The DCRO Institute The DCRO Institute

Guiding Principles for
Programmatic AI Governance

Principles for Directors in Overseeing AI Strategy and Risk-Taking

The DCRO Institute

Co-produced with

C Center for AI Oversight

A DCRO Institute Guiding Principles Publication · September 2026

Co-produced by the Programmatic AI Governance Council of the DCRO Institute and the Center for AI Oversight — defining oversight governance for AI in regulated industries. Drafted by the Center.  cfaio.org

Executive Summary

Five principles for boards overseeing AI strategy and risk-taking:

  • Charter a governance program with defined accountability.
  • Approve tolerances that work as decision architecture.
  • Require evidence that governance functions across the lifecycle.
  • Connect the program to strategy and value.
  • Keep the board informed enough to keep authorizing speed.

The through-line is the conviction the Institute’s publications have carried from the beginning: risk-taking is how organizations create value, and governance done well is what lets a board say yes sooner, and mean it.

Preface

The publications of the DCRO Institute have long carried a conviction that sets them apart: risk-taking is how organizations create value, and the board’s role is not to minimize risk but to see that it is taken well. In this view, governance is not there to slow the organization down; it is what gives a board confidence that ambition is being pursued responsibly.

Artificial intelligence now tests that conviction at a new tempo. In many sectors, strategy cycles that once ran annually now run quarterly, and capability cycles run faster still. A capability an organization declines this year may show up in a competitor’s hands within a few quarters. In this environment the cost of standing still can compound faster than the cost of acting. The question before the board is not how to avoid AI risk, but how to take it well in pursuit of the organization’s purpose.

The stakes deserve to be named plainly. AI is not another initiative to be governed alongside the rest. For many organizations it puts the business model itself in question: the products, the processes, the customer relationships, and the shape of the workforce that deliver today’s revenue. The Institute examined that disruption in the volumes noted below; this document assumes it. The program described here is therefore not the governance of a project. It is how a board governs the organization’s whole relationship with AI, from the productivity pilot to the existential bet, through one system.

None of this argues for recklessness. It argues for a stronger and more deliberate relationship with risk: the organization’s willingness to take AI risk should be settled as a matter of strategy, in advance, by people with the authority to decide, and revisited as often as the technology moves. This is a shift in posture, away from static compliance and toward an anticipatory and adaptive stewardship of a technology whose effects reach beyond the firm to the wider ecosystem in which it operates. Stewardship of that kind adds foresight to oversight: attention to the technology’s trajectory, on horizons stated in years rather than board cycles, and to the interdependence that comes with it, as organizations build on stacks of interlinked providers and systems where a failure, a model change, or a second-order effect in one layer travels through the rest. A periodic compliance check cannot see that far. A standing program can. We believe organizations that build this capability are better positioned to make faster decisions, with better information, and to demonstrate to capital providers, regulators, and counterparties that speed and control are not in tension.

In The Age of Strategy Disruption, the Institute examined how quickly the assumptions beneath a strategy can decay. In AI and Risk Governance: Six Critical Considerations, it gave directors a set of questions for approaching AI as a risk-taking challenge. This document takes the next step. It addresses how a board oversees AI strategy and risk-taking durably: not through familiarity with any particular technology, which will change again before this document is a year old, but through a governance program built to produce informed decisions at the pace the environment demands.

The principles that follow are sector-agnostic and are written for organizations of every size and structure, public and private, for-profit and nonprofit. They describe what must be governed and who must be accountable. They deliberately do not prescribe how. Operational design belongs to management, and it will differ, appropriately, from one organization to the next.

Introduction

The purpose of this document is to provide boards of directors a set of Guiding Principles for overseeing artificial intelligence strategy and risk-taking through a formal governance program.

The framing matters at the outset. AI is a management disruption before it is a technology deployment: it changes how decisions are made, how work is organized, and how fast the environment moves, and it does so across the whole organization at once. Governing disruption is not the same as governing a project. The program these principles describe is built for the former.

