What boards are accountable for
A board does not need to run AI, and directors do not need to be AI experts. What directors are accountable for is oversight: understanding the material AI risks and opportunities facing the organisation, making informed decisions about them, and being able to show that the oversight actually happened.
That is a governance responsibility, and it is being tested more sharply as AI moves from experiment to core operation. The board that can point to a structured, evidence-based view of its AI exposure is in a very different position from one relying on management’s reassurance.
The Questions
What boards should be asking about AI
Good AI oversight comes down to a small set of questions. If management can answer all of them with specifics, the board has genuine visibility. If the answers come back as generalities, that gap is itself the finding.
Where does AI expose the organisation, and how much?
Exposure is not uniform. Some functions face acute pressure from AI-native competitors while others change little for now. The board needs a structured read of which exposures are material, not a general sense that AI matters.
Is management running a strategy, or a list of pilots?
A chatbot here and a Copilot rollout there is activity, not strategy. The board should be able to see the strategic thesis, the sequence and the owners, and test whether investment is going where the exposure actually is.
Which of our moats survive AI, and which no longer do?
Some defensive advantages continue to protect the organisation through the transition. Others looked defensible but no longer are. Oversight starts with an honest reading of which is which.
Are we investing in the right order, with accountability?
Strategy without a sequenced plan is decoration. The board should be able to see what comes first, who owns it, what it costs and what success looks like.
Can we evidence our oversight against a recognised framework?
Increasingly, directors are expected to show that AI risk was governed against a named standard. Being able to map decisions to a framework such as the NIST AI Risk Management Framework is part of discharging the duty.
Are we meeting our obligations in every jurisdiction we operate in?
An organisation operating across Australia and the United States answers to different regulators and policy instruments in each. Oversight has to account for the obligations that actually apply, jurisdiction by jurisdiction.
The Frameworks
The frameworks that shape it
AI governance does not sit in a vacuum. Depending on where an organisation operates and the sector it is in, a set of regulators and voluntary frameworks shape what good oversight looks like. For organisations spanning Australia and the United States, both sets apply.
United States
NIST AI Risk Management Framework (AI RMF 1.0)
The voluntary framework boards are increasingly held to, structured around four functions: Govern, Map, Measure and Manage.
SEC
Public-company boards answer to the Securities and Exchange Commission on disclosure and oversight of material risk.
FINRA, Federal Reserve and OCC
Sector oversight for regulated finance.
FDA and CMS
Sector oversight for health and life sciences.
Australia
ASIC
Directors’ duties, including the duty of care and diligence, sit under the Australian Securities and Investments Commission.
APRA
Prudential oversight for regulated banking, insurance and superannuation.
OAIC (Privacy Act 1988)
Privacy obligations for the personal information AI systems handle.
AI Ethics Principles (Dept of Industry, Science and Resources)
The voluntary ethical guardrails for AI deployment in Australia.
Public-sector boards and agencies work within additional policy frameworks: in the US, Executive Order 14179 and OMB Memorandum M-25-21; in Australia, the National Framework for AI in Government and the Policy for Responsible Use of AI in Government.
A Closer Look
The NIST AI RMF, in brief
The NIST AI Risk Management Framework is the reference many boards map their oversight to. It is voluntary, and it is organised around four functions. A board that can show its decisions against these is a long way toward demonstrable oversight.
01
Govern
A culture of AI risk management: accountability, roles and policies for how the organisation manages AI risk.
02
Map
The context. Where AI is in use, and the risks and impacts that come with it.
03
Measure
Assessing, analysing and tracking those risks with evidence rather than assumption.
04
Manage
Prioritising and acting on the risks that matter most.
How Mireto Helps
Giving the board an evidence base
Mireto is not a compliance system, and it does not replace legal or risk advice. What it does is give the board the evidence base that good oversight depends on: a structured, defensible read of where AI exposes the organisation, scored across eight weighted dimensions against real evidence about the business, its peers and its industry.
That maps directly onto the Map and Measure work a governance framework asks for. The AI Disruption Score names where the pressure is; the AI Executive Presentation puts it in board-ready form; and because a scan can be re-run, the picture stays current rather than dating between meetings.
What the AI Disruption Score measures · The methodology behind it · For government and public sector
Common Questions
AI governance FAQ
What is AI governance for a board?
AI governance is how a board oversees the risks and opportunities AI creates for the organisation it is responsible for. It means understanding where AI exposes the business, holding management accountable against recognised frameworks, and being able to evidence that oversight.
Is the NIST AI Risk Management Framework mandatory?
No. The NIST AI RMF is a voluntary framework. But it has become the reference standard many boards, regulators and customers expect AI risk to be managed against, so aligning to its Govern, Map, Measure and Manage functions is a practical way to demonstrate oversight.
What are directors accountable for regarding AI?
Directors are accountable for overseeing material AI risk and opportunity, making informed decisions about it, and being able to show that the oversight happened. That is a governance responsibility, not a technical one, and it does not require directors to be AI experts.
How does an AI Disruption Score help a board?
It gives directors a structured, defensible read of where AI exposes the organisation, scored across eight dimensions, rather than a general impression. That evidence base is exactly what the Map and Measure work in a governance framework calls for, and the Executive Presentation puts it in board-ready form.
Does this cover Australian and US frameworks?
Yes. The assessment applies jurisdiction-appropriate regulators and policy frameworks for organisations in both Australia and the United States, so the oversight reflects the obligations that actually apply where the organisation operates.
More questions? See our full FAQ or get in touch.