Governance
Most board discussions of AI deployments focus on the opportunity. These five questions focus on the governance. They tend to reveal whether the deployment has a defensible oversight structure or a liability gap in waiting.
A company wants to deploy an AI system. Maybe it automates underwriting decisions. Maybe it surfaces recommendations to sales teams. Maybe it runs in the background, flagging anomalies in financial data. The business case is clear. The presentation is polished. The timeline is already in the plan.
The board approves it.
That approval is a governance decision. In most boardrooms, it is made without the five questions that would tell directors whether the deployment is safe to approve.
The relevant question is not who built it. The question is who is accountable when it produces a bad outcome. Is there a named individual with authority to halt the system? Is there a documented escalation path from model output to executive decision? Has the board approved that accountability structure?
The right answer is a documented chain of accountability that the board has reviewed. AI systems operating without a clear owner tend to produce incidents without a clear responsible party. That scenario generates the most director exposure.
AI systems require testing that differs fundamentally from traditional software QA. Bias testing. Adversarial testing. Out-of-distribution performance evaluation. Red team exercises. The relevant question is whether the right kinds of testing were done, by people with appropriate independence from the team that built the system.
Boards are not expected to evaluate model architecture. They are expected to ask whether the testing process was adequate and who signed off on it. If the answer is that the product team tested it themselves, that is a governance gap.
Every AI system will eventually produce an unintended output. The governance question is whether the organization has a clear, pre-documented pathway from "something unusual happened" to "the board is aware and has authorized a response." That pathway should exist before deployment.
Directors should ask to see the incident response plan for the AI system. A specific protocol that addresses what happens when the AI system produces a harmful, biased, or unexpectedly consequential output.
Most D&O policies do not automatically cover AI-related governance failures. The handoff between D&O, cyber, and E&O coverage is where AI exposure tends to hide. The answer to "are we covered" is almost never a simple yes.
Before approving a significant AI deployment, the board should have a documented assessment of how the existing coverage architecture responds to AI-related incidents. That assessment should come from counsel or the risk function.
Reversibility is a governance principle as much as a technical feature. The board should know whether the AI system can be halted or rolled back, what the operational impact of doing so would be, and who has the authority to make that decision without board approval.
Agentic AI systems that take autonomous actions, interact with other systems, or make sequential decisions without human review raise this question with particular urgency. A system that cannot be turned off without significant operational disruption is a system the board has less governance control over than it may realize.
None of these questions require technical expertise. They require the same structured oversight discipline that boards apply to financial risk, legal exposure, and operational resilience. The fact that AI is new does not change the governance obligation. It requires applying that obligation to a new class of decision.
Boards that ask these questions before approval build the oversight records that will matter when something eventually goes wrong.
The Compass is where every Vela engagement begins. Request access or a briefing to see what it surfaces for your board.