The Oversight Layer

The distinction between oversight and operations runs through everything that follows. This document is concerned with oversight governance: what must be governed and who is accountable for it, as distinct from the management layer, through which the organization pursues its AI objectives and manages the risk of doing so, and the technical controls that live in the systems themselves. Management designs and runs the systems through which AI is selected, built, procured, deployed, and monitored. The board’s role is different: to ensure that a system exists, that it is accountable to named individuals, that it operates within boundaries the board has approved, that it produces evidence of its own functioning, and that it keeps the board informed enough to act. Directors do not need to become technologists to discharge this role. They need a program that makes them informed enough, soon enough, to govern decisions rather than ratify them.

DIRECTION AND ACCOUNTABILITY CASCADE DOWN ▾ OVERSIGHT GOVERNANCE · THE BOARD AND ITS COMMITTEES Oversight Governance WHAT must be governed, and WHO is accountable The program charter and its authority · The accountable executive · Tolerances as decision architecture Evidence expectations · Escalation triggers that reach the board THIS DOCUMENT LIVES HERE Authority and boundaries flow down Evidence and escalation flow up MANAGEMENT · THE ACTIVITY, NOT THE RANK Management HOW the organization pursues its AI objectives and manages the risk of doing so Policies and standards · Committees and review forums · Risk assessments · KPIs and KRIs Inventories and vendor controls · Responsible use policies Direction and standards flow down Telemetry and issues flow up TECHNICAL CONTROLS · LIVES IN THE SYSTEM Technical Controls HOW the system is built, constrained, and watched Cyber and data governance · Model, prompt, and configuration controls · Testing Monitoring and logs · Agentic controls INDEPENDENT ASSURANCE · THIRD LINE Review across all three layers, independent of the functions that build and operate AI. RISK AND ASSURANCE INFORMATION FLOWS UP ▴
The three layers of AI governance. This document addresses the top layer; the two beneath belong to management and the systems themselves, and are scoped into the program, not into this document. Layer assignment follows subject matter, not audience altitude. Adapted from the Center for AI Oversight’s three-layer taxonomy: oversight governance, management, and technical controls.

Existing Duties, a New Object

None of this asks directors to take up a new body of duty. The duties they already hold (care, loyalty, oversight and monitoring, and the obligation to reach informed decisions) map directly onto the oversight of AI, and they give these principles a legal grounding as well as an operational one. That responsibility is collective and cannot be delegated away: committees and management may carry out the work, but the board answers for whether an effective governance framework exists and functions. Companion Tool E surveys these foundations, and the regulatory expectations now forming around them, for directors who wish to go deeper.

Most organizations already hold pieces of AI governance: a committee, a policy, an inventory of models and use cases, a set of vendor controls. Each is useful, but none of these by itself amounts to oversight governance. A committee is a place where discussion happens, and a policy is a statement of intent, unless something connects the pieces and someone answers for the whole. Oversight governance is present when the pieces function together as a system: chartered by the board or its delegate, owned by an accountable executive, resourced to operate, connected to strategy, and producing evidence that it works. That system is the program, and the program is what the board oversees.

One consequence of the disruption deserves emphasis of its own: new technology arrives on old process. Much of what organizations reach for first was built for earlier technologies: software approval pipelines, cyber review gates, vendor onboarding checks. Some of it will transfer. Some of it, applied unexamined, becomes the mechanism by which the speed the board authorized is quietly lost. The principles that follow therefore ask directors to have familiar structures re-examined through an AI lens, not because established frameworks no longer apply, but because assuming they apply unchanged is itself a risk decision, and one that is rarely brought to anyone for approval.

The Five Principles

Five principles follow from this premise:

  • Principle I addresses the program itself: its charter, its accountability, and its authority.
  • Principle II addresses the risk methodology: tolerances that function as decision architecture, so leadership can act at pace within boundaries the board has approved.
  • Principle III addresses evidence: the demonstration, rather than assertion, that governance is functioning across the AI lifecycle, including its relationship to directors’ existing legal and regulatory obligations.
  • Principle IV addresses strategy: the connection of AI governance to planning, investment, and value realization.
  • Principle V addresses intelligence: escalation and reporting channels that surface threats and opportunities in time to matter.

