The full board should oversee AI strategy and enterprise-wide risk appetite. Committees should handle the consequences that fall within their existing mandates: audit for financial reporting and controls, risk for enterprise exposure, technology for capability, and nominating and governance for the board's own oversight structure.
The gap to avoid is an AI program that receives several committee presentations but no joined-up judgment. Audit accepts the savings forecast. Technology reviews the architecture. Risk examines customer harm. Nobody checks whether those conclusions depend on contradictory assumptions.
Assign a lead for each issue and a coordinator for the overall picture. Those are different jobs.
Start with the decision, not the technology
Consider an insurer introducing AI into claims processing. The same program could change operating costs, customer outcomes, data exposure, workforce requirements and regulatory risk.
Calling it a technology project does not settle those questions. Neither does calling it a compliance project.
A useful starting exercise is to list the decisions that could materially affect the business, then assign oversight to the body already responsible for the underlying consequence. A financial reporting control belongs in a different discussion from a strategic choice to automate customer decisions.
The board should also identify one coordinating committee or chair. Coordination means making sure the coverage is complete. It does not mean absorbing every other committee's authority.
NIST's AI Risk Management Framework offers voluntary guidance for organizing AI risk management. It is a reference for management's processes, not a rule assigning AI to a particular board committee.
Keep enterprise strategy with the full board
The full board should retain the discussion about how AI changes the company's business model, competitive position and appetite for risk. A committee can examine a proposed control or investment in detail, but the strategic tradeoff may exceed its remit.
Management might propose a lower-cost service model that relies more heavily on automated decisions. An audit committee could assess whether the savings are credibly measured. A risk committee could consider customer harm. The full board still needs to understand whether this is the business the company intends to become.
The board does not need to approve every model change. It needs a clear statement of which decisions management can make within approved limits and which changes return for board consideration.
Give committees specific questions to own
Audit: can the numbers and controls be relied on?
Where AI enters financial reporting, estimates, transaction processing or controls, the audit committee is a natural oversight home. Its attention should be on evidence, exceptions, auditability and management's assessment of control effectiveness.
This is different from making audit responsible for all AI adoption. A committee already carrying a substantial reporting workload should not become the default destination simply because nobody has considered another structure.
Risk: what exposure is the enterprise accepting?
A standing risk committee can examine how AI changes the company's risk profile, including operational disruption, customer outcomes, supplier dependency and control exceptions. Its task is to connect individual deployments to aggregate exposure.
Several individually tolerable dependencies may become unacceptable when they rely on the same external provider. That concentration can be missed if each business unit reports separately.
Technology: can the architecture support the strategy?
A technology or innovation committee can challenge management on resilience, technical capability, dependency, system integration and the feasibility of proposed investment.
It should not become a product team. The useful question is whether the architecture and operating capability support management's commitments, not which model a director personally prefers.
Nominating and governance: can the board oversee this properly?
This committee can review committee charters, board capability, director education and gaps between oversight responsibilities. It should test whether AI has been incorporated into the board's existing governance structure rather than appended as an occasional presentation.
It may coordinate the initial allocation exercise without becoming the permanent owner of operational AI risk.
Compensation: are incentives creating the wrong behavior?
Where executive incentives or workforce measures reward AI deployment, the compensation committee should understand what is being rewarded. A target for tools launched can encourage a different outcome from a target for verified business improvement.
The committee's attention belongs on executive accountability and incentives within its remit. Routine deployment and workforce management remain management responsibilities.
A proposed responsibility matrix
Use this as a starting allocation, not a substitute for existing charters. Where a committee does not exist, assign the work explicitly to the full board or another appropriate committee.
| Issue | Primary oversight | Supporting oversight | Management responsibility |
|---|---|---|---|
| AI strategy and material investment | Full board | Technology; audit on financial assumptions | CEO, CFO, business leaders |
| Financial reporting and related controls | Audit | Technology where system changes matter | CFO, controller, CIO |
| Enterprise AI risk appetite | Full board | Risk; audit within its remit | CEO, CRO or designated risk owner |
| System inventory and risk classification | Risk or designated lead committee | Technology; audit for relevant controls | CAIO or CIO and system owners |
| Cybersecurity and agent permissions | Risk or existing cyber-oversight committee | Technology | CISO, CIO, operational owners |
| Data permissions and legal exposure | Risk or designated committee | Audit where relevant | GC, privacy lead, data owners |
| Supplier and model concentration | Risk | Technology; audit on material commitments | Procurement, CIO, CAIO, CFO |
| Material incidents | Full board or designated committee, by severity | Relevant specialist committee | Incident lead, CEO, GC, affected functions |
| Executive incentives and accountability | Compensation | Full board | CEO, CHRO, CFO |
| Board capability and charter gaps | Nominating and governance | All committee chairs | Corporate secretary, GC |
The value of this table is in what happens afterward. Each committee should know what evidence it expects, which executive supplies it and how exceptions reach the full board.
Write down the handoffs
The difficult issues usually cross committee boundaries. A control failure can become a customer issue. A vendor decision can become a strategic dependency. A workforce proposal can undermine the return forecast presented to audit.
For each major issue, record the lead oversight body, supporting committee, accountable executive and the condition requiring full-board attention. Add the next review date so that coordination has a deadline.
For the hypothetical claims program, an allocation note might read:
This is an illustrative note, not charter language to adopt without review. Its advantage is specificity: the COO knows which evidence to provide, and each committee knows where its judgment ends.
The coordinator should receive the conclusions from all three committees, including unresolved differences. Three green status labels are not a substitute for that reconciliation. Minutes and action logs should show who will resolve each open question and when.
Adapt the arrangement to the company
A smaller private company may need a full-board discussion and one named management owner, not a new committee. Adding a committee without additional expertise can create paperwork rather than oversight.
A venture-backed company may need to distinguish ordinary product iteration from a material change in what the system is allowed to do. The governance arrangement should make that boundary visible without requiring directors to manage releases.
A public company should connect AI oversight to existing reporting, control and disclosure processes. A regulated business should also consider its sector-specific obligations. An AI-native company may require particularly frequent strategic attention, because AI performance is part of the core product rather than a supporting tool.
In every case the organizing question is the same: which decisions deserve board attention, and who makes sure they arrive there?
Test the structure before approving a rollout
Return to the claims example. Management's business case assumes that most claims can proceed without human review. Risk's recommendation assumes that reviewers will check every consequential decision. Both committees may have approved a reasonable proposal, but they have not approved the same proposal.
The coordinator's task is to surface that conflict. Management must then produce one operating plan with a consistent cost model, control design and level of residual risk. The full board considers the strategic tradeoff where it falls within its reserved authority. Directors do not redesign the workflow themselves.
At the next governance review, ask the corporate secretary and management to bring a one-page allocation map for the company's most consequential AI uses. Each should have a lead committee, a management owner and an escalation condition. Any blank cell is an unresolved assignment, not a reason to create another presentation.
For the questions directors should ask once responsibility is assigned, see the ten AI questions every board director should ask management. For recurring oversight information, see the board AI dashboard. Those tools serve different purposes from the allocation proposed here.
Where directors compare oversight structures
Open Future Forum brings directors and executives together for AI and board governance conversations. The useful outcome is not one committee structure copied across companies. It is a structure each board can explain and use.
Last updated: September 17, 2026
Frequently Asked Questions
Where Directors Compare Oversight Structures
Open Future Forum runs a Public Board Member Dinner Series for directors of public and late-stage companies, alongside the executive forums for each C-suite seat.