InsightsAI & the BoardBoard Brief

AI governance for boards: a plain-language starting point

The short version

AI governance does not start with a policy document. It starts with an inventory: what AI is already in use, by whom, with what data. From there, four agenda questions cover what most boards need this year, and the NIST AI Risk Management Framework gives the structure without requiring anyone technical in the room.

Why is this a board matter at all?

Because AI is already in your organization whether or not anyone approved it: in the tools staff use, the features vendors switched on, and the drafts being pasted into public chatbots. The risk is not hypothetical misuse of some future system; it is ungoverned use of current ones, with donor data, client records, and payroll in scope. That is a fiduciary question, and it belongs on the agenda now.

What is the NIST AI RMF, in one paragraph?

The NIST AI Risk Management Framework is the U.S. standards body’s playbook for using AI responsibly. Its four functions are plain verbs: govern (decide who is accountable), map (know where AI touches your work), measure (check whether it behaves), and manage (act when it does not). Alignment requires just one thing: that those four verbs have owners, with no certification or technical team needed. V Consulting Services aligns its assessment and governance work to this framework, including for public institutions.

Govern, map, measure, manage: four verbs, four owners. A framework nobody owns is a framework nobody follows.

What four questions should the board ask next meeting?

  • What AI is in use today? Name the tools, the users, and the data each touches. If no list exists, that is finding one.
  • Who approves new AI use? A named owner. Approval must be someone’s job, and a policy PDF cannot do it for them.
  • What data may never leave? Define the categories (donor records, client files, personnel data) and say where they may not go.
  • What would we tell stakeholders? If AI produced a harmful error tomorrow, who explains it, and could they honestly say the use was governed?

What should we do before buying any AI tool?

Answer the four questions first. A tool purchased before governance exists becomes shadow infrastructure by default. When the questions have owners, evaluation is straightforward: what data does it touch, does the vendor train on your data, can you turn it off, and who reviews its output. This is standing work for the technology owner described in What a vCIO does, and if no one holds that seat, a Technology Assessment includes the AI inventory as a deliverable.

What this means for your board

  • Start with inventory before policy: what AI is already in use, by whom, with what data.
  • The NIST AI RMF is four verbs (govern, map, measure, manage) and each needs a named owner to hold it.
  • Define the data that may never leave the organization before evaluating any tool.
  • AI governance is standing work for whoever owns technology; without that seat, it decays in a quarter.

Bring your AI questions to one conversation.

No preparation needed. We'll tell you honestly where your AI governance stands today.

15 MINNO PREPHONEST ANSWER
Book the call