The principles are written to be tailored. A global financial institution and a two-hundred-person nonprofit face the same oversight obligation and will discharge it through very different structures. A set of companion tools accompanies this document on the Institute’s site: Tool A restates the five principles in summary form; Tool B offers an illustrative mapping of roles and accountabilities across the board, its committees, management, and assurance functions; Tool C addresses application across organizational scale; and Tool D presents one illustrative model of a programmatic approach, offered as an example rather than a template. The Conclusion describes the full set.

I.

Directors should ensure the organization has established a formal AI governance program with a charter, defined accountability, and authority proportionate to its AI risk exposure.

A.Charter the program with defined scope, decision rights, and accountability.

B.Name the accountable executive, distinguishing accountability from responsibility.

C.Treat the program as the management system the board oversees; a committee alone is not governance.

D.Scale structures to the size and complexity of the organization as well as its exposure.

The most common condition in AI governance today is not absence but fragmentation. Boards ask whether the organization is governing AI and hear a reassuring inventory: a working group has been formed, a policy has been adopted, a review process exists for new use cases. Each of these is a piece. The board’s first task, we suggest, is to ask the question the inventory avoids: do the pieces constitute a system? Is there a charter that connects them, an executive who answers for them, a budget that sustains them, and a record that would demonstrate to an outside observer that the system operates as described?

The Charter

A charter is where the program becomes real, and approving one is not new work invented for a new technology; it is an exercise of the board’s established duty to review and guide risk policy and major plans of action. It need not be long, but it must settle the questions that fragmented governance leaves open:

  • Scope. What the organization treats as AI for governance purposes, including systems it builds, systems it buys, and AI embedded in vendor products it already uses, together with the instruction and configuration layers that direct how those systems behave. The embedded category is the most commonly missed and, increasingly, the largest.
  • Reach. How deep into the organization the program extends: to subsidiaries, business units, and individual use. No use of AI sits outside the program, but the depth of review is tiered by materiality, so that ubiquitous low-stakes use is governed through policy and monitoring rather than case-by-case approval.
  • Decision rights. Which decisions management may take in the ordinary course, which require the program’s approval, and which must come to the board or a committee of the board.
  • Accountability. The named executive who owns the program and answers to the board for its operation.
  • Cadence and reporting. What the board receives, from whom, and how often.
  • Evidence. The standard of documentation the program maintains, sufficient for a director, an auditor, or a regulator to reconstruct how a decision was made.

Accountability, Distinguished from Responsibility

The distinction between accountability and responsibility warrants particular attention. Responsibility for AI is necessarily distributed: data science teams, procurement, legal, information security, and the business lines all hold pieces of it. Accountability, however, cannot be spread across a committee; in practice that means no one is accountable, and this usually becomes apparent only after something has gone wrong. We recommend that the program name one executive who is accountable to the board for its operation, whatever the reporting lines beneath. Two boundaries keep the distinction clean. Naming an accountable executive does not relieve the leaders who sponsor AI initiatives of accountability for the commercial outcomes and the specific risks of what they sponsor; the program executive answers for the system of governance, and sponsors answer for what they run through it. Nor does it relieve the board: responsibility for ensuring that an effective framework exists is collective, and it may be delegated in execution but not in ownership. Companion Tool B offers an illustrative mapping of these roles.

Proportionality and Authority

Proportionality is a feature of this principle, not an exception to it. A large institution may charter a dedicated AI governance function with its own leadership and staff. A smaller organization may vest the program in an existing officer, with the charter, decision rights, and reporting handled in existing forums. The obligation is identical; the structure is scaled. What does not scale down is the requirement that the program be real: a charter that is followed, an owner who is named, and authority that is proportionate to what the organization has at stake. Companion Tool C addresses these differences in scale directly.

