Implementation Kit
Board AI Oversight Charter and Executive Role Templates
What board and executive leadership of AI governance looks like in practice. A board oversight charter, an executive sponsor role description distinct from product leadership, and a plan to integrate AI risk into enterprise risk management.
Who this is for: The chair, CEO, or CRO defining who leads AI governance at the top and how.
1. Board AI oversight charter
DocumentWhat the board (or a committee of it) is responsible for on AI, its escalation triggers, and its reporting cadence.
Template
One page. Adopted by the board and minuted. Distinct from the management committee charter.
- Which board body holds AI oversight (full board, audit, risk, or a dedicated committee) and why
- Responsibilities: approve AI risk appetite; review the program's effectiveness; oversee major AI-related decisions and incidents
- What management must bring to the board: the quarterly report, any Sev-1 incident, material regulatory changes, risk-appetite breaches
- Escalation triggers: the specific events that require immediate notification of the board chair
- Reporting cadence: quarterly operational report; annual context briefing; annual risk-appetite review
- Independent assurance: the board's expectation for internal audit or third-party review of the program
- Review date
Worked example
- Body: the Audit Committee holds AI oversight, given AI risk is primarily regulatory and financial for us; the full board receives an annual briefing.
- Responsibilities: approve the AI risk appetite statement annually; receive an independent opinion on program effectiveness annually; be notified of any Sev-1 AI incident.
- Management must bring: quarterly AI risk report; any Sev-1 within 24 hours to the committee chair; material regulatory change within 10 business days; any risk-appetite metric in breach for two consecutive months.
- Escalation triggers: regulator inquiry about our AI use; AI incident with external harm; discovery that a board report materially misstated the position.
- Cadence: quarterly report; annual briefing; annual appetite review.
- Assurance: Internal Audit reviews the program at least annually.
- Review: 2027-06.
Acceptance criteria
- ✓The charter names which board body holds oversight and the reason.
- ✓Escalation triggers are specific events, and the board chair notification path is explicit.
- ✓It sets an expectation for independent assurance of the program.
2. Executive sponsor role description
DocumentThe senior executive accountable for AI governance, deliberately not the head of AI product or engineering.
Template
A named executive, distinct from AI product or engineering leadership, to avoid the builder marking their own work.
- Purpose of the role: own AI governance outcomes at the executive level; unblock resourcing; carry it to the board
- Why not product or engineering: independence from the teams whose systems are being governed
- Responsibilities: sponsor the program charter; approve the policy set; chair or sit on the committee; present to the board; hold the risk-acceptance authority for high-tier systems
- Authority: can require assessments and controls; can pause a deployment; controls the governance budget line
- Time commitment: realistic estimate
- Success measures: program milestones met; clean independent assurance; no surprise incidents
Worked example
"The Chief Risk Officer is the executive sponsor for AI governance. The role is held outside the AI product and engineering organisation so that the function governing AI systems is independent of the teams building them. The sponsor approves the AI policy set, chairs the AI Governance Committee, holds risk-acceptance authority for High-tier systems, controls the governance budget, and presents the quarterly report to the Audit Committee. Estimated commitment: two days a month plus committee time. Success is measured by program milestones met on schedule, a clean annual internal audit, and the absence of material AI incidents that governance should have caught."
Acceptance criteria
- ✓The sponsor is a named executive outside AI product and engineering.
- ✓The role carries real authority: pause power, budget control, risk-acceptance authority.
- ✓Time commitment and success measures are stated.
3. Enterprise risk management integration plan
SpreadsheetHow AI risk feeds the existing ERM framework rather than running as a parallel track.
Template
| ERM element | Current state for AI | Integration action | Owner | Done |
|---|---|---|---|---|
| Risk taxonomy | AI risk not a named category | add AI risk with sub-types (model, data, third-party, agentic, regulatory) | ||
| Risk register | AI risks tracked separately | feed AI risk register rows into the enterprise register | ||
| Risk appetite | no AI-specific appetite | add AI appetite metrics and tolerances | ||
| Risk reporting | AI reported ad hoc | AI risk in the standard enterprise risk report to the board | ||
| Controls assurance | AI controls not in the assurance plan | add AI controls to internal audit's universe | ||
| Incident aggregation | AI incidents in a separate register | roll AI incidents into enterprise incident reporting |
Worked example
| ERM element | Integration action | Owner | Done |
|---|---|---|---|
| Risk taxonomy | AI risk added with 5 sub-types | ERM lead | Y |
| Risk register | AI register rows mapped to enterprise register quarterly | AI Gov Lead | Y |
| Risk appetite | 4 AI appetite metrics added to the enterprise statement | CRO | Y |
| Risk reporting | AI section now standard in the board enterprise risk report | ERM lead | Y |
| Controls assurance | AI controls added to the audit universe | Head of Audit | in progress |
| Incident aggregation | AI incidents roll up monthly | ERM lead | Y |
Acceptance criteria
- ✓AI risk is a named category in the enterprise risk taxonomy.
- ✓AI risk appears in the standard enterprise risk report, not a separate one.
- ✓AI controls are in internal audit's universe.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The board oversight charter is the board-level AI safety and oversight committee charter.
The sponsor role description clarifies executive accountability alongside the committee charter.
Board oversight responsibilities depend on director AI literacy being in place.
The charter's reporting cadence and escalation triggers define board risk reporting.
Approving AI risk appetite is a named board responsibility in the charter.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →