Start here if you sit on a board or in the C-suite.
Seven stops, in order. Each one answers a question a board should already be asking about AI — an assurance walk, not a technical education.
- What good AI oversight looks like The operating model: roles, policy, and the evidence that lets you prove AI is governed day to day, not just documented in principle.
- What could actually blindside you Four severity tiers, nine categories. Start with Critical — the risks that would stop a launch — before reading the rest.
- What's legally required, and by when The EU AI Act timeline, separated into what's active now and what's deferred, plus where ISO/IEC 42001 and the NIST AI RMF each stop short.
- A worked example, not a hypothetical An open investigation: can a handful of people actually govern and steward a UK-regulated retail bank's AI? Built on the FCA's own Mills Review.
- The vendor question, answered directly Almost no organisation trains its own model — this is the SS2/21 discipline, applied to AI vendors specifically.
- Independent opinions, not vendor pitches Board and committee papers framed around risk appetite and tolerance, from someone who has held a GEC-1 risk role reporting to a Group CRO.
- The oversight question, laid out step by step A seven-stop learning path on who owns AI risk, what good oversight looks like, and where board authority cannot be delegated to a control.
This is the walk Andrew sends to a board considering AI risk.
Board & Executive Risk Reporting is one of five areas of expertise on the services page.