Board directors are not technologists. They are not expected to be. What they are expected to do is exercise sound judgment on matters that carry material risk to the organisation — financial, reputational, regulatory, and strategic. Artificial intelligence now sits squarely in that category, and yet the briefings most boards receive on AI governance are either impenetrable technical documents or surface-level presentations that leave directors with no actionable insight whatsoever.
For senior advisors working with regulated organisations, this is both a problem and an opportunity. Getting AI governance right at the board level requires more than good slides. It requires a disciplined approach to translation — converting the genuine complexity of AI risk into the fiduciary vocabulary boards already use every day. This article sets out how to do that, anchored in the Find. Fix. Flow. diagnostic model that Navitec AI uses to structure AI governance advisory engagements.
Why Most AI Governance Briefings Fail at the Board Level
The failure mode is almost always one of two things: too much, or too little.
The too-much version arrives as a dense briefing pack full of references to large language models, model drift, algorithmic bias, and data lineage — terminology that means nothing to a director whose background is in law, finance, or operations. They nod through the presentation, ask no questions (because they do not know what to ask), and approve a governance framework they do not truly understand. This is not governance. It is the performance of governance.
The too-little version is the opposite problem. An advisor, anxious not to confuse, strips all substance from the briefing and delivers a set of high-level principles so generic they could apply to any technology from spreadsheets to satellites. Directors leave feeling they have been briefed but possessing no greater capacity to challenge management, interrogate AI-related decisions, or identify where the organisation is genuinely exposed.
Both failures stem from the same root cause: the briefing has been designed around the technology, not around the board's actual role. Directors do not need to understand how a machine learning model works. They need to understand what their oversight responsibilities are, where the material risks sit, and what questions they should be asking management on an ongoing basis.
A third, subtler failure is timing. Many organisations bring AI governance to the board only after something has gone wrong — a regulatory inquiry, a media incident, a model that produced discriminatory outputs. At that point, the conversation is reactive and defensive. The advisors who create lasting value are those who build a proactive governance posture before the incident, not after it.
Translating AI Risk Into Fiduciary Language Directors Already Speak
The most effective move an AI governance advisor can make is to stop treating AI as a special category and start mapping it onto the risk language boards already use fluently.
Boards understand credit risk, liquidity risk, conduct risk, and operational risk. They understand the concept of a material threshold — the point at which an issue requires escalation. They understand accountability structures, delegated authority, and the principle that risk ownership must sit with someone who has both the authority and the information to manage it. These are not foreign concepts. They are the grammar of board-level governance.
AI risk maps directly onto this grammar once you make the translation explicit.
Model risk is not a new concept in regulated industries — banks have had model risk management frameworks for years, as reflected in longstanding supervisory guidance such as the SR 11-7 guidance on model risk management issued by the US Federal Reserve and OCC. Extending that concept to AI systems, including generative AI and third-party models embedded in vendor products, is a natural extension of existing practice, not a leap into the unknown.
Third-party and supply chain risk applies directly to organisations using AI through APIs, software platforms, or outsourced services. When a vendor's AI model produces a flawed output that affects a customer, the organisation that deployed it carries the reputational and regulatory consequence. Boards understand vendor risk. They need to understand that AI vendor risk has particular characteristics: it can be opaque, it can change without notice when a vendor updates their model, and it can scale at a speed that traditional vendor oversight processes were not designed to handle.
Conduct risk is immediately legible to boards in financial services and increasingly relevant across all regulated sectors. Any AI system that touches customer decisions — pricing, eligibility, communications, complaint handling — creates conduct risk. Framing it this way transforms AI governance from an IT conversation into a compliance conversation, which is exactly where board attention belongs.
Reputational risk requires no translation at all. Show a director a news headline about an organisation that deployed a biased AI recruitment tool or a chatbot that gave harmful advice, and the relevance is immediately clear.
The advisor's job is to build these bridges consistently, so that when an AI risk is presented, the board hears it in a language they can act on.
The Find. Fix. Flow. Framework: A Board-Ready Diagnostic Model
Navitec AI's Find. Fix. Flow. model provides a practical structure that works at every stage of an AI governance engagement — from the initial diagnostic through to ongoing board reporting. It is useful precisely because it is simple without being simplistic.
Find is the diagnostic phase. Before any governance framework can be meaningful, an organisation needs to know what AI it actually has in operation. This is not as straightforward as it sounds. In many organisations, AI has been deployed incrementally — embedded in vendor products, built by individual teams, or adopted through shadow IT processes — without any central inventory or oversight. The Find phase surfaces this landscape: what AI systems are in use, what decisions they influence or automate, what data they consume, and what regulatory obligations attach to each system.
At the board level, the Find phase translates into a simple but powerful question: Do we have a complete and current inventory of the AI systems operating in our organisation? If the answer is no — and in many organisations it is — that is itself a material governance gap. Boards should be asking management to close it, with a defined timeline and ownership.
Fix is the remediation phase. Once the AI landscape is visible, gaps in governance, documentation, testing, and oversight can be identified and prioritised. Not every gap carries the same risk. A low-stakes internal productivity tool that uses AI to summarise meeting notes is not in the same risk category as an AI system that influences credit decisions or patient triage. The Fix phase applies proportionate governance — appropriate documentation, accountability, and controls for each system based on its risk profile.
For the board, Fix translates into questions about prioritisation and accountability: Which AI systems have we assessed as high-risk, and who owns the governance of each? This is delegation of authority language. It is entirely familiar to any experienced director.
