AI Governance Institute
All governance templates →What does AI governance leadership look like at the board and executive level?

Implementation Kit

Board AI Oversight Charter and Executive Role Templates

What board and executive leadership of AI governance looks like in practice. A board oversight charter, an executive sponsor role description distinct from product leadership, and a plan to integrate AI risk into enterprise risk management.

Who this is for: The chair, CEO, or CRO defining who leads AI governance at the top and how.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. Board AI oversight charter

Document

What the board (or a committee of it) is responsible for on AI, its escalation triggers, and its reporting cadence.

Template

One page. Adopted by the board and minuted. Distinct from the management committee charter.

  • Which board body holds AI oversight (full board, audit, risk, or a dedicated committee) and why
  • Responsibilities: approve AI risk appetite; review the program's effectiveness; oversee major AI-related decisions and incidents
  • What management must bring to the board: the quarterly report, any Sev-1 incident, material regulatory changes, risk-appetite breaches
  • Escalation triggers: the specific events that require immediate notification of the board chair
  • Reporting cadence: quarterly operational report; annual context briefing; annual risk-appetite review
  • Independent assurance: the board's expectation for internal audit or third-party review of the program
  • Review date

Worked example

  • Body: the Audit Committee holds AI oversight, given AI risk is primarily regulatory and financial for us; the full board receives an annual briefing.
  • Responsibilities: approve the AI risk appetite statement annually; receive an independent opinion on program effectiveness annually; be notified of any Sev-1 AI incident.
  • Management must bring: quarterly AI risk report; any Sev-1 within 24 hours to the committee chair; material regulatory change within 10 business days; any risk-appetite metric in breach for two consecutive months.
  • Escalation triggers: regulator inquiry about our AI use; AI incident with external harm; discovery that a board report materially misstated the position.
  • Cadence: quarterly report; annual briefing; annual appetite review.
  • Assurance: Internal Audit reviews the program at least annually.
  • Review: 2027-06.

Acceptance criteria

  • The charter names which board body holds oversight and the reason.
  • Escalation triggers are specific events, and the board chair notification path is explicit.
  • It sets an expectation for independent assurance of the program.

2. Executive sponsor role description

Document

The senior executive accountable for AI governance, deliberately not the head of AI product or engineering.

Template

A named executive, distinct from AI product or engineering leadership, to avoid the builder marking their own work.

  • Purpose of the role: own AI governance outcomes at the executive level; unblock resourcing; carry it to the board
  • Why not product or engineering: independence from the teams whose systems are being governed
  • Responsibilities: sponsor the program charter; approve the policy set; chair or sit on the committee; present to the board; hold the risk-acceptance authority for high-tier systems
  • Authority: can require assessments and controls; can pause a deployment; controls the governance budget line
  • Time commitment: realistic estimate
  • Success measures: program milestones met; clean independent assurance; no surprise incidents

Worked example

"The Chief Risk Officer is the executive sponsor for AI governance. The role is held outside the AI product and engineering organisation so that the function governing AI systems is independent of the teams building them. The sponsor approves the AI policy set, chairs the AI Governance Committee, holds risk-acceptance authority for High-tier systems, controls the governance budget, and presents the quarterly report to the Audit Committee. Estimated commitment: two days a month plus committee time. Success is measured by program milestones met on schedule, a clean annual internal audit, and the absence of material AI incidents that governance should have caught."

Acceptance criteria

  • The sponsor is a named executive outside AI product and engineering.
  • The role carries real authority: pause power, budget control, risk-acceptance authority.
  • Time commitment and success measures are stated.

3. Enterprise risk management integration plan

Spreadsheet

How AI risk feeds the existing ERM framework rather than running as a parallel track.

Template

ERM elementCurrent state for AIIntegration actionOwnerDone
Risk taxonomyAI risk not a named categoryadd AI risk with sub-types (model, data, third-party, agentic, regulatory)
Risk registerAI risks tracked separatelyfeed AI risk register rows into the enterprise register
Risk appetiteno AI-specific appetiteadd AI appetite metrics and tolerances
Risk reportingAI reported ad hocAI risk in the standard enterprise risk report to the board
Controls assuranceAI controls not in the assurance planadd AI controls to internal audit's universe
Incident aggregationAI incidents in a separate registerroll AI incidents into enterprise incident reporting

Worked example

ERM elementIntegration actionOwnerDone
Risk taxonomyAI risk added with 5 sub-typesERM leadY
Risk registerAI register rows mapped to enterprise register quarterlyAI Gov LeadY
Risk appetite4 AI appetite metrics added to the enterprise statementCROY
Risk reportingAI section now standard in the board enterprise risk reportERM leadY
Controls assuranceAI controls added to the audit universeHead of Auditin progress
Incident aggregationAI incidents roll up monthlyERM leadY

Acceptance criteria

  • AI risk is a named category in the enterprise risk taxonomy.
  • AI risk appears in the standard enterprise risk report, not a separate one.
  • AI controls are in internal audit's universe.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

BRD-003
BRD-003

The board oversight charter is the board-level AI safety and oversight committee charter.

BRD-002
BRD-002

The sponsor role description clarifies executive accountability alongside the committee charter.

BRD-001
BRD-001

Board oversight responsibilities depend on director AI literacy being in place.

HOC-007
HOC-007

The charter's reporting cadence and escalation triggers define board risk reporting.

BRD-006
BRD-006

Approving AI risk appetite is a named board responsibility in the charter.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →