
For your company
Governance & Compliance
Module · The board approves what it cannot question
The Board AI Literacy Check
A board cannot govern what it does not understand, yet most approve AI budgets and strategies on faith. This module tests whether your board can exercise real oversight: whether it has been trained, asks the hard questions, has set a risk appetite, sees unfiltered information, and can still say no.
What the five levels look like
Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.
The board is trained
- 1None
- 2One vendor pitch
- 3A single briefing
- 4Structured session
- 5Ongoing education
At the low end: A vendor demo is marketing, not education. Commission one independent briefing on what AI can and cannot do for your business, pitched at directors, not engineers. What good looks like: Ongoing board education is rare and valuable. Keep it independent of the vendors and executives whose proposals the board must judge.
It asks hard questions
- 1Rubber-stamps
- 2Asks about cost only
- 3Occasional challenge
- 4Probes risks
- 5Structured scrutiny
At the low end: A board that only asks about returns approves risk it never priced. Add three standing questions to every AI proposal: what could go wrong, who is accountable, how would we know. What good looks like: Structured risk scrutiny is genuine governance. Capture the questions in a checklist so the discipline survives a change of chair.
Risk appetite is set
- 1Never discussed
- 2Vague sense
- 3Discussed, unwritten
- 4Written appetite
- 5Appetite, with limits
At the low end: Without a defined appetite, every AI decision is argued from scratch. Have the board write one paragraph: how much autonomy, error, and exposure it will accept, and where it will not. What good looks like: A written appetite with limits is what lets the board delegate safely. Revisit it as your AI footprint grows; last year's line may be this year's constraint.
Information is unfiltered
- 1Management-filtered
- 2Good news only
- 3Summary reports
- 4Regular metrics
- 5Direct + independent
At the low end: A board that sees only what management curates cannot govern it. Insist on direct access to AI performance metrics and incident logs, not just the deck. What good looks like: Direct plus independent information flow is the mature state. Guard it: the pressure to filter grows precisely when the news gets bad.
It can say no
- 1In name only
- 2Defers to management
- 3Rarely pushes back
- 4Has said no
- 5Independent by design
At the low end: A board that cannot say no is a signature, not a check. Establish that AI proposals can be declined, and demonstrate it once; precedent creates permission. What good looks like: Independent judgment by design is real oversight. Protect it by keeping at least one voice free of management and vendor influence.