What Boards Should Be Asking Before Approving an AI Strategy
Why AI Strategy Requires More Than Just IT Department Approval
I keep seeing the same problem when I work with companies exploring AI. Someone walks into the boardroom with an AI strategy. The presentation sounds impressive: Automation. Efficiency. Productivity. Transformation. Cost savings. Competitive advantage.
Then everyone looks toward the IT person as if they are automatically the most qualified person in the room to determine whether the strategy makes sense. That is where I think many organizations are making their first mistake.
AI is technology, but AI strategy is not simply an IT strategy.
Your IT department absolutely belongs in the conversation. Cybersecurity belongs in the conversation. Data belongs in the conversation. But so do operations, legal, compliance, finance, human resources, risk, customer experience, and executive leadership. And increasingly, so does the board.
Think about it this way. A traditional mechanic may be extremely skilled at repairing an engine. But hand that same mechanic a highly computerized smart vehicle filled with sensors, software, machine-learning systems, cameras, automated decision-making, and constant data exchange, and suddenly, understanding the engine is only part of understanding the car.
AI creates a similar shift inside organizations. Knowing infrastructure, networks, databases, and software does not automatically mean someone understands AI governance, model behavior, hallucination risk, data provenance, human oversight, algorithmic bias, third-party model exposure, or the business consequences of deploying AI into a workflow.
Those are different questions. And boards need to start asking them.
Before Approving an AI Strategy, I Would Want Answers to These Questions
1. What Business Problem Are We Actually Solving?
"We need AI" is not a strategy.
What are we trying to improve? Revenue? Customer response time? Operational efficiency? Fraud detection? Research? Employee productivity? Decision support?
Before approving technology, boards should understand the business case. If nobody can clearly explain the problem AI is supposed to solve, I would not approve the solution yet.
2. Where Exactly Will AI Be Making or Influencing Decisions?
There is a huge difference between using AI to summarize an internal meeting and using AI to recommend whether someone receives credit, employment, healthcare, insurance, housing, or another significant opportunity.
Boards should know where AI sits in the decision chain.
Is AI providing information? Making recommendations? Creating customer-facing content? Triggering an automated action? Or effectively making the decision?
Those distinctions matter.
3. What Data Is Being Fed Into These Systems?
This question needs to go much deeper than: "Is our data secure?"
I want to know: Where did the data come from? Who owns it? Do we have permission to use it? Does confidential company information leave our environment? Can customer data become training data? What information are employees allowed to enter? What information is prohibited? What happens to prompts, uploaded documents, and outputs?
Data governance and AI governance overlap, but they are not the same thing. A company can have excellent data governance and still deploy AI irresponsibly.
4. Who Is Accountable When the AI Gets It Wrong?
Not who gets blamed. Who is accountable?
There should be an actual answer.
AI can produce remarkably convincing information that is completely incorrect. So if an AI-generated recommendation causes financial loss, reputational damage, customer harm, or a compliance problem, who owns that risk?
The vendor? IT? The employee who used the system? The department head? The executive team?
If accountability becomes unclear the minute the system fails, governance was never properly designed.
5. Where Is the Human Oversight?
"Human in the loop" has become one of those phrases organizations like to put into AI presentations.
I want to know what it actually means.
Which decisions require human review? Who performs that review? Are they trained enough to recognize when AI is wrong? Do they have the authority to override it?
Or are we putting a human in front of a screen who simply clicks "approve" because the computer appears confident?
Human oversight without competence or authority is not meaningful oversight.
6. How Was This System Tested Before Deployment?
I would want to see more than a vendor demonstration.
How did it perform with our workflows? Our customers? Our terminology? Our data? Our edge cases? Our regulatory environment?
What happens when users intentionally misuse it? What happens when bad information is entered? What happens when the AI confidently gives the wrong answer?
A polished demo tells me what the system can do when everything goes right. Governance asks what happens when something goes wrong.
7. How Dependent Are We Becoming on the AI Vendor?
This is one I believe boards will eventually wish they had asked much earlier.
What happens if the vendor changes pricing? Changes its model? Changes its privacy policy? Removes a feature? Gets acquired? Experiences an outage? Stops supporting the product?
Can we retrieve our information? Can we migrate the workflow? Does the organization understand how the process works without the vendor?
You do not want your AI strategy to quietly become your vendor's business strategy.
8. What Risks Are We Introducing That Did Not Exist Before?
Every efficiency creates a new risk profile.
AI may reduce labor in one area while increasing exposure somewhere else: Cybersecurity. Intellectual property. Bias. Privacy. Regulatory risk. Misinformation. Brand reputation. Customer trust. Workforce displacement. Third-party dependencies.
Boards should not ask whether AI has risks. Of course it does.
The question is whether the organization understands those risks, has defined its tolerance for them, and has controls appropriate to the impact.
9. What Will We Measure After Deployment?
An AI strategy should not end when the system goes live.
What tells us this implementation is successful? Hours saved? Revenue generated? Errors reduced? Conversion increased? Customer satisfaction improved? Operating costs reduced?
Then comes another category of measurement: How often is the system wrong? How often does a human override it? What types of incidents are occurring? Has its performance changed over time? Are employees using unauthorized AI systems outside the approved environment?
You cannot govern what nobody is monitoring.
10. Who Inside This Organization Actually Understands AI Well Enough to Challenge the Strategy?
This may be the most uncomfortable question. And boards need to ask it anyway.
Who in the room has enough AI knowledge to challenge the vendor? Who can challenge the consultant? Who can challenge IT? Who understands the business implications? Who understands the governance implications? Who can explain where automation should stop?
If everyone around the table is depending on the person selling or implementing the AI to explain whether the AI is safe, appropriate, and strategically sound, there is an obvious oversight gap.
That does not necessarily mean every board suddenly needs a computer scientist. It does mean boards need access to legitimate AI competency.
AI Literacy Is Becoming a Governance Issue
Organizations are moving beyond experimenting with ChatGPT in the office. AI is increasingly being embedded into workflows, customer interactions, analytics, hiring, marketing, software development, financial processes, and executive decision-making.
Governance frameworks are moving in the same direction. International AI management standards now emphasize organization-wide responsibility, defined roles, risk assessment, monitoring, and continual improvement. Regulators are also increasingly focusing on meaningful human oversight and whether the people supervising certain AI systems actually have the competence and authority to do so.
This should tell boards something important:
AI governance cannot live exclusively inside the IT department.
The IT department should absolutely have a seat at the table. It just should not be the only seat.
Boards should be thinking about AI the same way they think about financial risk, cybersecurity, legal exposure, executive succession, and corporate strategy.
Not because directors need to understand every technical component underneath an AI model. They don't. But they need to understand enough to recognize when the organization has not asked the right questions.
That is governance.
Because approving an AI strategy should never come down to: "The technology team said it's fine."
The better question is:
"Have we demonstrated that this AI strategy is valuable, governable, measurable, and aligned with the level of risk this organization is prepared to accept?"
If the board cannot get a clear answer to that question, the organization probably isn't ready to approve the AI strategy yet.
And sometimes the biggest AI risk in the boardroom isn't the technology.
It's not having anyone in the room who knows what questions to ask.
- Jamilah N. Lawry
AI Consultant | Business Strategist | Technology & Governance Thought Leader