| Oversight Domain | Full BoardOversight · WHO | Risk / Audit CommitteeDelegated Review | CEO & Executive ManagementOperation · HOW | AI Oversight Program OwnerProgram of Record | Internal AuditIndependent Assurance | General Counsel & ComplianceDuty & Defensibility |
|---|---|---|---|---|---|---|
| Board OversightExercise the duty of oversight. Demand reporting that meets the Informed Decision Standard. | AHolds the fiduciary duty of oversight | RRuns the review cadence and challenge process | CPresents the state of the system | RSupplies decision-grade reporting | IReceives oversight expectations | CAdvises on Caremark exposure |
| Risk AppetiteSet AI risk appetite and tolerance, including limits on automated decisions. | AApproves appetite and tolerance | RShapes and stress-tests the recommendation | RProposes appetite from strategy | CTranslates appetite into program limits | ITests limits in later assurance work | CConfirms limits align with regulatory obligations |
| Policy GovernanceApprove policy direction and keep the policy architecture current as obligations change. | AApproves policy direction and decision rights | CReviews the policy suite before approval | RIssues and enforces policy | RDrafts and maintains the policy architecture | IAudits against the approved policy set | CConfirms legal sufficiency |
| Control AssuranceObtain independent evidence that controls hold, including automated and embedded controls. | IReceives confidence signals | AOwns the assurance agenda and evidence quality | CRemediates what assurance surfaces | CProduces audit-ready evidence | RPerforms independent testing | ITracks findings with legal consequence |
| Regulatory ReadinessMaintain the accountability narrative and respond as enforcement expectations rise. | COwns the governance story regulators will test | IMonitors examination outcomes | AAnswers to regulators for the institution | CMaintains lifecycle and explainability records | IAligns audit plan to regulatory change | RTracks obligations and manages engagement |
| Third-Party GovernanceGovern Builder dependencies as a Buyer. Extend the accountability chain through the supply line. | ISees concentration and dependency exposure | CChallenges reliance on critical suppliers | AOwns the dependency portfolio | RSets supplier guardrails and monitors embedded AI | CValidates supplier controls and exit scenarios | CBuilds guardrails into contracts |
| AI & Data OversightApply the Informed Decision Standard to material AI-enabled decisions. Close the Velocity Gap without ceding the decision. | AAnswers for material AI decisions | RReviews escalations and model accountability | COperates within approved decision limits | RRuns escalation, monitoring, and decision records | CChecks automated controls and data usage | CAdvises where accountability is created |
| Resilience PlanningProve service accountability under disruption. Plan fallback controls where AI fails. | IConfirms critical services are prioritized | CTests disruption tolerance against appetite | AAnswers for continuity of service | RPlans fallback controls and substitute providers | CConfirms response readiness | ISupports incident disclosure duties |
The WHAT and WHO line
Oversight governance is the WHAT and the WHO: what must be governed, and who is accountable for governing it. Everything to the right of the CEO column is the HOW, and it belongs to management. A board that reaches into the HOW is not governing better; it is governing the wrong layer.
A committee is a decision right, not a defense
The committee column on this matrix assigns review responsibility. It does not constitute governance. That is the Committee Fallacy: treating the existence of a committee as evidence that oversight is occurring. The evidence is the program, its reporting, and the decisions it can show it made. The program is the governance.