Center for AI Oversight

Defining oversight governance for AI in regulated industries.

The Center is an independent, educational institution. It defines what boards and executives in regulated industries must govern in AI, and who is accountable, so they can make informed decisions at the speed the technology demands. Governance, on this view, is not a brake on AI adoption. It is what makes confident adoption possible.

The AI Oversight Program

Governance is not a committee or a control on the technology. It is the program that allows boards and executives to make timely, trusted decisions about AI, finding the informed strategic balance of risk and reward. The AI Oversight Program is built on five pillars and fourteen domains, with each control mapped to the laws, regulations, case law, and standards that define the standard of care across jurisdictions and industries.

5 Pillars
14 Domains
Mapped to authoritative sources Case law · Regulations · International standards · Fiduciary duty
I
Agile Governance
The Constitution
  • AI Governance Program and Policy standards
  • AI Governance Structure, Oversight, and Resources
  • Governance Program Assurance and Continuous Learning
II
Risk-Informed System
The Guardrails
  • AI Risk Methodology, Scope, and Tolerance
  • Risk Intelligence and Threat Landscape
III
AI Trust and Assurance
The Evidence
  • AI Model Risk and Agentic Lifecycle Oversight
  • AI Data Governance Oversight
  • AI Transparency, Explainability, and Human Oversight
  • AI Security and Resilience Assurance
IV
Risk-Based Strategy and Execution
The Strategic Alignment
  • Risk-Informed Strategy, Resources, and Organizational Readiness
  • AI Value Realization and Operational Resilience Oversight
  • Third-Party AI and Supply Chain Governance
V
Risk Escalation and Disclosure
The Voice
  • AI Risk Escalation and Disclosure Protocols
  • Validation of Escalation and Governance Effectiveness

Co-authored with the institutions that define governance standards.

Forthcoming, Q3 2026
AI Oversight: The Private Director's Body of Knowledge
A strategic guide for private company boards on AI governance as a fiduciary obligation. Covers the Velocity Gap, the Builders and Buyers distinction, the Caremark duty of oversight, and the director's toolkit.
Co-published with Private Directors Association
Forthcoming, Q3 2026
AI Governance Best Practices for Internal Auditors and Governance Professionals
A practical tool that equips internal auditors and governance professionals to provide strategic assurance over AI governance. It defines the AI governance program as the primary auditable entity and gives internal audit a structured way to assess the program's design adequacy and operating effectiveness.
Developed to support implementation of the IIA AI Auditing Framework

The intellectual foundation of the Center's work.

The Problem

The Velocity Gap

AI is being adopted faster than most organizations can govern it. The gap between the speed of AI adoption and the speed of AI governance is where fiduciary risk, regulatory exposure, and missed strategic opportunity all live. The AI Oversight Program is the institutional capability that closes it.

Read the essay →
The Trap

The Committee Fallacy

Forming an AI committee is not a governance program. Without a program defining what must be governed and who is accountable, committees produce activity without accountability and leave the Governing Body exposed.

Read the essay →
The Standard

The Informed Decision Standard

When a regulator, court, or auditor asks whether the organization made an informed decision about AI, the Program must demonstrate the answer in evidence. The Standard is satisfied when the Governing Body has what it needs, the Program is real rather than theatrical, and the chain from policy to practice to assurance is traceable.

Read the essay →
The Outcome

Decision Velocity

Decision Velocity is the ability to make faster, risk-informed decisions backed by evidence, without sacrificing accountability. It is the strategic outcome the AI Oversight Program is built to deliver, and the reason oversight governance is an enabler of AI adoption rather than a constraint on it.

Read the Insights →

One oversight signal. One governance insight. One action item.

Once a month. Read in under 3 minutes. For board directors, audit executives, and risk leaders responsible for AI oversight governance.

Latest issue: June 2026

From the Center.

Paper

The AI Oversight Governance Layer

Three layers of governance operate in any organization deploying AI. The oversight layer, which decides what is governed, at what granularity, and who is accountable, is usually missing.

~12 min read
Essay

The Two Duties

Examining the dual responsibilities of AI oversight: the duty to oversee the system's compliance and risk, and the duty to oversee the human capacity to direct it.

