Skip to content

Topic

AI governance for UK boards

A UK board does not govern AI against a statute. It governs against duties it already holds, principles its regulators already apply, and evidence it must be able to produce on demand. The work is to name who is accountable, choose the framework that structures the evidence, and keep that evidence live.

What is a board actually accountable for on AI?

Everything the organisation's AI does, whether or not the board understands it. Directors' existing duties of care, skill and oversight extend to AI without amendment. Accountability does not transfer to the vendor or the model: it lands on the organisation that points AI at a real decision, which means it lands on the board.

This is sharper than it sounds, because most boards now answer for capability they bought rather than built. Nobody in the company trained the model, can read its weights, or can say precisely why it produced one sentence rather than another. Yet the moment the tool acts under the company's name, the board owns the outcome, and "the model decided" is not a defence any regulator will accept. We set out that position in full in Governing the Intelligence Age.

Is there a UK law on AI that boards must comply with?

No single one. The UK has no AI Act and no dedicated AI regulator. Five voluntary principles are applied by the regulators you already answer to, on top of binding law that reaches AI without naming it: UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

The five principles, confirmed in the government response of February 2024, are safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. They are deliberately abstract. They tell a board the outcomes a regulator will look for, not the controls that get there, and the space between the principle and the control is exactly the space the board must fill. Underneath the principles sits law that binds today: the ICO is lead regulator wherever AI touches personal data, and the Data (Use and Access) Act 2025 reformed the rules on significant automated decisions from February 2026. The full picture is in our guide to what UK boards govern instead of an AI Act, and every instrument is listed, dated and sourced in the UK AI Regulation Tracker.

Which framework should a board govern AI against?

ISO/IEC 42001 for the management system, with the NIST AI Risk Management Framework for risk structure. Neither is law. In the absence of a UK statute they are the most concrete, auditable evidence a board can produce that its AI is governed, and they map cleanly onto the five UK principles.

ISO/IEC 42001 produces exactly the artefacts a regulator, a procurement team or an auditor asks for: policies, named roles, risk registers, impact assessments and continual-improvement evidence. NIST's Govern, Map, Measure, Manage structure sits comfortably inside it and gives the board a defensible way to articulate how risk is identified across the AI lifecycle. One point of language matters here: only a UKAS-accredited certification body can certify an organisation to ISO/IEC 42001. A consultancy helps you align and prepare; it cannot issue the certificate. We unpack what the standard concretely asks of a board in ISO/IEC 42001 explained.

What evidence will a regulator or auditor ask to see?

Evidence that operates, not policy that sits. A named accountable owner for each AI system, a completed Data Protection Impact Assessment where personal data is processed, a record of who decided and when, and a risk register that is live, dated and owned rather than reviewed once a year.

The test we put to boards is simple: for each of the five UK principles, name the control that evidences it and the person accountable for it. Accountability means you can prove who decided and when. Transparency means a claim the model makes is checkable against its source. Contestability means a person who disagrees with a decision can have it reviewed and reversed by a human. A risk register updated annually is not evidence of governance; it is a record that governance once happened. We make that argument, and show what a living register looks like, in Make your AI risk register living evidence.

Where should a board start?

With an honest reading of where it stands. Map where AI already operates, including inside supplier systems the board cannot independently test. Name the accountable owner. Confirm which binding regimes apply. Then choose the framework that structures the evidence.

The duties differ by sector: a housing association answers to the Regulator of Social Housing, a financial services firm to the FCA and PRA, a charity's trustees to the Charity Commission. The starting discipline is the same everywhere. The free Board AI Scorecard gives a board that first reading across accountability, policy, risk, data and capability in about two minutes, and the articles below take each duty further.

Articles in this topic.

Navy automated decision flow on a near-white background with a violet review checkpoint

AI governance for UK boards

ADM assessment for board approval under UK GDPR

How UK boards should approve automated decision-making under Articles 22A to 22D, with the controls and evidence to put in the pack.

ArticleHamada Mahdi9 min read
Abstract launch gate with checklist panels, risk controls and a restrained violet approval mark

AI governance for UK boards

AI go-live checklist for regulated organisations

A board-ready pre-launch checklist for regulated AI: decisions, evidence, controls and regulator mapping before an AI system goes live.

