andremagrini.com

AI Governance Framework for Corporate Boards - article by Andre Magrini

Written by

in

AI REVENUE AND GOVERNANCE

AI Governance Framework for Corporate Boards

A board AI governance framework covering materiality, ownership, risk tiers and incidents, plus the five questions a standard risk register will never surf

7 minute read
AI Governance Framework for Corporate Boards - article by Andre Magrini

BUYER GUIDE · UPDATED AUGUST 26, 2026

AI Governance Framework for Corporate Boards

A practical board AI governance framework covering materiality, ownership, evidence, risk tiers, human control, reporting and incidents, plus the five questions a standard risk register will not surface.

Direct answer. A board AI governance framework should identify material systems, assign accountable executives, define risk tiers and evidence standards, require human controls, monitor exceptions, and establish escalation and incident reporting. It should also contain at least one question about competitive displacement, which standard risk frameworks systematically omit.

Start with materiality

Boards do not need an inventory of every productivity tool. They need visibility into AI that affects customers, revenue, safety, employment, regulated decisions, financial reporting, intellectual property, security and strategic dependency.

The practical test for materiality is not how advanced the system is. It is what happens when it is wrong. A model that drafts internal meeting notes and a model that scores credit applications may use identical technology and belong in entirely different oversight categories.

Three questions establish materiality quickly:

  • Does a customer, employee or regulator experience the output of this system?
  • Would a systematic error in it appear in the financial statements, a regulatory filing, or a headline?
  • If it stopped working tomorrow, would a revenue line or an operating process stop with it?

Any yes puts the system on the board’s map. Everything else belongs to management.

Assign decision rights and evidence

Every material system needs a named executive owner, a stated intended use, documented known limitations, defined approval authority, a monitoring plan, a human intervention point, vendor obligations, and a record of why deployment was considered acceptable at the time.

That last item is the one most often missing and the one that matters most in hindsight. Boards routinely receive a description of what a system does. They rarely receive the reasoning for why the risk was accepted. When something goes wrong two years later, the absence of that record is what turns a defensible decision into an indefensible one.

The standard is not perfection. It is that a competent outsider could reconstruct why a reasonable person approved this.

Use risk tiers to match oversight

Low-consequence assistance should not receive the same process as a consequential customer or financial decision. Risk tiers should change testing, approval, monitoring, disclosure, human control and board reporting requirements.

A workable three-tier structure:

TierDefinitionWhat changes
AdvisoryProduces a recommendation a person acts on, with the person’s own information availableManagement oversight. No board reporting unless it moves tier
ConsequentialMaterially shapes a decision affecting a customer, employee, regulator or the financial statementsNamed owner, documented limitations, monitoring plan, defined intervention point, periodic board summary
ActingTakes an action or completes a transaction without a person approving that specific instanceExplicit board awareness, pre-approved action boundaries, kill authority named, incident reporting by default

The tier boundary that matters most is between the second and third. A system that recommends and a system that acts are different governance objects, and the distinction is often lost because the vendor calls both of them an assistant.

Boards should be able to answer one question at any time: which of our AI systems can take an action rather than make a recommendation, and who can stop them.

Review incidents and near misses

Governance improves when exceptions, overrides, drift and failed assumptions are reviewed. A board should understand whether the control system detected the issue, whether people acted, and what changed afterward.

Near misses matter more than incidents here, and they are the harder thing to get reported. An override that a person made correctly is evidence the control worked. An override nobody made because nobody noticed is the finding, and it will not appear in an incident log by definition.

Ask for the override rate, not only the incident count. A material system with a zero override rate over a quarter is either performing perfectly or is not being checked, and those two look identical on a dashboard.

The five questions a risk register will not surface

Here is the part most board AI frameworks, including the earlier version of this one, leave out.

A risk register is built to catalog threats: things that could happen to the company. Cyber breach, regulatory action, model failure, vendor outage, reputational harm. That is the correct design for a risk function, and it is complete on its own terms.

The largest AI risk to most companies is not a threat. It is a competitor. And competitors do not appear in risk registers, because a risk register is not built to hold them.

This is measurable. In Gartner’s 2Q26 Emerging Risks Survey of 316 risk management leaders, auditors and senior executives, respondents were asked to score twenty emerging risks and their organizations’ level of attention to each. The survey plots the gap. AI-driven competitive displacement appears as the leading potential blind spot: scored high on risk, receiving low attention. AI platform lock-in and AI-driven skill erosion sit in the underattended half as well, while the risks receiving the most attention are the recognizably risk-shaped ones: agentic AI, AI discovery of cyber vulnerabilities, energy supply shocks and information integrity.

