The 7 Columns Every Director Should Demand
The 7 Columns Every Director Should Demand
This Is Not Optional
When the audit committee presents AI governance, directors should see a risk register with exactly seven columns. Not five, not ten — seven. These seven columns answer the questions every director needs answered.
If the presentation lacks a clear register with these seven categories, ask: "Where is the risk register? What are we governing against?"
A governance conversation without a concrete register is just theater.
Column 1: AI Application Name — Know What You Own
The Director's Question: "What AI systems do we actually run?"
What You Should Demand: A clear name for each system. Not "Machine Learning Platform" — that's useless. Actual names:
- "Hiring Recommendation Engine (HR Tech)"
- "Customer Churn Prediction (Sales)"
- "Loan Approval Scorer (Finance)"
- "Demand Forecasting (Supply Chain)"
Why This Matters: You cannot govern what you cannot name. Many boards discover, months later, that the company has AI systems they didn't know about. This column forces an inventory conversation and creates accountability.
The Red Flag: If business units list different systems than you knew about, governance has a visibility problem. Ask: "How many unknown systems are out there?"
Column 2: Exact AI Function — Understand the Power This System Has
The Director's Question: "What exactly does this system do? Does it decide, or does it recommend?"
What You Should Demand: One sentence describing what the system does and who uses it:
- "Recommends candidates to recruiters. Recruiter makes final hire decision."
- "Auto-approves loans under $50K. Loans >$50K routed to underwriter."
- "Predicts demand. Operations team reviews and decides inventory."
- "Scores applicants for credit. Score drives decision (90% approval within score band)."
Why This Matters: This column separates advisory systems (lower governance burden) from consequential systems (higher burden). A recommendation engine is less risky than an auto-decision system.
Also, this reveals whether humans actually oversee the AI. If the description says "auto-approves" with no human review, that's consequential. If it says "recommends and human approves," that's advisory. Governance requirements differ.
The Red Flag: If the second-line owner says "it's advisory" but the operations team says "we almost never override it" — governance is weak. Nominal human review doesn't count.
What to Demand: Evidence of override rate. If the system auto-decides 99% of the time, treat it as consequential.
Column 3: Data Sources Touched — Understand What Biases Might Live Here
The Director's Question: "What data feeds this system? Where did that data come from?"
What You Should Demand: The top 3-5 data sources that drive the system:
- "Hiring engine: Internal hiring records (5 years), LinkedIn profiles, skills assessments"
- "Credit scorer: Credit bureau data, payment history, income verification, prior defaults"
- "Churn predictor: Customer purchase history, customer service tickets, contract terms"
Why This Matters: Data quality determines system quality. If the training data is biased (e.g., only includes profitable customers, reflecting past discrimination), the model will replicate that bias. Directors need to know this.
Also, data sources reveal privacy and compliance risks. If the system uses sensitive data (health, financial, biometric, genetic), that's material governance concern.
The Red Flag: "We don't fully know where the data comes from" or "Data sources are listed in the technical documentation." If the second line can't articulate data sources, data governance is weak.
What to Demand: A simple data lineage — not a 50-page technical doc, but a one-page picture of where data comes from.
Column 4: Access Level — Understand Whether Humans Actually Control This
The Director's Question: "Can a human override this system's decisions? Is the override documented?"
What You Should Demand: One of three categories:
- Read-Only: System recommends. Human makes separate decision. Human can ignore system entirely.
- Read/Write with Audit Trail: System suggests or auto-decides, but human can override with documented reason (logged).
- Read/Write without Audit Trail: System makes decision, human rarely overrides, overrides not formally recorded.
Why This Matters: This column shows whether humans actually control the system or whether the AI is effectively running on autopilot.
Strong human-in-the-loop (HITL) governance means:
- Override rate is non-trivial (>5% of decisions)
- Override reasons are documented
- Audit team can trace overrides
Weak HITL means the system is basically automated, humans are rubber-stamping, and there's no real control.
The Red Flag: "The system is advisory, but we override <1% of the time." That's not advisory; that's rubber-stamping. Treat as consequential.
What to Demand: Show me the override rate. Show me a sample of override documentation. If overrides are rare or undocumented, this system needs stronger governance.
Column 5: Risk Category — Understand What Could Go Wrong
The Director's Question: "What specific risks does this system pose?"
What You Should Demand: One to three risk categories checked:
- Regulatory Risk: Could we violate a law? (Fair lending, FCRA, ECOA, EU AI Act, employment law, healthcare law)
- Fairness/Bias Risk: Could this system have disparate impact on protected groups? (Race, gender, age, disability, national origin)
- Safety Risk: Could failure cause physical harm or critical system failure?
- Privacy Risk: Could this system misuse personal data?
- Operational Risk: Could system drift, data corruption, or outage harm the business?
