Our Approach

Three Lines. One Framework. Board-Ready.

We reviewed 14 governance standards a board can pull today against the oversight model your audit committee already uses. The result: a methodology that gives directors instruments, not advice.

The Foundation

Why Three Lines

The IIA Three Lines Model — operational management, risk & compliance, internal audit — is the governance architecture boards already trust. It's how your audit committee structures oversight for financial risk, cyber risk, and regulatory exposure.

But few of the 14 governance standards we reviewed were designed for it. They were written for engineers, regulators, or policymakers — not for directors asking "who owns the independent challenge function for this risk?"

BoardSight put one question to every standard. The finding: only one of the 14 — SR 11-7, a 2011 banking rule — actually requires an independent second line for AI. Every dedicated AI standard leaves the function meant to challenge your AI teams on the board's behalf optional. That's the gap we close.

The Methodology

The Three Lines, Instrumented for AI

Well covered

nearly every standard assigns it

1st Line — Operational Ownership

AI teams document what they build — risk registers, data lineage, model cards. Almost every standard we reviewed assigns this ownership, and it's where organizations feel most comfortable. The guidance is strongest here.

1 of 14

standards require it

2nd Line — Independent Risk

The line that challenges operations on behalf of the board. Only one of the 14 standards requires it — every dedicated AI standard leaves it optional. This is where BoardSight builds the function: independent risk assessment, escalation protocols, and board-grade reporting.

Addressed

in most standards

3rd Line — Internal Audit

Audit verifies that 1st and 2nd line controls work. BoardSight provides the audit-ready artifacts — the evidence packages and testing frameworks your internal audit team needs.

Each verdict reflects one binary question — does the standard require that line for AI? — applied to 14 board-available standards, with every call tied to a cited clause. It measures what the guidance requires, not any one organization's implementation. See how we tested.

The Evidence Base

14 Standards. One Verdict.

We put every one of these 14 board-available standards to the same test, then translate the result into the oversight language directors already use. Each is mapped to the Three Lines Model and labeled by what it is — a binding regulation, a voluntary framework, or director guidance.

NIST AI RMF 1.0ISO/IEC 42001ISO/IEC 23894ISO/IEC 38507EU AI Act 2024/1689OECD AI PrinciplesNIST CSF 2.0COSO ERMCOSO Internal ControlIIA Three LinesCOBIT 2019SR 11-7NACD Cyber-Risk OversightSEC Cyber Disclosure

The Pipeline

From Research to Boardroom

1

175+ Research Papers

Internal AI governance research literature — the raw evidence base

2

Five Proprietary Frameworks

Building AI Governance Index, Human-in-the-Loop Maturity Model, AI Governance Readiness Framework, Governance-Aware Technology Evaluation, and AI Incident Response Protocol — preliminary quantitative instruments built from the research

3

Board-Ready Artifacts

Risk registers, charter templates, assessment scorecards, quarterly reports

See if we're the right fit

15 minutes. No obligation. We'll tell you where your board stands — and whether BoardSight is the answer.

Request a Briefing
B
BoardSight

The AI Oversight Practice from Cognitive Corp.

Standards

NIST AI RMF 1.0ISO/IEC 42001:2023EU AI ActCOSO ERM

BoardSight provides independent, board-ready oversight evidence and advisory support. It does not provide legal opinions, regulatory certification, statutory audit assurance, or a guarantee that an AI system is safe or compliant.

© 2026 Cognitive Corp. All rights reserved.

BoardSight · AI Governance · Three Lines for AI