An audit committee does not need to understand the models to oversee how its organization uses AI. It needs to know whether the organization can answer a short set of questions about data, accountability, and control. If management cannot answer them clearly, AI use is running ahead of its governance.
These questions cover how the organization uses AI day to day, the control layer an audit committee is built to oversee. They are the foundation, not the whole picture.
Most of these questions are not new. They are the same questions directors ask about cybersecurity, financial controls, privacy, and operational risk. Yet fewer than one in four companies have a board-approved, structured AI policy. That gap between AI adoption and AI oversight is what these questions are meant to close.
The questions below come from how we structured Architech's own AI use policy. They are deliberately practical. A director should be able to ask any one of them in a meeting and get a direct answer.
01Data and classification
- Is there a data classification scheme, and is it clear which categories of data may enter which AI tools?
- How is personal and identifiable information handled, and is it prohibited from AI tools unless a tool has been explicitly approved for it?
- Is client data treated as restricted by default, rather than only when someone remembers to flag it?
02Tools and connectors
- Is there a register of approved AI tools, and does it specify the data classification each tool is allowed to handle?
- Are connectors to other systems off by default and enabled only with explicit approval and minimum necessary access?
- Who is permitted to approve a new tool or connector, and is that authority documented?
03Levels of autonomy and oversight
- Does the organization distinguish between AI that provides recommendations, AI that generates work for human review, and AI systems that can take actions autonomously?
- Does the level of required human oversight rise as the system's autonomy rises?
- For any agent operating in production, are its scope, permissions, and the ability to stop it defined in advance?
04Accountability and review
- Is a named, qualified human accountable for every AI-influenced deliverable and prepared to take ownership of the output as if they had produced it themselves?
- Is AI-generated content reviewed before external release, with review depth proportional to the impact of the decision?
05Traceability
- Where AI materially influences a deliverable, is its use documented, including the tool, the type of use, and the responsible reviewer?
- Is that documentation held within standard project records rather than in someone's memory?
06Exceptions, monitoring, and incidents
- Is there a formal exception process, with approvals that are written, scoped, and time-bound rather than informal and permanent?
- Are tool and connector usage audited periodically, and are deliverables spot-checked?
- Is there a clear path to report misuse or unauthorized data exposure, and does someone own the decision to escalate?
An organization that can answer these questions is not necessarily low-risk. But it is governable, which is the standard a board should hold it to.
The organizations that succeed with AI will not be the ones using the most tools. They will be the ones that can explain, tool by tool, who is accountable and how use is controlled.