~8 min read
Paper

Agentic AI and the Oversight Lens

When AI acts rather than advises, model risk standards fail. Why the oversight program is the only standard that reaches it.

~11 min read
CFAIO Board Brief

One page. One question. Written to be forwarded into a boardroom.

Named concepts

The Velocity Gap → The Committee Fallacy → The Informed Decision Standard → Decision Velocity →
Working with
Private Directors Association DCRO Institute Virginia Tech Innovation Campus The IIA State AI Safety Roundtable

Guided by leaders who built the regulatory landscape.

The Center's work is informed by former senior leaders who shaped the oversight and regulatory infrastructure governing AI adoption today.

Includes former senior leaders from:
Federal Reserve U.S. Securities & Exchange Commission Federal Communications Commission U.S. Department of the Treasury
Jim Cunha
Jim Cunha
Former EVP, Federal Reserve Bank of Boston
Led innovation strategy at the Boston Fed, including digital currency research and payment systems modernization.
LinkedIn →
Chuck Senatore
Chuck Senatore
Former Director, SEC Southeast Region
Directed SEC enforcement and examination programs across financial services regulatory oversight. Former Head of Risk Oversight at Fidelity Investments.
LinkedIn →
David Simpson
David Simpson
Rear Admiral, U.S. Navy (retired), former Chief of the Public Safety and Homeland Security Bureau, FCC
Senior military and regulatory leadership across telecommunications, cybersecurity, and critical infrastructure.
LinkedIn →
Brian Peretti
Brian Peretti
Former CTO & Deputy CAIO, U.S. Treasury
Led technology strategy and AI governance at one of the largest federal agencies.
LinkedIn →
Rudy Brioche
Rudy Brioché
Former VP & Policy Counsel, Comcast Corp.
Led global public policy at Comcast and served as Chief of Staff and Legal Advisor at the FCC, shaping telecommunications, cybersecurity, and AI strategy.
LinkedIn →
Senior Fellows
Ankur Singhal
Ankur Singhal
Board of Directors, Cyber Risk Institute
Technical leadership spanning financial regulation and technology risk.
LinkedIn →

The Center's work takes four forms.

As an educational institution, the Center produces positions, reference tools, research, education, and convening on the board-level discipline of AI oversight governance. Its work serves boards, audit executives, risk leaders, regulators, and trade organizations in regulated industries.

The Oversight Program

A practical model for board-level AI oversight: 76 controls across 5 pillars and 14 domains, with diagnostics tied to the laws, regulations, and case law that define what boards are accountable for.

Explore the Program →

Publications & Research

AI Oversight: Guidelines for Private Directors, developed with the Private Directors Association, and guidance in development with the DCRO Institute and the internal audit profession

See publications →

Education & Training

NASBA-compliant education for directors, chief audit executives, and risk leaders, in online, virtual, and in-person formats. Governance competency for senior professionals, not technology tutorials.

Inquire about training →

Convening & Speaking

Keynotes, panels, board briefings, and roundtables that bring the Center's thinking to conferences, boardrooms, and regulator forums on AI oversight governance.

Invite the Center →

Every form of the Center's work serves a single mission: defining oversight governance for AI as a board-level discipline in regulated industries. To engage with the Center's education, research, or convening, write to info@cfaio.org.

The AI Oversight Program: five pillars, fourteen domains, seventy-six controls, mapped to the law, regulation, case law, and standards that define the standard of care. Explore the Program →

Co-authored with the institutions that define governance standards.

Published Q3 2026
AI Oversight: Guidelines for Private Directors
A strategic guide for private company boards on AI governance as a fiduciary obligation. Covers the Velocity Gap, the Builders and Buyers distinction, the Caremark duty of oversight, and the director's toolkit.
Co-published with Private Directors Association
In drafting
AI Oversight: Guidelines for the DCRO Institute
Guidance for risk committee members and chief risk officers on establishing AI oversight governance and integrating it into enterprise risk infrastructure.
Co-published with DCRO Institute
Forthcoming, Q3 2026
AI Governance Best Practices for Internal Auditors and Governance Professionals
A practical tool that equips internal auditors and governance professionals to provide strategic assurance over AI governance. It defines the AI governance program as the primary auditable entity and gives internal audit a structured way to assess the program's design adequacy and operating effectiveness.
Developed to support implementation of the IIA AI Auditing Framework
Six questions only the oversight layer answers
1.