Finally, the program must have real authority. A program with a charter but no budget, no expected outputs, or an accountable executive without the standing to stop a deployment is a paper program. A paper program is dangerous in a way absence is not: it creates the appearance of oversight while the organization’s actual risk-taking goes unexamined. Directors should satisfy themselves, at the outset and periodically thereafter, that the program’s authority and resources match the organization’s AI exposure as it grows. Resources include people: the skills, the leadership, and the depth of bench to operate and oversee AI as its scale and complexity increase. A program can be outrun by the adoption it governs, and directors should ask whether the organization has the capacity to keep pace.

Establishing the program is the board’s first task. Deciding how much risk the program may authorize, and how fast, is the second. That is the subject of Principle II.

II.

Directors should approve a risk methodology that defines tolerance as decision architecture, giving leadership clear authority to act at pace within board-approved boundaries.

A.Approve tolerances as pre-authorized decision space rather than as constraints.

B.Require the methodology to address risk-taking for value as well as risk mitigation.

C.Define clear triggers for board involvement when boundaries are approached.

The best risk functions have long translated appetite into limits and delegated authorities. Artificial intelligence requires that same discipline, extended to decisions that arrive weekly and to categories those frameworks were never built to cover: whether to deploy a customer-facing model, whether to adopt a new foundation model, whether to permit AI-assisted decisions in a regulated process, whether to let an agentic system act without human review. If each of these must wait for a governance forum with the authority to decide, the organization will either move too slowly or, far more commonly, the decisions will get made anyway, informally and without the board’s knowledge.

Tolerance as Decision Architecture

Tolerance as decision architecture resolves this. Rather than describing risk preferences in the abstract, the board approves boundaries that define, in advance, the space within which management is authorized to act. Inside the boundaries, leadership moves at the pace the opportunity demands, without returning for permission. At the boundaries, defined triggers bring the decision to the program, and through it to the board. The board’s deliberation is spent where it belongs: on setting and revising the boundaries, not on ratifying individual deployments after the fact.

Boundaries are conclusions, not starting points. Each should rest on a structured assessment of the risks it governs, specific to the use and its materiality, so that anyone exercising delegated authority can see why the threshold sits where it does. A methodology built this way should specify:

  • Decision domains. The categories of AI decision the organization actually faces: customer-facing deployment, internal productivity use, third-party and embedded AI, data usage, the degree of autonomous action permitted, and the use of AI in decisions with significant consequences for individuals or in regulated processes, among others. Where a decision carries significant consequences for an individual, the methodology should provide a defined route by which the affected person can reach a human with the authority to review and change the outcome.
  • Boundaries and thresholds. For each domain, what management may authorize, what requires program approval, and what comes to the board.
  • Triggers. The specific conditions, quantitative or qualitative, that move a decision upward or require the board to be informed; what matters is that they are defined in advance and observable in practice.
  • Aggregate exposure. How decisions taken individually within the boundaries are monitored in the aggregate, so that many authorized decisions do not sum to an exposure the board never approved. The aggregate view should recognize that AI risk seldom stays in its category, amplifying operational, conduct, legal, and reputational exposure alongside the risk first taken; that many authorized decisions may rest on the same third-party provider, whose degradation or withdrawal becomes a concentrated exposure; and that experimentation counts, with pilots bounded in advance by population, duration, and exposure, and expanded or ended as deliberately as any deployment.
  • Recalibration. The cadence and conditions on which the boundaries themselves are revisited, because tolerances set for last year’s capabilities will misfit next year’s.
  • The record. How decisions taken within the boundaries are documented, so that authority exercised at pace remains visible to the program and, through it when appropriate, to the board.

Three Features of the Methodology

We would press for three features in any such methodology. First, it must address both directions of risk: the downside the organization protects against, and the upside it intends to pursue through deliberate risk-taking. A methodology that speaks only of what the organization will not do is a compliance instrument, not a governance one. The board should expect the methodology to be equally explicit about the risk the organization intends to take: where AI advantage is being pursued, what the organization is willing to accept in pursuing it, and who decided. Declining to deploy has costs too. A sound methodology makes the cost of inaction as visible as the cost of action. Escalation, accordingly, runs in both directions: an opportunity discovered inside the boundaries, a practice that would make the organization materially faster or better, deserves the same disciplined path upward as an approaching limit. Principle V returns to this.

