AI Governance Training for Executives: The Decisions Only the Board Can Make
🔒 This course requires registration
To access this course and all our learning materials, please register for the AI Fluency programme.
This online course is designed for senior leaders and board members who need to understand the critical decisions surrounding artificial intelligence implementation in their organisations. The training addresses the governance challenges that executive teams face when AI systems become integral to business operations. Participants will explore the ethical, legal, and strategic considerations that only board-level decision makers can properly evaluate. The curriculum examines how AI affects organisational culture, regulatory compliance, and long-term business strategy. Learners will discover the difference between technical AI deployment and the broader governance frameworks that ensure responsible usage.
The course consists of fifteen detailed lessons, each followed by a quiz to test understanding of key concepts. A final examination assesses overall comprehension of AI governance principles. All course materials are freely accessible to anyone interested in executive AI leadership. Upon completion, participants will be equipped to make informed decisions about AI investments, establish appropriate oversight structures, and develop policies that align technological advancement with organisational values. They will understand their role in ensuring AI systems serve the organisation’s best interests while maintaining public trust.
Frequently asked questions
What does a board need to know about AI governance?
A board needs to understand what AI systems the company operates, what risks they create, and how those risks are being managed. The board should know which systems are high-risk (decisions about people, sensitive data), which are being monitored, and what controls are in place. The board does not need to understand how algorithms work, but it needs to understand business impact, regulatory requirements, and whether the risks are acceptable given the company’s risk appetite.
Who is accountable for AI risk in a company?
Accountability flows from the board downwards. The board is accountable to investors and regulators. The board delegates responsibility to the CEO and senior management for day-to-day AI governance. A management steering committee typically owns the AI system register, approval gates, and monitoring. Individual teams are accountable for their specific systems. The key is clarity: each system should have an owner who is responsible for its performance and behaviour.
What questions should directors ask about AI systems?
Directors should ask: What problem does this system solve? How is it better than the current approach? What data was it trained on, and is that data representative? How does it perform on test data, broken down by demographic group? Are there significant performance gaps between groups? What monitoring will happen after deployment? Can the system be shut down quickly if problems arise? Who is accountable for this system’s ongoing performance?
Does the EU AI Act create duties for company directors?
Yes. Article 4 of the EU AI Act requires that persons responsible for high-risk AI systems have sufficient AI literacy to understand and evaluate risks. This applies to boards and senior management. The requirement has been in force since 2 February 2025. National authorities can start enforcing it from 2 August 2026. This does not mean directors need technical expertise, but they must understand enough to ask informed questions and evaluate advice.
How should a board set AI risk appetite?
Risk appetite should be defined in terms that teams can apply. Instead of “we accept only low risk,” the board might say “high-risk decisions (about people) must be tested for bias on representative data before deployment” or “systems must have monitoring in place and human override capability.” The board should set different appetites for different categories of AI: very low for high-risk decisions affecting people, moderate for decisions affecting multiple customers, and higher for internal analysis. Risk appetite should be reviewed annually.
Should a company have an AI ethics committee?
A dedicated ethics committee is optional, but the governance structures described (board oversight, management steering committee, approval gates, internal audit) typically cover ethics issues within their remits. An ethics committee can be useful if the company wants to give ethics a distinct voice separate from compliance or risk management. If an ethics committee exists, its role should be clear: does it make decisions, or does it advise? To whom does it report? Without clarity, ethics committees can become ineffective.
What AI risks belong on a corporate risk register?
Any AI system that could cause significant financial, regulatory, or reputational harm should be on the risk register. This typically includes: high-risk systems that make decisions about people; systems that process sensitive personal data; systems that the company is dependent on; and systems in regulated sectors. The risk register should list the system, the risk it creates (e.g., discrimination, data leakage, vendor dependence), the likelihood and impact, and the controls in place to mitigate the risk.
How do you report AI use to investors?
Include AI governance at a high level in annual reports. Disclose the board’s oversight of AI, the number and category of AI systems in use, and the controls in place. Disclose any material AI-related risks, such as dependence on a third-party model, regulatory compliance concerns, or recent incidents. Keep the disclosure factual and balanced. Do not claim there is no AI risk (not credible), but do explain how risk is being managed. This tells investors the company understands AI governance and is managing it professionally.
Can directors be liable for harm caused by an AI system?
In some circumstances, yes. If an AI system causes harm (discrimination, financial loss, privacy breach) and the board approved it without adequate diligence, the board faces liability. If a regulator finds that the board failed to ensure appropriate AI literacy or governance, the board faces regulatory action. Individual directors can be liable for gross negligence in some jurisdictions. Good documentation showing the board reviewed risks, asked challenging questions, and made an informed decision is the best protection.