Flow is the ongoing phase — the normalisation of AI governance into business-as-usual processes. Governance frameworks that exist only as documents quickly become irrelevant. Flow embeds AI risk into existing risk management cycles, reporting structures, and committee accountabilities so that the board receives regular, meaningful information about AI risk without requiring a separate briefing every quarter.
For senior advisors, the Flow phase is where the most durable value is created. It is the shift from one-off advisory engagement to a sustained governance posture — and it is the phase that most AI governance work never reaches because organisations treat the initial diagnostic as the endpoint rather than the beginning.
Structuring the Briefing: What to Cover, What to Cut
A well-structured board briefing on AI governance should take no more than forty-five minutes of substantive time, with materials that can be read in twenty minutes in advance. Anything longer signals that the advisor has not done the hard work of distillation.
What to cover:
The AI landscape the board is actually governing. Not a general overview of AI trends, but a concise picture of what AI the organisation is using or planning to use, categorised by risk level. Three to five categories maximum. Directors need to know what they are responsible for overseeing.
The regulatory context. What are the specific obligations that apply to this organisation, in this jurisdiction, for these AI systems? Relevant frameworks might include the EU AI Act, sector-specific guidance from the FCA or other regulators, data protection obligations under GDPR, or emerging requirements in the organisation's operating markets. Do not list everything. Identify what is live, what is upcoming, and what requires a board-level decision.
The current governance posture against the Find. Fix. Flow. model. Where has the organisation found its AI landscape? What has been fixed, and what remains open? What is flowing through normal governance processes, and what is not? A simple traffic-light dashboard is entirely appropriate here — boards respond to visual summaries that make the state of play immediately legible.
The two or three decisions the board needs to make. Every effective board presentation ends with a clear ask. In an AI governance context, this might be: approving the formation of an AI risk subcommittee, setting a risk appetite statement for AI, endorsing a remediation timeline, or commissioning an independent review of a high-risk system.
What to cut:
Anything that explains how AI works at a technical level. The board does not need it, and including it wastes time and attention that should be focused on governance. Cut vendor names and product comparisons. Cut academic references. Cut anything that reads like it was written for a technology team.
Common Board Questions and How Senior Advisors Should Answer Them
Experienced directors will ask good questions if they have been given the right frame. Here are the questions that come up most frequently, and how an AI governance advisor should approach them.
"Are we compliant?" This is the natural first question, and it deserves a precise answer rather than a reassuring one. The honest response in most cases is: partially, and it depends on the system. Compliance with AI-related obligations is not binary. Different systems carry different requirements, and the regulatory landscape is evolving. What the board should hear is: here is what we know, here is what we are working to confirm, and here is the timeline for closing open items.
"Who is responsible for this?" This question reveals a governance gap if the answer is unclear. AI accountability must be named — not assigned to 'the business' or 'the technology team' as a collective. The advisor should be able to name the individual or role accountable for each material AI system and describe what that accountability actually means in practice.
"What happens if something goes wrong?" This is a business continuity and incident response question. Does the organisation have a process for detecting when an AI system is producing unreliable or harmful outputs? Is there a mechanism for human override? Who gets notified, and how quickly? These questions should have operational answers, not aspirational ones.
"How are we different from our peers?" Boards are often benchmarking against sector peers, whether explicitly or implicitly. A well-prepared advisor can provide a calibrated view of where this organisation sits relative to regulatory expectations and industry practice — without making unfounded claims about competitive positioning. This is an area where senior advisors with genuine sector experience add significant value.
"Is our AI vendor doing this responsibly?" This question often surfaces when there has been a public incident involving AI at another organisation. The answer should connect to the organisation's third-party risk management framework: what due diligence has been done on AI vendors, what contractual protections exist, and what monitoring is in place? If the answer is 'not much', that is a Fix priority.
Turning the Briefing Into Ongoing AI Governance Advisory Engagement
A single board briefing is a starting point, not a solution. The organisations that develop genuine AI governance capability are those where the board receives regular, structured information about AI risk as a matter of course — not as a one-off event triggered by a regulatory development or an incident.
For senior advisors, the transition from briefing to ongoing engagement requires making the case that AI governance is not a project with an endpoint. It is a continuous function, because the AI landscape itself is continuous. Models change. Vendors update their products. Regulations develop. New use cases emerge. An organisation that has a current and accurate view of its AI risks today may not have one in twelve months without deliberate effort to maintain that view.
The Find. Fix. Flow. model supports this transition naturally. Find is not a one-time exercise — it needs to be repeated as the AI landscape evolves. Fix generates a remediation roadmap that requires tracking and reporting. Flow creates the ongoing governance rhythm that keeps the board appropriately informed without requiring repeated diagnostic work.
Practically, ongoing AI governance advisory engagement might take several forms: quarterly AI risk reporting to the board or a relevant committee, periodic refreshes of the AI inventory and risk assessment, independent review of high-risk AI systems before deployment, support for management in developing AI policies and internal governance frameworks, and readiness assessments ahead of regulatory reviews.
The advisor's role in this ongoing engagement is not to replace internal capability but to provide the external perspective, sector expertise, and structured methodology that most organisations cannot maintain internally — particularly as the regulatory environment becomes more demanding and the consequences of governance failures become more significant.
For regulated organisations at every stage of AI maturity, the question is not whether to invest in AI governance advisory support. The question is whether to do it before or after the incident that makes the need undeniable. The boards that are asking the right questions now — about accountability, risk appetite, regulatory compliance, and third-party exposure — are the ones that will be in a stronger position when regulators, investors, and customers begin demanding answers.
Getting those questions right starts with a briefing that respects the intelligence of the directors in the room and gives them the language, the framework, and the practical insight they need to govern AI as confidently as they govern any other material risk in the business.