Governance accountability and the board.

Seven stops, in order. This walk answers one question: when AI goes wrong, who was accountable — and could they actually have done anything about it?

  1. What board-level AI oversight actually requires Accountability that doesn't delegate away — what 'good oversight' means in practice, before the detail.
  2. Is there a policy at all Operating AI systems without a top-management-approved policy defining acceptable use, risk appetite, and escalation routes.
  3. Who actually owns this No individual or committee owns AI risk decisions end-to-end — accountability that's diffuse in practice, however clear it reads on paper.
  4. The control that names an owner A named individual or committee accountable for each AI system's risk posture, with defined reporting lines.
  5. When oversight exists but does nothing A human-oversight mechanism that exists on paper but isn't actually usable or effective in practice — the gap between a control's design and its operation.
  6. Where the board's authority can't be delegated Eight EU AI Act prohibitions with almost no matching controls in this library — deliberately, because the correct response to a legal prohibition is a decision, not a mitigation.
  7. A worked example, not a hypothetical An open investigation: can a handful of people actually govern and steward a UK-regulated retail bank's AI? Built on the FCA's own Mills Review.

Accountability that reads well on paper isn't accountability.

Every stop above maps to a named risk in the library, not a general governance principle.