authority to impose limits when the risks outweigh the benefits.