That pattern is not a failure of competence. It is a boundary problem. Risk owns threats. Strategy owns competition. The AI risk with the largest expected effect on revenue sits on the line between them, and lines are where things get dropped.

Five questions close the gap. None of them belongs on a standard risk register, and all of them belong in a board meeting.

1. Which of our revenue lines could a competitor deliver at materially lower cost using AI, and how long would that take them?

Name the line and the timeline. If nobody can answer, that is the answer. This is competitive displacement stated as a number rather than a category.

2. If our primary AI vendor doubled its prices, what happens to our gross margin?

Platform lock-in is scored low and attended to less, which is exactly the profile of a risk that arrives suddenly. If your cost of delivery runs through one vendor’s pricing, that vendor holds a lever on your margin. Boards routinely test customer concentration and rarely test supplier concentration on this dimension.

3. What decisions can our people no longer make without the tool?

Skill erosion is the slowest of these risks and the hardest to reverse. It shows up first as capability that quietly relocated from the organization into a subscription, and it is only visible when the tool is unavailable or when a novel case arrives.

4. Which of our AI systems can take an action rather than make a recommendation, and who can stop them?

The tier three question from the section above, asked directly. This is the one risk in the set that boards do reliably ask about, and it is worth asking precisely rather than generally.

5. What do we know that our competitors cannot buy?

The inverse of question one, and the only one with an upside answer. Proprietary operating knowledge is the asset AI makes more valuable rather than less, because models amplify whoever holds better material. If the answer is nothing, the company is competing on a capability that is available at list price to everyone in the market.

What a board should receive quarterly

One page, not a deck.

  • Material systems by tier, with any tier changes since last quarter
  • Named owner per material system, with changes flagged
  • Override and exception rates on tier two and three systems, with the trend
  • Incidents and near misses, with what changed as a result
  • One paragraph on question one above, updated by management, even when the answer has not moved

That last line is the discipline. A displacement question asked once becomes a slide. Asked every quarter, it becomes a habit of looking, and looking is the entire control.

OPERATING EVIDENCE

Operating evidence

In executive advisory work, the first value often comes from stopping low-readiness pilots, clarifying decision rights, and moving resources toward use cases with measurable workflow evidence. Client-identifying details are disclosed only with authorization.

Read the operating case: more than 4x revenue growth in three years

Questions boards ask

What should be in an AI governance framework for a board?

Materiality criteria, a named executive owner per material system, risk tiers that change the level of oversight, documented limitations and approval reasoning, human intervention points, incident and near-miss review, and quarterly reporting. It should also include at least one standing question about competitive displacement, which standard risk registers omit by design.

Why is AI competitive displacement missing from most risk registers?

Because a risk register catalogs threats to the company, and a competitor is not a threat in that sense, it is a market condition. Risk functions own threats and strategy owns competition, so the risk sits on the boundary. In Gartner’s 2Q26 Emerging Risks Survey of 316 risk leaders and executives, AI-driven competitive displacement appeared as the leading blind spot, scored high on risk and receiving low attention.

How many risk tiers should we use?

Three is usually enough: advisory, consequential and acting. The important boundary is between systems that recommend and systems that act without a person approving the specific instance. Vendors often describe both as assistants, so the distinction has to be made internally.

How often should a board review AI?

Quarterly for material systems, on one page. Incidents and tier changes should be reported when they happen rather than held for the cycle.

What is the most commonly missing item in board AI reporting?

The reasoning behind the original approval. Boards receive descriptions of what systems do and rarely receive the record of why the risk was considered acceptable. That record is what makes a decision defensible in hindsight, and it cannot be reconstructed after an incident.

Sources

  1. Gartner Quarterly Emerging Risk Report, 2Q26. Data from the 2Q26 Gartner Emerging Risks Survey, n = 316 risk management leaders, auditors and senior executives, with trend data drawn from the 3Q25, 4Q25, 1Q26 and 2Q26 surveys. Used for the emerging risk misalignment quadrants and the identification of AI-driven competitive displacement as a leading potential blind spot.

Apply this to your company

Diagnose the operating constraint before adding more activity, tools or AI.

Request an AI Revenue Diagnostic

About the author

Andre Magrini is a chief revenue officer and fractional CRO based in the Greater Chicago Area. He led North America for Ag Growth International and, as general manager in Brazil, scaled an operation more than 4x in three years. He served as Vice President of the Marketing and Communications Committee at the American Feed Industry Association, and is the author of seven books, including five on sales, marketing analytics and corporate governance.

APPLY THE THINKING

Turn this analysis into an accountable operating decision.

Start with the revenue, GTM, RevOps, governance, or AI constraint that matters most.

Request an AI Revenue Diagnostic

EVIDENCE AND NEXT STEPS

Continue with the source, the complete guide, and the scorecard.

More posts