Start here if you sit on a board or in the C-suite.

Seven stops, in order. Each one answers a question a board should already be asking about AI — an assurance walk, not a technical education.

  1. What good AI oversight looks like The operating model: roles, policy, and the evidence that lets you prove AI is governed day to day, not just documented in principle.
  2. What could actually blindside you Four severity tiers, nine categories. Start with Critical — the risks that would stop a launch — before reading the rest.
  3. What's legally required, and by when The EU AI Act timeline, separated into what's active now and what's deferred, plus where ISO/IEC 42001 and the NIST AI RMF each stop short.
  4. A worked example, not a hypothetical An open investigation: can a handful of people actually govern and steward a UK-regulated retail bank's AI? Built on the FCA's own Mills Review.
  5. The vendor question, answered directly Almost no organisation trains its own model — this is the SS2/21 discipline, applied to AI vendors specifically.
  6. Independent opinions, not vendor pitches Board and committee papers framed around risk appetite and tolerance, from someone who has held a GEC-1 risk role reporting to a Group CRO.
  7. The oversight question, laid out step by step A seven-stop learning path on who owns AI risk, what good oversight looks like, and where board authority cannot be delegated to a control.

This is the walk Andrew sends to a board considering AI risk.

Board & Executive Risk Reporting is one of five areas of expertise on the services page.