ArticleHamada Mahdi8 min read
Three abstract assurance routes passing through control checkpoints beneath a board oversight compass

AI governance for UK boards

AI governance assurance map for boards

A board-ready assurance map connects AI risks, controls, owners and evidence so audit committees can test whether governance is operating.

ArticleHamada Mahdi9 min read
Abstract layered evidence files linked to control nodes and audit-trail lines

AI governance for UK boards

AI governance evidence pack for UK boards

What boards should collect before approving, auditing or reporting on AI systems, from control evidence to regulator mapping.

ArticleHamada Mahdi8 min read
Abstract board dashboard with KPI gauges, evidence cards and violet control markers

AI governance for UK boards

AI governance KPIs for boards

Measure AI governance with board-ready KPIs that connect use cases, controls, evidence, incidents and decisions to accountable owners.

ArticleHamada Mahdi8 min read
Five ascending governance evidence columns connected by fine navy lines with one restrained violet control node

AI governance for UK boards

AI governance maturity model for UK boards

Assess AI maturity by controls, evidence and assurance rather than vendor scores or vague policy self-assessments.

ArticleHamada Mahdi10 min read
Abstract navy incident timeline contained by a violet boundary on a near-white field

AI governance for UK boards

AI incident response plan for UK boards

A board-ready response plan for AI incidents, covering data leakage, model failures, harmful output, ADM issues and reportable routes.

ArticleHamada Mahdi10 min read
Abstract navy assessment grid on a near-white field with one violet decision path

AI governance for UK boards

AI risk assessment template for boards

A board-ready template for assessing a proposed AI use before approval, with evidence, owners and framework mapping.

ArticleHamada Mahdi8 min read
A navy register grid on near-white paper crossed by a violet control path

AI governance for UK boards

AI risk register template for boards

A board-ready AI risk register structure with fields, owners, evidence, review cadence and mappings to NIST, ISO 42001 and UK GDPR.

ArticleHamada Mahdi9 min read
A near-white field of navy record cards with one violet path linking a decision to public evidence

AI governance for UK boards

ATRS checklist for UK board approval

A board-ready checklist for deciding whether an ATRS record is mandatory, what evidence to clear and how it maps to UK AI governance.

ArticleHamada Mahdi10 min read
A violet decision point on an abstract UK and EU regulatory map, with glass evidence panels and routed compliance lines

AI governance for UK boards

EU AI Act consultancy UK: what to buy (and what to refuse)

Buying EU AI Act advice for a UK organisation? The scope tests, dates and evidence a serious consultancy must produce — and the red flags that mean you are paying for commentary.

ArticleHamada Mahdi9 min read
Boardroom evidence packs joined by a violet governance line across a stone table, representing ISO 42001 readiness work

AI governance for UK boards

ISO 42001 consultant UK: board buyer guide

How UK boards should scope ISO 42001 consultancy, separate preparation from accredited certification, and demand evidence before audit.

ArticleHamada Mahdi8 min read
Abstract audit evidence grid with charcoal document outlines and a restrained violet pathway on a near-white background

AI governance for UK boards

ISO 42001 readiness assessment

How UK boards assess ISO 42001 readiness, gather evidence, map NIST and UK GDPR duties, and decide whether certification preparation is sensible.

ArticleHamada Mahdi8 min read
Layered translucent cloud forms inside a navy security frame with a violet control spine through the centre

AI governance for UK boards

NCSC cloud principles for AI governance

How UK boards can turn NCSC cloud guidance into evidence for AI systems, supplier assurance and ISO 42001 governance.

ArticleHamada Mahdi7 min read
Abstract near-white and navy editorial composition with violet survey grid lines and layered evidence panels

AI governance for UK boards

RICS responsible AI standard: board guide

What the RICS AI standard requires from surveying firms, and the board controls needed before clients, insurers or regulators ask.

ArticleHamada Mahdi10 min read
Abstract violet decision path pausing at a circular review point over layered near-white and navy panels

AI governance for UK boards

UK GDPR Article 22 automated decision-making: board controls

What Article 22A to 22D now require, and the controls UK boards should evidence before significant automated decisions go live.

ArticleHamada Mahdi8 min read
A violet-accented policy document stack with approval, review and restriction marks arranged on a precise governance grid

AI governance for UK boards

AI acceptable use policy for UK boards

A board-level guide to acceptable AI use: permitted uses, prohibited data, approval routes, evidence, training and review.

