Blog

What boards should ask before approving an AI project


A lot of organisations approved their first AI tool in the last eighteen months. Far fewer can tell you who signed it off, what data goes into it, or what happens to the work if the supplier changes its pricing.

That is not really a technology problem. It is a governance gap, and it looks very like the ones that have been surfacing in risk and audit meetings for decades, usually about something else entirely.

I sit on the other side of this as a trustee. The thing I notice at board level is not that people are frightened of AI. It is that they are unsure whether they are allowed to ask about it. There is a widespread and quite understandable assumption that you need to understand how the technology works before you can scrutinise it.

You do not. Every question below can be asked and answered in plain business language, and none of them requires anybody in the room to know what a model is.

The six questions

What organisational data goes into this, and who approved that?

Not what data could go in. What is going in, from which systems, put there by whom. In most organisations the honest answer at the point of approval is that nobody has looked, because the tool was adopted by a team rather than procured centrally.

For charities and anyone holding data about vulnerable people, this is the question that matters most and the one most likely to be answered vaguely. Vagueness here is itself the finding.

If the supplier doubled the price tomorrow, what would we do?

This tests dependency, which is the risk that gets underpriced in every technology decision I have seen. If the answer is that the organisation would pay, you have a supplier relationship you do not control.

I would follow it with a harder version. If the supplier withdrew the product entirely, what would we lose, and how long would it take to replace? A tool that has quietly become the way a department works is a bigger commitment than the invoice suggests.

Who here can explain, in plain terms, how it reaches its answers?

Not the mathematics. The shape of it. What it has been trained on, what it is good at, where it is known to be unreliable.

If nobody in the organisation can do that, you are not in a position to defend a decision that the tool influenced. That becomes a problem the first time somebody challenges an outcome, which will happen, and probably at the worst possible moment.

What is the decision we would never let it make on its own?

This one produces the most useful conversation in the room, in my experience, because it forces the board to define where human judgement is not negotiable. Eligibility. Safeguarding. Hiring. Anything affecting an individual's access to a service.

Write the answer down. A boundary that exists in everyone's head is not a control.

What does success look like, and when will we know?

AI proposals arrive with an unusual amount of enthusiasm attached, and enthusiasm makes people vague about measurement. Ask what specifically will be different, by when, and what would count as this not having worked.

Agree it at approval, while everyone is calm. Nobody agrees a failure condition retrospectively.

Who is accountable for this in a year?

Not who is running the pilot. Who owns it once the person who was excited about it has moved on. Adoption without ownership is how organisations end up with tools that nobody can explain, nobody can switch off and nobody will admit to having chosen.

Why this is a board matter rather than a management one

There is a reasonable objection to all of this, which is that boards should set direction and leave operational decisions to executives. I have some sympathy with it. Boards that get into the weeds are usually a symptom of something else going wrong.

But AI adoption has three characteristics that make it a governance question rather than an operational one.

It moves organisational data outside the organisation, often to jurisdictions and terms nobody has read. It influences decisions that affect individuals, which brings duties that sit with the board rather than the department. And it creates dependencies that are expensive and slow to unwind, usually well after the person who approved it has moved on.

Any one of those would put it on a risk register. Together they make it a standing item.

There is also a practical reason. Trustees and non-executive directors carry personal accountability for oversight. If an AI-influenced decision goes badly and the question is asked, "the executive team handled it" is not a comfortable answer to give.

A note for charity boards specifically

Charities are getting a particular flavour of bad advice at the moment. It arrives as enthusiasm about efficiency, usually from somebody with something to sell, and it lands on organisations with limited internal capability to evaluate it.

Two things are true at once. AI can genuinely help resource-constrained organisations do more, and I have seen it do so. And charities carry obligations that make careless adoption more serious than it would be in a commercial business of the same size. Restricted funding cannot be moved to rescue a mistake. Trustees are personally accountable. The data is often about people who are not in a position to complain.

None of that argues for avoidance. It argues for the six questions, asked properly, and recorded in the minutes.

Where I sit on this

I am a trustee as well as an advisor, so I have asked these questions from inside a board rather than only recommending them from outside. I have also been the person on the other side of the table, presenting a proposal to people whose job was to be sceptical about it. Both perspectives have been useful.

I have no software to sell, no reseller agreements and no platform commissions, which means I have no interest in whether a board approves a proposal or declines it. That is the position from which the questions above are worth asking.

The boards that handle AI well are not the technical ones. They are the ones that treat it as a normal governance subject, ask normal governance questions, and refuse to be told that the topic is too specialised for them to scrutinise.


If your board or trustees want an independent view on an AI proposal before approving it, AI strategy and governance covers oversight, controls and responsible adoption. An AI readiness assessment answers the prior question of whether the organisation is in a state to adopt anything yet.


Not sure where to start?

Most clients begin with a conversation. No pitch, no hard sell.

Just a straightforward discussion about where you are and whether I can help.

Book a free 30-minute call

We handle your details in line with our privacy policy.