Skip to content

AI Board Wake-Up Call

Get your board fluent in the AI decisions in front of it.

The AI Board Wake-Up Call is a board literacy session for chairs, boards and company secretaries. In one focused session, directors build a shared language for AI risk, learn the questions to ask of any AI decision, and leave with an honest read of where the organisation is exposed.

Scoped to your board.

A 15-minute call settles the format, the audience and the fee.

Built for the people who answer for AI.

Chairs

You have to lead the board's AI conversation. The session gives you the ground to lead it from.

Boards

Directors are accountable for AI before they are comfortable with it. The session closes that distance.

Company secretaries

You have to put AI on the agenda and keep it there. The session gives the board a reason to hold it.

What the board leaves with.

  • A shared language for AI risk, so the board can discuss it without translation
  • The questions to ask of any AI decision: what to ask, what to govern, and what to leave alone
  • An honest read of where your organisation is exposed

What board AI training covers.

The session starts from the decisions already in front of the organisation: a supplier to approve, staff using public models, a customer-facing tool, or an AI feature that appeared inside software you already bought. Directors do not need to know what a transformer is. They need to know whether the organisation can evidence that a system is lawful, controlled, secure and inside its risk appetite.

What counts as AI here

A working definition broad enough to catch the features suppliers switched on inside existing software, and the tools teams adopted without sign-off. Security and control run across the whole life cycle, not the launch.

The UK regulatory map

There is no single AI statute. Regulators apply cross-sector principles inside their own remits, and those principles reach you through sector rules, data protection law, procurement duties and board reporting.

What evidence looks like

Registers, impact assessments, approval records, supplier answers, incident logs, training records and human-review evidence. A verbal assurance that governance is in place is not the standard an auditor or a serious customer applies.

The controls lens

ISO/IEC 42001 is the management-system spine. The NIST AI RMF is the risk cycle: govern, map, measure, manage. The session turns both into questions a director can ask without a technical brief.

What changes on Monday

Training that leaves everyone better informed but changes no agenda, no owner and no evidence request has not done enough. The session ends in named follow-up actions.

The six questions the board keeps.

The frame is what makes the session reusable. It keeps the board out of management detail without leaving it dependent on reassurance. A chair can ask whether a DPIA exists without deciding the lawful basis in the room.

  1. What AI use is already in scope?

    Ask for a system inventory, including supplier features and tools adopted without formal approval.

  2. Who owns each system?

    Ask for one named accountable owner per system, not a working group.

  3. Which rule reaches it?

    Map the system to UK principles, data protection obligations, sector rules, EU AI Act exposure where relevant, and any contractual duties.

  4. What control makes the rule true?

    Name the approval gate, human-review route, security test, bias check, access constraint or supplier obligation.

  5. What evidence proves the control operated?

    Ask for dated artefacts, not policy statements.

  6. What changes before the next meeting?

    Convert the gap into an owner, a date and a board reporting item.

What the board should be able to ask for afterwards.

Training is only useful if directors leave knowing what proof looks like. This is the minimum evidence set a board should recognise.

Board questionControl to expectEvidence to ask forOwner
Where is AI already used?AI system inventory and an intake route for new usesCurrent register, with owner, purpose, data types, supplier and review dateExecutive AI owner or risk lead
Are people affected by a decision?Human-review route for significant decisionsReview procedure, override records, complaint route and response timesService owner, legal or DPO
Does it process personal data?Data protection impact assessment before go-liveCompleted DPIA, lawful-basis analysis, privacy notice changes and residual-risk sign-offDPO or data protection lead
Is the system secure?AI-specific security assessment and incident routeThreat model, access controls, monitoring logs and incident playbookCISO or technology lead
Is supplier AI controlled?Procurement and contract questions for AI featuresSupplier due diligence, model-change notification clauses and data-use termsProcurement and legal
Can the board evidence capability?Board and staff AI literacy planTraining attendance, board skills matrix update and a scheduled refreshChair, company secretary or people lead

How the session maps to frameworks.

Framework mapping stops a board session becoming an opinion exercise. No board adopts all six after one sitting. It does need to know which one answers which question.

Framework or ruleWhat it asks of the boardWhat the session produces
UK cross-sector principlesUnderstand how regulators apply safety, transparency, fairness, accountability and contestability within their remitsA principle-to-control question set for your main AI uses
ICO AI and data protection guidanceDemonstrate accountability wherever AI processes personal dataDPIA questions, an owner map and evidence-pack expectations
EU AI Act, Article 4Ensure sufficient AI literacy among staff and others dealing with AI on your behalf, where you are in scopeA role-based literacy plan, with board exposure to duties, risks and safeguards
ISO/IEC 42001Put policies, objectives and processes in place for responsible AI managementA management-system view of policy, controls, evidence and assurance
NIST AI RMFGovern, map, measure and manage AI risk across the life cycleA repeatable board agenda: inventory, risk mapping, measurement evidence, action tracking
NCSC secure AI guidanceTreat AI security as a life-cycle issue across design, development, deployment and operationSecurity questions for procurement, release, monitoring and incident response

One session is not a governance programme. AI capability, regulation and supplier behaviour move too quickly for an annual lecture to stay current, so the record should show the date, the audience, the agenda and the planned refresh. If you want the wider structure the training sits inside, read our guide to the AI governance framework UK organisations actually need, then 20 questions every UK board should ask about AI.

Where it sits in the work.

Three steps, each proportionate to the commitment your board is ready to make. You commit one step at a time.

Board AI Scorecard

Start free. Ten questions, about two minutes, and a readiness score for your board.

Take the Scorecard

AI Board Wake-Up Call

The low-friction entry: a focused board session, scoped to your board.

This page.

GovernIQ™ Diagnostic

Go deeper: a structured read of where your AI governance actually stands, from £3,950.

About the diagnostic

Start with a 15-minute call.

Tell us about your board. We will tell you plainly what the session would cover, and whether it is the right first step for you.