Second, the boundaries must be honest about uncertainty. AI systems present risks that resist precise quantification: model behavior shifts, vendor models change beneath the products built on them, and usage spreads faster than inventories record. This is not a defect in the methodology; it is a design condition. Sound boundaries will mix quantitative measures with qualitative ones: defined conditions, scenario judgments, and the assessment of the people closest to the risk. What matters is that the basis for each boundary is stated, that qualitative judgments are documented with the same discipline as quantitative ones, and that where confidence is genuinely low the methodology compensates with tighter triggers and shorter recalibration cycles rather than false precision. A framework that claims exactness should raise more questions for directors than one that is candid about the limits of what it knows.

Third, the methodology must be clear about what is not on the table. Some boundaries are not tolerances to be calibrated but commitments the organization has already made: its ethics, its obligations under law, the privacy of the people whose data it holds, the trust of its customers. The methodology should name these as fixed constraints, so that expected value is never the argument for crossing them. A strong upside case does not loosen a commitment; it tests it.

Agentic Systems

Agentic systems, AI that acts rather than recommends, deserve particular candor. The degree of autonomous action permitted already appears among the decision domains above, and it is the domain where uncertainty runs highest: the consequences of autonomous action at scale are the least understood, and the experience base is the thinnest. Directors should expect the boundaries around agentic use to be the most conservative in the methodology and the most frequently revisited, and should expect the methodology to say plainly what is not yet known. Principles III and V return to the evidence and intelligence this domain will demand.

Governance at Speed

When this works, governance makes the organization faster, not slower. Routine AI decisions are made in days rather than quarters, and the board’s limited attention is spent on the decisions that genuinely require it.

III.

Directors should require the program to produce evidence of functioning governance across the AI lifecycle, building trust through demonstration.

A.Require evidence standards that span the AI lifecycle, from intake through retirement.

B.Expect demonstration rather than assertion, for the board and for those whose trust the organization needs.

C.Treat fiduciary and regulatory obligations as satisfied through governance that demonstrably works.

D.Commission periodic independent assurance of the program’s operation.

Principles I and II establish a program and give it boundaries. Principle III asks the question an outside observer would ask: how would anyone know it is working? The answer cannot be assertion. Organizations assert governance constantly; policies are adopted, committees convene, frameworks are referenced. What separates a functioning program from a paper one is evidence: a record, kept in the ordinary course, from which a director, an auditor, or a regulator could reconstruct what was decided, by whom, under what authority, and on what information.

Evidence as an Asset

Evidence deserves to be understood as an asset rather than an administrative burden. An organization that can demonstrate its governance earns something competitors cannot easily copy: the confidence of capital providers weighing an investment, regulators deciding how closely to look, counterparties deciding what to entrust, and customers deciding whom to believe. In a market where every organization claims to use AI responsibly, demonstration is the differentiator, and the program is what produces it.

The standard we suggest the board set is that evidence spans the lifecycle: from the decision to pursue or acquire a capability, through deployment and monitoring, to the decision to retire it. Retirement belongs in the record as fully as adoption: models withdrawn deliberately, the dependencies of other systems and agents unwound, and decision logs preserved for the lookbacks that regulators increasingly require. At oversight altitude, the record should show:

  • Decisions. Each consequential AI decision traceable to the authority that made it: within whose tolerance it fell, under which trigger it moved, and on what information it rested. Consequential carries both of its meanings here: decisions material to the enterprise, and decisions with significant effects on individuals.
  • Boundaries in practice. That the tolerances of Principle II are observed, along with its fixed constraints, that exceptions are escalated as designed, and that aggregate exposure is monitored as authorized decisions accumulate.
  • Systems over time. That the organization knows what its systems are doing after deployment, not only at approval: tested before release and re-tested after material change, behavior monitored for drift, vendor models watched as they change beneath the products built on them, and agreed limits tested rather than presumed.
  • Integrity. That the organization can explain, at a level appropriate to the audience, what a system does and does not do, and that changes in behavior and second-order effects are surfaced rather than discovered.

