AI Governance Institute
← All controls
BRD

Board & Executive Governance

Operational controls for board & executive governance, with maturity levels, evidence requirements, and implementation guidance.

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →

11 controls

BRD-001
medium

Director AI Literacy and Competency Assessment

Assess directors’ AI knowledge against defined standards. Address gaps through targeted education so the board can carry out its oversight duties.

BRD-002
medium

AI Governance Committee Charter and Decision Rights

Charter an AI governance committee with members from relevant functions. Define its mandate, membership, decision rights, quorum, escalation paths, and board reporting duties.

BRD-003
medium

Board-Level AI Safety Committee Charter

Establish a board committee responsible for AI safety oversight and high-consequence risk decisions. Keep its fiduciary responsibilities distinct from the operational governance committee.

BRD-004
medium

AI Governance ESG and Investor Disclosure

Set a process for reporting AI governance maturity, risk management, and safety practices to shareholders, institutional investors, and ESG agencies.

BRD-005
medium

AI Governance Maturity Assessment

Assess the governance program against defined maturity frameworks and external benchmarks. Use the findings to prioritize improvements.

BRD-006
medium

AI Risk Tolerance and Appetite Documentation

Document and approve AI risk tolerance across relevant risk categories. Obtain board sign-off and schedule periodic reviews.

BRD-007
high

Federated AI Governance Design

Define accountability across distributed AI deployments. Allocate central and business-unit responsibilities, and set escalation routes when local governance is insufficient.

BRD-008
medium

Voluntary AI Governance Adequacy Standard

Define an internal governance standard where binding AI mandates are absent. Document how it meets stakeholder expectations and anticipated regulatory requirements.

BRD-009
high

Unified Multi-Framework AI Risk Register

Consolidate NIST AI RMF, ISO 42001, EU AI Act, and sector obligations in one risk register. Remove duplication and identify controls satisfying several requirements.

BRD-010
low

AI Governance Committee Operating Cadence and Membership Lifecycle

Document committee meeting schedules, standing agendas, quorum enforcement, and chair responsibilities. Define member onboarding and offboarding so oversight continues consistently.

BRD-011
medium

AI Governance Training Program and Completion Tracking

Maintain AI training tailored to staff roles, with documented curricula and annual completion targets. Keep auditable completion records and review content periodically. Cover staff responsible for design, deployment, review, and oversight.

Board & Executive Governance, tracked weekly

New board & executive governance controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.

Powered by Buttondown.