- Reputational Risk: If this system fails publicly, would it damage brand trust?
Why This Matters: Different risks require different mitigations. If the main risk is bias, you need fairness auditing. If the main risk is regulatory, you need compliance review. This column forces clarity on the specific threat.
The Red Flag: Everything marked "Regulatory" or "Fairness" without specificity. Push back: "Which regulation? Which demographic group? How do you know?"
What to Demand: Specific risk statements, not generic risk category checks:
- "Regulatory: Fair lending law (FCRA). Credit scorer could have disparate impact by race."
- "Not just: "Regulatory Risk."
Column 6: Impact × Probability Score — Understand the Magnitude of Risk
The Director's Question: "How risky is this system, really? Should we devote governance resources here?"
What You Should Demand: A risk score based on:
- Impact: High ($1M+ loss, major regulatory fine, safety incident), Medium ($100K-$1M loss), Low (<$100K)
- Probability: High (>30% annual), Medium (10-30%), Low (<10%)
- Score: Impact × Probability (High-High is highest; Low-Low is lowest)
Why This Matters: Not all AI systems are equally risky. A recommendation engine touching one department is lower-risk. An auto-approval system touching lending decisions is higher-risk. This column quantifies it.
Also, this forces accountability on risk assessment. If the second line says "Low probability of a fairness violation," they're committing to that assessment. If a violation occurs later, the board can ask whether the assessment was reasonable.
The Red Flag: Everything rated "High-High" or everything rated "Low-Low." Overestimating inflates governance budgets. Underestimating creates exposure.
What to Demand: Risk assessment methodology. "How did you determine this is Medium probability? What data supports that?"
Column 7: Mitigation Status — Understand Whether Governance Is Actually Happening
The Director's Question: "What is the second line actually doing about this risk? Is governance real or theater?"
What You Should Demand: One of four statuses:
- Covered: Active mitigation in place. Examples: "Quarterly fairness audit + monthly bias testing," "Monthly compliance review + regulatory change tracking."
- Partial: Some mitigation, but gaps. Example: "Fairness audit quarterly for hiring subgroup A, but subgroup B not yet covered."
- Planned: Mitigation to be implemented. Example: "Fairness audit planned for Q3 2026."
- Accepted: Risk deliberately not mitigated (cost exceeds benefit). Must be board-approved.
Why This Matters: This column shows whether second-line governance is active. It's the difference between a governance framework (pretty) and governance execution (real).
Also, "Accepted" risks must be conscious decisions. If the board says "This risk is material but we accept it because mitigation costs $2M," that's a documented board decision and a defensible position. If nobody has made that decision, governance is just theater.
The Red Flag:
- Everything marked "Covered" (too good to be true; where's the evidence?)
- Everything marked "Partial" (governance is incomplete and acknowledged as such)
- Multiple systems marked "Planned" for more than a quarter (governance is stalled)
- "Accepted" risks without board approval memo (board hasn't made a conscious decision)
What to Demand: Evidence of coverage:
- For "Covered": When was the last audit? What did it find? Show me the testing methodology.
- For "Partial": Which subgroups or systems lack coverage? When will you close the gap?
- For "Planned": What's the timeline? What's blocking implementation?
- For "Accepted": Show me the board approval memo explaining why this risk is accepted.
How to Use These Seven Columns in a Meeting
When governance is presented, ask:
-
"Show me the register. All seven columns." If it doesn't exist or is incomplete, that's a governance gap.
-
"Which systems are High-High risk, and what's the mitigation status?" High-risk systems marked "Partial" or "Planned" are governance red flags.
-
"How many systems are marked Accepted? What board decisions authorized acceptance?" Accepted risks need explicit board approval.
-
"What was our override rate for Read/Write systems last quarter?" If override rates <1%, HITL governance is weak.
-
"How does this register align with EU AI Act requirements?" If you have EU exposure, each high-risk system should be documented and governed.
-
"Who owns the second line? Can they defend each row of this register?" The second-line owner should be able to articulate the risk and mitigation for every system.
The Director's Authority
Directors don't need to understand how neural networks work. But directors absolutely can understand and should demand:
- "What systems exist?" (Column 1)
- "What do they do?" (Column 2)
- "What risks do they pose?" (Columns 3, 5)
- "How risky?" (Column 6)
- "Is anyone mitigating that risk?" (Column 7)
These are governance questions, not technical questions. Audit committees own governance.
The Uncomfortable Implication
If these seven columns don't exist in concrete form — if governance is still at the "framework" stage or "strategy" stage — the board has not yet established adequate AI governance systems.
That is a Caremark issue. That is a fiduciary liability.
Demand the register. Demand the seven columns. Hold the board accountable for concrete governance, not abstract principles.
Word count: ~1,200 | Reading time: 10 minutes