The Program.

Have we chartered an AI oversight program, and does the record show which standards we elected to apply, how far, and who decided?

2.

The Accountability.

Which committee holds oversight of the program by charter, which officer answers to it by name, and what have we allowed to sit outside it, accepted by whom?

3.

The Tolerance.

Did we set the boundaries of acceptable AI risk in advance, on a stated basis, and ratify them, or were they set by default?

4.

The Authority.

What operates without a person in the loop, under what limits, until when, and who can withdraw it?

5.

The Line.

Do escalation and disclosure reach us on triggers and thresholds fixed in advance, by at least one path that does not depend on management's discretion?

6.

The Record.

When a regulator, court, or auditor asks, can we show the informed decision, the report we received, what we did with it, and that someone independent confirmed the program did what it said?

The oversight charter is what makes them answerable on a record. One page, amended onto a document the institution already keeps.

The oversight layer.

Three layers of governance operate in any organization deploying AI. Technical controls govern how the system is built, constrained, and watched. Management governs how the organization pursues its AI objectives and manages the risk of doing so. Oversight governance sits above both. It decides what is governed, at what depth, and who answers when the decision is examined, and it never decides how. The first two layers are well served by mature standards. The third is usually missing, and nothing beneath it supplies it.

Direction and accountability cascade down ▼
Oversight Layer · Usually Missing Held at the fiduciary level

Oversight Governance

The WHAT and the WHO. Chartered once, then operated. Decides what is governed, at what depth, and who answers.
Charteradoption, depth, basis, scope, granularity, required outputs Accountabilitynamed, recorded, with delegation Risk toleranceratified at the accountable level Authority to operatebounded and expiring Reportingescalation and disclosure line Competencyto interrogate the report
Management Layer · Present The activity, not the rank

Management

How the organization pursues its AI objectives and manages the risk of doing so. Decides what the organization will do and how well. Mature external instruments serve it.
Objectives and strategy execution Prioritization and resourcing Enterprise risk management and compliance Vendor selection and monitoring Policies, standards, and procedures Incident response and remediation
Technical Controls Layer · Present The system

Technical Controls

How the system is built, constrained, and watched. Decides how the model operates. Mature standards serve it.
Data provenance and integrity Model evaluation and testing Access controls and security Drift monitoring and logging Explainability and transparency System boundaries and safety margins
Assurance · Independent of Management

Internal audit and independent third parties test that the controls are designed adequately and operating effectively. Escalates findings upward to the accountability layer.

▲ Escalation and evidence flow up
The layers of AI governance. Layer assignment follows subject matter, not rank.
Distributed accountability

Responsibility for AI is distributed to every organization that builds, adapts, or puts it to work. Inside each organization it attaches to a named person: the committee that holds oversight of the program by charter, and the officer who answers for it by name. Accountability that is shared by everyone is held by no one.

Read The AI Oversight Governance Layer →

The debate is about the frontier. The risk lands on the enterprise.

Three groups hold responsibility for AI: those who build the models, those who adapt them, and those who put them to work. The public debate speaks almost entirely to the first. The risk lands on the third: the bank, the insurer, the hospital system, the utility that grants an AI system authority to act inside its own operations.

Unlike cyber, this is not a threat arriving from outside. It is what an organization does with its own authority. The duty to oversee it is not new; the courts have applied it to mission critical risk for years. What is new is the object: authority granted to systems that act until the authority is withdrawn. The frontier's safety is the labs' job. The authority you grant inside your own walls is yours.

Center for AI Oversight

Defining oversight governance for AI in regulated industries.

The Center for AI Oversight is an independent educational institution. It defines what boards and executives must govern in AI and who is accountable, and never how. Governance built to that standard is not a brake on adoption. It is what lets an institution take risk at speed and defend the decision.

Read the Center's position → Subscribe to The AI Oversight Brief →