Explain how existing directors' duties extend to decisions involving AI strategy, investment and risk.
AI Oversight Responsibilities for Boards and Non-Executive Directors
Prepare board members and non-executive directors to exercise effective oversight of AI strategy and risk, from setting risk appetite to challenging management on model decisions.
Course Overview
Boards are increasingly expected to oversee AI strategy and risk with the same rigour they apply to financial reporting, yet many non-executive directors have not been given a structured way to exercise that oversight without either rubber-stamping management's plans or attempting to review technical detail they are not equipped to judge. This course sets out how existing directors' duties of care and diligence extend to AI decisions, and gives participants a practical method for building sufficient literacy, structuring board-level governance and setting a risk appetite that management can be held to. Participants work through the specific questions a board should ask on AI strategy, investment, model risk and harm, so oversight moves beyond generic assurance-seeking to informed challenge. The course also covers the regulatory and disclosure obligations a board must track as AI regulation matures, and closes with a simulated AI incident that rehearses the board's escalation and communication role under pressure. Case material draws on realistic governance scenarios so participants leave able to structure, resource and exercise AI oversight that satisfies a regulator, an auditor or a shareholder reviewing board minutes.
Expected Learning Outcomes
Assess the board's AI literacy gaps and commission education that closes them without requiring technical depth.
Design a governance structure and reporting line that gives the board visibility of AI risk and strategy.
Set and monitor a board-approved AI risk appetite with thresholds that trigger escalation.
Formulate incisive questions to challenge management on AI strategy, investment and model risk.
Identify regulatory and disclosure obligations relevant to the organisation's AI use and risk profile.
Rehearse the board's role in an AI incident, including escalation triggers and public disclosure decisions.
Who Should Attend
Non-executive directors serving on boards with active or planned AI investment.
Board chairs and committee chairs designing AI governance structures.
Company secretaries supporting board papers and governance processes for AI oversight.
Chief executives and chief data and AI officers preparing board reporting on AI.
Audit and risk committee members extending their remit to cover AI-related risk.
Aspiring non-executive directors building board-level AI governance credentials.
Course Modules
Select any module to see its sessions and points.
01The Board's Duties and Literacy for AI Oversight
2 sessions · 8 points
Session 1Fiduciary Duties Extended to AI Strategy and Risk
- Explain how existing directors' duties of care, skill and diligence extend to decisions involving AI strategy and deployment.
- Distinguish the board's oversight role from management's execution role in AI adoption, avoiding both overreach and disengagement.
- Assess personal and organisational liability exposure arising from inadequate oversight of high-risk AI systems.
- Identify board-level decisions that require explicit AI risk sign-off rather than delegation to a management committee.
Session 2Building Sufficient AI Literacy at Board Level
- Assess the board's current AI literacy gaps against the AI-related decisions it is expected to make.
- Commission board education sessions that build shared vocabulary on model risk, bias and generative AI without requiring technical depth.
- Recruit or develop a non-executive director with sufficient technical background to challenge management credibly on AI matters.
- Establish a mechanism for the board to access independent technical advice separate from management's own AI specialists.
02Structuring Board Oversight of AI
2 sessions · 8 points
Session 1Governance Structures, Committees and Reporting Lines
- Decide whether AI oversight sits within an existing risk or technology committee or requires a dedicated AI governance committee.
- Define the terms of reference, membership and reporting frequency for the chosen AI oversight structure.
- Establish reporting lines from the Chief Data and AI Officer or equivalent executive directly into board-level oversight.
- Align AI governance committee structures with existing enterprise risk management and internal audit functions.
Session 2Setting and Monitoring AI Risk Appetite
- Define a board-approved AI risk appetite statement covering model risk, ethical use, safety and reputational exposure.
- Translate risk appetite into thresholds that trigger board notification, such as high-risk model deployment or a significant AI incident.
- Review management's AI risk register at a cadence proportionate to the pace of AI adoption in the organisation.
- Reassess risk appetite as the organisation moves from piloting generative AI to embedding it in core products and processes.
03Challenging Management on AI Strategy and Risk
2 sessions · 8 points
Session 1Questions to Ask on AI Strategy and Investment
- Question management on how proposed AI investments align with overall corporate strategy and expected return.
- Probe the build, buy or partner rationale behind a proposed AI initiative and the vendor lock-in risk it creates.
- Challenge overly optimistic AI business cases by asking for evidence from completed pilots rather than projected benefits.
- Assess whether management's AI investment plan adequately funds governance, monitoring and risk controls, not only development.
Session 2Questions to Ask on Model Risk and Harm
- Question management on how a high-risk AI system was tested for bias, safety and robustness before deployment.
- Ask what human oversight and override mechanisms exist for AI systems that affect customers, employees or the public.
- Probe how the organisation would detect and respond to an AI system causing harm at scale before it is reported externally.
- Request evidence of independent assurance or audit over AI systems classified as high risk under applicable regulation.
04Regulatory Exposure and Crisis Preparedness
2 sessions · 8 points
Session 1Regulatory Exposure and Disclosure Obligations
- Identify the AI-related regulatory obligations applicable to the organisation, including sector-specific and cross-sector requirements.
- Assess what AI-related disclosures the organisation must make in financial statements, sustainability reports or regulatory filings.
- Monitor emerging AI regulation and enforcement action in relevant jurisdictions for its effect on the organisation's risk profile.
- Confirm that management's compliance programme evidences accountability in a form that would satisfy a regulator or auditor.
Session 2Crisis Preparedness and Incident Escalation
- Review the organisation's AI incident response plan and confirm that board escalation triggers are clearly defined.
- Rehearse the board's role in a simulated AI incident, such as a discriminatory outcome or a public model failure.
- Define what the board needs to know, and by when, when an AI incident becomes reportable to a regulator or the public.
- Review lessons from a past AI incident, whether internal or industry-wide, to strengthen future oversight practice.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