ArticleHamada Mahdi8 min read
A precise violet board pack showing AI systems, risks, controls and evidence columns

AI governance for UK boards

AI board reporting: what UK directors need to see

A board-level reporting format for AI use, risk movement, control evidence and decisions, grounded in UK governance duties and recognised frameworks.

ArticleHamada Mahdi7 min read
A violet board agenda with committee remit, risk register and evidence pack arranged as connected governance papers

AI governance for UK boards

AI governance committee terms of reference

A board-ready ToR structure for AI oversight: remit, membership, reporting, controls, evidence, and framework mapping for UK organisations.

ArticleHamada Mahdi9 min read
A violet-accented board procurement pack with checklist pages, supplier matrix and AI risk cards on a pale institutional desk

AI governance for UK boards

AI procurement checklist for UK boards

The board gates, supplier evidence, contract terms and risk-register handoff to use before buying or renewing an AI system.

ArticleHamada Mahdi8 min read
A board table with violet threshold lines separating acceptable, escalated and prohibited AI decisions

AI governance for UK boards

AI risk appetite statement for boards

A board-level guide to setting AI risk appetite: decisions, controls, evidence, framework mapping and next steps for UK organisations.

ArticleHamada Mahdi9 min read
A violet thread linking a supplier dossier, risk register and decision matrix on a precise boardroom table

AI governance for UK boards

AI Vendor Due Diligence Questions for Boards

A board-level checklist for testing AI suppliers: data use, model limits, assurance evidence, contract controls and post-go-live monitoring.

ArticleHamada Mahdi8 min read
A board table viewed from above with violet evidence lines connecting directors, systems and risk controls

AI governance for UK boards

Board AI oversight: what directors need to see

A board AI oversight guide for UK directors: decisions, evidence, frameworks and controls that make AI accountable in the boardroom.

ArticleHamada Mahdi10 min read
A structured board paper with violet approval marks, evidence tabs and risk controls arranged for an AI decision

AI governance for UK boards

Board Paper Template for AI Approval

Use this board paper structure to approve AI work with clear decisions, evidence, owners and UK governance mapping.

ArticleHamada Mahdi8 min read
An abstract violet assessment grid connecting data inputs, AI decision points, risks, controls and board sign-off

AI governance for UK boards

DPIA for AI: a board guide before go-live

When an AI use case needs a data protection impact assessment, what the board should ask for, and how to turn it into evidence.

ArticleHamada Mahdi9 min read
Four dark navy stepped tiers crossed by a single violet upward arrow, representing AI risk classification and escalation

AI governance for UK boards

EU AI Act risk tiers: a board guide

A board-level guide to the EU AI Act's prohibited, high-risk, transparency and minimal-risk categories, with controls and next steps.

ArticleHamada Mahdi8 min read
Near-white board table connected by violet control lines to evidence tiles and reporting checks

AI governance for UK boards

FRC AI Guidance for Boards and Audit: 2026 Checklist

FRC AI guidance for boards and audit committees, mapped: Provision 29 material controls, the FRC AI-in-audit rules, and the evidence your board needs.

ArticleHamada Mahdi8 min read
A structured policy document on a near-white boardroom surface, with violet control markers, evidence tabs and abstract data-flow lines

AI governance for UK boards

Generative AI policy template UK: board guide

A board-level UK guide to adapting a generative AI policy template into working controls, evidence, ownership and next steps.

ArticleHamada Mahdi7 min read
Translucent governance documents connected to an AI node and violet shield, showing data protection controls for AI

AI governance for UK boards

ICO AI code of practice: what boards do now

The ICO's statutory AI and ADM code is mandated, not final. Boards should map AI personal-data use to lawful basis, safeguards and evidence now.

ArticleHamada Mahdi8 min read
A violet audit ledger with stacked evidence cards, site markers and a certification seal, representing ISO 42001 cost drivers for UK boards

AI governance for UK boards

ISO 42001 certification cost UK: board guide

What UK boards should budget for: scope, readiness work, audit days, certification-body choice, surveillance and internal evidence.

ArticleHamada Mahdi9 min read
A violet boardroom checklist grid with ISO 42001 clause bands, evidence cards and audit status markers

AI governance for UK boards

ISO 42001 checklist for UK boards

A board-level checklist for ISO/IEC 42001 scope, leadership, risk, support, operations, review and Annex A evidence.