Management’s record beneath this will be operational and technical: data and decision lineage, version histories, the results of adversarial testing, the auditability of vendor commitments. Directors do not review that record; they require that it exists, that it stays current, and that it can be produced on demand. A useful board question is not whether documentation exists but how long it would take to show an examiner how a particular decision was made. The answer should be measured in days.

Evidence will also reveal whether the organization’s adjacent disciplines are connected. AI, cybersecurity, and data quality are frequently run as separate initiatives, and the record shows the seams: a model governed carefully but fed by data no one vouches for, a system reviewed for security but never for behavior. The connection matters more as agentic systems spread, because an error in data that one system would have contained can pass from agent to agent and compound. The board need not manage the connection; it should expect the program’s evidence to demonstrate that someone does.

Where Legal Obligations Are Answered

This is also where directors’ legal and regulatory obligations are answered, and deliberately so. The duties described in the Introduction are discharged in substance by what this principle produces: a documented, functioning system of oversight is the strongest demonstration that directors informed themselves and acted. Supervisory expectations forming across jurisdictions point in the same direction, commonly placing responsibility for AI governance with the board and commonly resting on authority regulators already hold. Organizations should not wait for new rules to learn what will be asked of them; the program that satisfies this principle will already have the answer. Protection, in this view, is not the reason to govern. It is a product of governance that works. Companion Tool E gathers the underlying foundations.

Independent Assurance

Finally, we recommend that the record be tested by someone without a stake in it. The assurance functions the organization already maintains, internal audit chief among them, should periodically examine whether the program operates as chartered: whether decisions stayed within boundaries, whether escalations happened as designed, and whether the evidence would hold up under outside examination. Where the organization builds on third-party models it cannot see inside, assurance extends to the vendors’ own independent attestations and certifications, and to the audit commitments written into contracts, held to rather than filed. For smaller organizations this may be an external review on a proportionate cycle. The point is independence, not scale.

Evidence demonstrates that the system works. The next principle addresses what the system is for.

IV.

Directors should ensure AI governance is connected to strategic planning, investment decisions, and value realization.

A.Start from purpose: why the organization is adopting AI, stated plainly enough to be measured.

B.Integrate the program with strategic planning and capital allocation.

C.Measure value realized alongside risk taken.

D.Treat governance as the discipline that allows the organization to compete with confidence.

A governance program disconnected from strategy will drift toward what it can measure: policies adopted, reviews completed, incidents avoided. Those are the mechanics of governance, not its purpose. The program described in these principles exists so the organization can pursue AI advantage deliberately: taking the risks it chose, at the speed the opportunity demands, with the board’s confidence rather than its anxiety.

Start from Purpose

The connection begins with a question the board is uniquely positioned to insist upon: why is this organization adopting AI? The answers differ, and the difference matters. For one organization the purpose is competitive, protecting market position through productivity and cost. For another it is innovation, compressing the time from idea to market. For a third it is judgment, better decisions built on better use of what the organization already knows. And for some, the honest answer is larger: AI changes what the business is, the products it sells, the markets it serves, and the basis on which it competes. The strategy conversation must be allowed to reach that answer, and directors should be wary of one that never does. Until leadership can state the purpose, adoption is imitation, and no methodology can say whether it is working.

Stating the purpose does something else: it makes the cost of standing still calculable. An organization adopting AI to defend market position can estimate what inaction costs in share and margin as competitors lower their costs and shorten their delivery times. An organization adopting for speed can state its exposure as the gap between its release cycle and the cycle AI makes possible. These are estimates, and the discipline of Principle II applies to them: stated bases, documented judgment, and honesty about uncertainty. But once the purpose is explicit, the cost of inaction can enter planning with the same standing as the cost of action, which is where the Preface’s argument becomes operational.

