AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

NACD Board Governance Guide Raises the Bar on Director AI Competency and ERM Integration

Source

Director Essentials: Implementing AI Governance

National Association of Corporate Directors (NACD)

Via National Association of Corporate Directors (NACD)

What happened

The National Association of Corporate Directors published Director Essentials: Implementing AI Governance, a structured guide addressed directly to corporate directors rather than to management teams or legal counsel. The guide requires boards to integrate AI risk into enterprise risk management frameworks as a discrete category, not as an extension of existing technology or cyber risk buckets. It directs directors to assess their own AI competency and close identified gaps, and to establish AI-specific KPIs that allow boards to track governance performance over time. The publication does not carry the force of law, but NACD guidance has historically been treated by courts, securities regulators, and institutional investors as a baseline statement of what reasonable board oversight looks like. Organizations already aligning with the ISO/IEC 42001:2023 – Information Technology – Artificial Intelligence – Management System or the NIST Artificial Intelligence Risk Management Framework Playbook will find the NACD guide largely consistent with those frameworks, but the guide's board-facing framing makes it operationally distinct.

Why it matters

  • ·Regulatory and litigation exposure: Courts and the SEC have increasingly used recognized practitioner standards to assess board oversight adequacy in securities and derivative actions; NACD guidance now gives plaintiffs and regulators a named benchmark against which director conduct on AI risk can be measured, raising the stakes for boards that have not formally addressed AI governance.
  • ·Operational impact on ERM and reporting programs: The requirement to establish AI-specific KPIs and integrate AI risk into ERM frameworks means compliance and risk functions will need to produce board-ready AI risk data on a recurring basis, which most organizations do not yet have a formal process to generate.
  • ·Director competency as a governance gap: The guide's call for boards to assess and close their own AI competency creates a new accountability layer above management; organizations that cannot demonstrate director-level AI literacy may face heightened scrutiny from institutional investors and proxy advisory firms applying AI governance criteria.

Governance controls affected

What to do now

  • Map the NACD guide's requirements against your current board reporting cadence and identify gaps in AI-specific risk data delivered to directors.
  • Commission a director AI competency assessment using BRD-001 criteria and document findings before the next board cycle.
  • Update your ERM framework to classify AI risk as a standalone category with defined risk appetite and tolerance statements under BRD-006.
  • Develop at least three AI-specific KPIs for board consumption, covering risk exposure, incident trends, and governance program maturity, and establish a reporting baseline.
  • Brief the audit committee on the NACD publication and its implications for board oversight adequacy, and capture that briefing in board minutes to create a contemporaneous record.

What to watch next

Compliance teams should monitor whether the SEC references the NACD guide in future AI-related disclosure guidance or enforcement actions, as agency staff have previously cited NACD publications when evaluating board oversight adequacy. Institutional investors and proxy advisory firms are also refining their AI governance voting criteria for the 2027 proxy season, and the NACD guide is likely to inform those frameworks. Organizations subject to the SEC AI Governance Guidance should assess whether their current board disclosures satisfy the elevated competency and ERM integration expectations the NACD publication now codifies. Any forthcoming NACD updates to this guide, particularly if they incorporate sector-specific obligations, should be tracked and compared against existing internal governance documentation.

Stay ahead of stories like this

Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-24

PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance

PwC India published guidance titled 'Governing models in the AI era' recommending that organizations establish board-approved AI model risk appetite thresholds, build complete model inventories with ownership and validation metadata, and apply AI-specific due diligence to third-party solutions. The guidance addresses a persistent implementation gap: most enterprises have neither a formal definition of what counts as a model nor a complete register of model-like tools in production. Compliance teams can adopt the framework as a practical operating model for cataloguing AI systems and governing external vendors.

Corporate Policy2026-08-22

Anthropic IPO Prospectus Makes AI Backlash a Material Investor Risk

Anthropic's forthcoming IPO prospectus is expected to formally list public opposition to AI and data center construction as a material risk factor, according to sources cited by CNBC. The company, privately valued near $1 trillion, will also disclose compute capacity constraints and open-source competition as investor-facing risks. The filing will be the first SEC-reviewed document from a major frontier lab to characterize societal AI opposition this way.

Standards2026-08-26

NIST Extends CSF Into AI-Assisted Workflows, Comments Due October 15

NIST released the initial public draft of Special Publication 1353, a quick-start guide for applying AI tools to Cybersecurity Framework 2.0 analysis and reporting. The draft is open for public comment through October 15, 2026. It creates a new expectation that AI used in security analysis workflows should itself be governed, documented, and auditable.