ArticleHamada Mahdi6 min read
Five horizontal strata on a near-white field, threaded by a single violet line descending from the top layer to the base

AI governance for UK boards

The AI governance framework UK organisations actually need

A working AI governance framework has five connected layers — principles, policy, controls, evidence, assurance — and a 90-day route to stand one up.

ArticleKarl George MBE13 min read
Eight stacked rectangular panels on a near-white field, one traced in violet, suggesting the ordered sections of a policy document

AI governance for UK boards

What a UK AI policy must include in 2026

The eight working parts of a defensible UK AI policy, what each section is for, and why a template without controls is a disclaimer, not governance.

ArticleKarl George MBE9 min read
Three violet lines crossing a near-white field towards a single marked boundary, suggesting routes into regulatory scope

AI governance for UK boards

Does the EU AI Act apply to UK organisations?

Three routes pull UK organisations into the EU AI Act. A plain-English decision guide for boards: scope, roles, risk tiers and the June 2026 timeline.

ArticleKarl George MBE9 min read
A closed violet square frame interlocking with an open four-segment ring on a near-white field, suggesting a certifiable system holding a risk cycle

AI governance for UK boards

ISO 42001 vs NIST AI RMF: which do you need?

One is a certifiable management system standard, the other a voluntary risk framework. How a UK board chooses between them — or runs both inside one AIMS.

ArticleHamada Mahdi9 min read
Twenty short violet strokes ranked in five columns on a near-white field, one stroke raised like a hand asking a question

AI governance for UK boards

20 questions every UK board should ask about AI

Twenty AI questions for UK boards, grouped into five areas, each with the artefact a good answer produces and the UK rule it rests on.

ArticleKarl George MBE11 min read
Dozens of faint grey marks drifting beneath a single violet boundary line on a near-white field, a few marks crossing above it

AI governance for UK boards

Shadow AI: the policy boards need before the ban reflex

Staff already paste work into consumer AI. The answer is not a ban: discover use, triage it into three bands, provide sanctioned tools, police the line.

ArticleKarl George MBE8 min read
A navy grid of cells with one violet diagonal line, a static register turning live

AI governance for UK boards

Make your AI risk register living evidence, not a spreadsheet

An AI risk register that only updates quarterly is already stale. Structure it with NIST's Govern-Map-Measure-Manage and feed it from the systems themselves.

ArticleKarl George MBE9 min read
Stacked navy horizontal layers with one violet seam, representing the layered clauses of a management system standard

AI governance for UK boards

ISO/IEC 42001 explained: what it asks of a board

What ISO/IEC 42001 concretely requires of a board across clauses 4-10 and Annex A, and the honest difference between aligning to the standard and being certified.

ArticleKarl George MBE9 min read
Five converging lines on a near-white field, one highlighted in violet, suggesting principles aligning to a single standard

AI governance for UK boards

The UK has no single AI Act. What your board governs instead

There is no UK AI statute. Your board governs against five voluntary, regulator-applied principles, which makes voluntary frameworks the practical route to compliance.

ArticleKarl George MBE9 min read

Questions directors ask.

Does a board need AI expertise to govern AI?
No, but it needs enough literacy to interrogate what it is told. Most boards are recruited for finance, legal or sector standing, and the duty is reasonable care and skill, not technical mastery. What a board cannot do is defer entirely to executives or vendors on model accuracy, bias and data flows.
What is the difference between aligning to ISO/IEC 42001 and being certified?
Alignment means building your AI management system to the standard's requirements. Certification is a formal assessment that only a UKAS-accredited certification body, such as BSI, can issue. A consultancy can prepare you for certification; it cannot certify you, and a claim otherwise is a warning sign.
How often should a board review its AI risk register?
Continuously, not annually. AI capability changes between meetings, so a register that updates once a year is already stale. The practical fix is to feed the register from the systems themselves, so the board reviews live evidence rather than a snapshot assembled for the meeting.
Who should own AI risk at board level?
A named person, for every system. In financial services the Senior Managers and Certification Regime makes this explicit: a Senior Management Function holder carries AI risk in their Statement of Responsibilities. The same discipline serves every sector: an inspector should be able to see who owns each AI system that touches a real person.

Find out where your AI exposure sits.

We'll tell you plainly what's worth doing, what isn't, and what a board or regulator will expect to see. No pitch deck.

No obligation · no pitch.