Integration with Strategy and Capital

Integration then follows naturally. AI strategy should be examined wherever strategy is examined: in the planning cycle, in capital allocation, and in the investment gates through which significant commitments pass. We recommend that a proposal involving AI state the value it intends, the risk it accepts, and the tolerance domain within which it falls, and that the same gates carry the criteria for scaling, pausing, or ending an initiative once its results are in, so that the board sees strategy and risk as one conversation rather than two. Over time the board should see both sides of the ledger, risk and return in a single view: the value realized from the risks taken, alongside the losses avoided and incurred. A program that reports only incidents will teach the organization that governance is about incidents. Incentives are part of the connection as well: leaders paid for speed alone will trade governance for speed, and compensation should reward value created inside the boundaries the board approved. The Institute’s Guiding Principles for Compensation Committees treats this discipline in depth.

What AI Does to the Organization Itself

Strategy also includes what AI does to the organization itself. This technology changes how work is organized: decision authority moves, management layers compress, and people at the front line resolve matters that once traveled upward for approval. Part of what a governance program must watch, in other words, is organizational design in motion. So does capability: the skills, the leadership, and the depth of people the chosen strategy requires. Principle I asks that question of the program; the board should ask it of the enterprise. Culture belongs in the same conversation. How leadership frames AI, as a capability to be developed or merely a cost to be cut, will shape whether people surface what they are doing with it or conceal it, and that difference determines whether the intelligence channels of the next principle carry signal or silence. For some organizations the strategic frame extends further still, to their position in the AI ecosystem, their dependencies in its supply chain, and the policy debates forming around it. The board does not manage any of this; it ensures the strategy conversation is wide enough to see it.

A program connected to strategy knows what it is for. What remains is the flow of intelligence that lets the board govern it at pace.

V.

Directors should confirm that escalation and reporting channels deliver timely, unfiltered intelligence, surfacing both threats and opportunities.

A.Require reporting that reaches the board without dilution.

B.Expect opportunity escalation alongside incident escalation.

C.Confirm the board’s information architecture keeps the board informed enough to authorize speed.

The final principle is the program’s nervous system. Everything before it depends on information arriving where it is needed, in time to matter: boundaries cannot be recalibrated around conditions no one reports, strategy cannot capture opportunities no one surfaces, and evidence cannot record decisions that were never visible. When directors ask whether escalation is covered, the common answer is an incident response plan. An incident plan escalates failures. A governance program escalates more than failures: it escalates use, decisions approaching boundaries, and opportunities.

Surface the Use

Begin with use. In most organizations, people are already using AI, whether the organization knows it or not. The choice available to the board is not whether this happens but where it happens: in the known, where use is surfaced, inventoried, and assessed, or in the unknown, where risk accumulates unseen and the organization meets it by surprise. The program’s channels should make surfacing easy and safe: a person who discloses a use, or a capability they have discovered, should find a receptive path rather than a penalty. This is where the cultural point of Principle IV becomes structural; channels carry what the culture permits people to say.

Opportunity Escalation

Opportunity escalation deserves equal standing, stated in Principle II and completed here. A practice discovered at the keyboard that would make the organization materially faster or better is intelligence of the same rank as an emerging threat, and its loss carries a cost measured in the terms Principle IV made explicit. The program should define how such discoveries move upward, who weighs them, and when they reach the board. Not everything reaches the board, nor should it; what reaches the board is what changes the picture.

Properties of the Channels

The channels themselves should be defined, and we would press for a few properties:

  • Reach without dilution. Reporting arrives with its severity and facts intact: management adds context and remediation plans on the way up, but findings are not softened and red flags are not filtered out. Bad news travels as fast as good.
  • Defined triggers. The conditions requiring immediate board or committee notification, set in advance in the methodology of Principle II.
  • Both directions. Threats and opportunities travel the same paths, with the same discipline.
  • A record. What was escalated, to whom, and what was decided, feeding the evidence of Principle III.

Cadence

Cadence is the hard problem. The technology moves weekly; boards meet quarterly. The program should therefore define the board’s information architecture between meetings: a continuous briefing stream proportionate to the organization’s exposure, thresholds for interim notification, and the standing ability of directors to inform themselves, through recognized access to the program’s reporting and through briefings they can request without waiting for an agenda. Where the board maintains technology or risk committees, the accountable officers should keep those chairs informed of significant developments as they arise; that line stays open between meetings. Directors who are informed enough, soon enough, can authorize speed. Directors who are not will reasonably hesitate, and the organization will pay for that hesitation in the opportunity cost Principle IV made visible.

Taken together, the five principles form a single argument. A chartered program gives the pieces structure and an owner. Board-approved tolerances give leadership room to move at pace. Evidence turns governance into trust. Strategy gives the risk-taking its purpose. And intelligence keeps the board informed enough to keep authorizing all of it. This is what the Institute’s conviction looks like in operation: not governance that slows the organization down, but governance that lets ambition move with confidence.

Conclusion

This document opened with the conviction that has run through the Institute’s publications from the beginning: risk-taking is how organizations create value, and the board’s role is to see that it is taken well. Artificial intelligence has not changed that conviction. It has raised the price of holding it loosely.

The five principles ask for nothing a board does not already have. The duties are the ones directors hold today; the disciplines are the ones good risk governance has always used; the program simply connects them into a system built for the speed at which this technology moves. What is new is the posture the moment requires: stewardship that adds foresight to oversight, boundaries revisited as often as the technology moves, and an appetite for the upside held as deliberately as the guard against the downside.

Where to Begin · Three Moves This Quarter

For a board wondering where to begin, the first moves are modest, and each can happen this quarter.

  1. 1.Ask whether the pieces of AI governance the organization already holds constitute a system, and who answers for the whole.
  2. 2.Put the program’s charter on an agenda, and treat approving it as the exercise of a duty the board already carries.
  3. 3.Ask leadership to state, plainly enough to be measured, why the organization is adopting AI.

Each begins producing the confidence this document is about.

A set of companion tools accompanies these principles and is maintained on the Institute’s site, where it can be kept current as practice and expectation evolve: the principles at a glance, an illustrative oversight RACI, guidance on applying the principles at scale, an illustrative program model, the legal and regulatory foundations of AI oversight, and an illustrative program charter, together with a responsible AI use policy template. Each is designed to be taken into a boardroom.

The technology will keep moving; that is the one assumption this document makes without qualification. Boards that meet it with a chartered program, honest boundaries, working evidence, connected strategy, and open channels will not merely keep up. They will be able to say yes sooner, and mean it. That is governance in the Institute’s tradition: not the brake on ambition, but the reason ambition can be trusted.

The Companion Tools

Six standalone tools accompany this document. Each opens as its own page, each is downloadable as a PDF, and each is designed to be taken into a boardroom.

About this publication

Guiding Principles for Programmatic AI Governance is a publication of the DCRO Risk Governance Institute, produced by its Programmatic AI Governance Council. It joins the Institute’s Guiding Principles series alongside the volumes on board risk committees, cyber risk governance, compensation committees, and reputation risk governance. Citations of this document should reference the originating work of the Council.

The document was co-produced with the Center for AI Oversight, an independent 501(c)(3) educational institution that defines oversight governance for AI in regulated industries. The Center served as drafter to the Council. The Center’s AI Oversight Program, from which the illustrative model in Tool D is drawn, is available at cfaio.org.

The companion tools on this site are maintained as living resources: the paper states the principles, which are built to endure; the tools carry the material that moves with practice, and they are kept current as expectation and experience evolve. The document is designed to be read on this site or downloaded as a PDF; each tool downloads separately.

The DCRO Institute

Citations of this document should reference the originating work of the DCRO Institute’s Programmatic AI Governance Council.
Co-produced with the Center for AI Oversight — defining oversight governance for AI in regulated industries — drafter of this document. cfaio.org
© The DCRO Risk Governance Institute.