← Back to Perspectives
Board Governance

Why Boards Need to Rehearse AI Governance Decisions

A board can approve an AI governance framework and still not know how management will behave when an AI decision stops being hypothetical.

Board-level AI oversight often loses the decision inside a good paper. When directors see it, the principles, roles, risk appetite and approval pathway have been assembled into a coherent account of the system. What the paper cannot show is how management behaves when the business wants the benefit, the supplier says the feature is standard, the data question arrives late, and no one is quite sure who has authority to slow the decision down.

Boards should ask more than whether AI governance has been designed. They should ask whether management has rehearsed using it against a decision that still has room to move. That’s the narrow version of a broader claim I’ve made elsewhere: privacy, data and AI governance have to work where decisions are actually made.

Rehearsal makes the decision visible. It shows whether management can identify the call being made, bring in the people who can change it, test the evidence and the benefit case, keep the privacy and data consequences in view, and leave one person accountable for the residual exposure before momentum does the deciding for them.

The Board Paper Does Not Show The Room

Board papers usually arrive coherent. The disagreement has been smoothed into options, the uncertainty has been converted into risk language, and the awkward parts have often been resolved somewhere below the board line. That’s part of how board reporting works, not a flaw in itself.

AI governance can look much stronger in that form than it is when the organisation has to make a live decision.

A framework assigns accountability cleanly while nobody is yet asking a business owner to narrow a use case, delay a launch, reject a supplier setting, or explain why the claimed benefit isn’t enough to justify the intrusion. A dashboard records AI uses without showing whether the difficult ones were challenged while challenge still mattered. A committee appears to own the issue because it receives the paper, even when the actual decision was made earlier by people who never thought they were making an AI governance call.

Board assurance thins at exactly that point. Directors are asked to take comfort from the existence of a system, but the risk sits in whether management can use it while the decision is still open.

AI Decisions Arrive Before They Look Like Board Decisions

Many AI decisions don’t arrive wearing a board label.

They arrive through the weak pathways I described in AI Governance Is the Stress Test for Your Operating Model: the vendor feature already inside a platform, the tool staff adopted because the formal process was too slow. Or they arrive looking like something else entirely: a fraud control with a persuasive loss-reduction case and a thin account of customer impact, or a workforce analytics feature that looks useful until someone asks what kind of visibility into employees it is normalising.

A formal AI governance paper often arrives after the organisation has built a position around proceeding: the supplier has been briefed, the business case has been socialised, the pilot has produced promising numbers and the operating team has started to rely on the output. Governance is still possible, but it is no longer operating in neutral conditions. Everyone in the room can feel the cost of changing course.

Rehearsal tests whether management recognises an AI governance decision before it has gathered enough organisational weight to become the default.

Trace The Decision Management Already Made

Before asking management to rehearse a plausible decision, a board should ask it to trace a material AI decision that has already happened. That trace follows the sequence behind the completed assessment or committee paper: when the use first became visible, when privacy and the other relevant functions entered, what evidence behind the claimed benefit was tested, which alternatives still existed, what changed, who accepted the remaining exposure, and whether the conditions attached to approval took effect in the business.

That account tells directors much more than another dashboard of completion rates. It shows when the assessment arrived after supplier selection, whether the supposedly fixed configuration was alterable, whether a challenge narrowed the use, and whether a launch condition was lost once delivery moved on. The documents still matter, but the trace connects them to the decision they were meant to govern.

A real decision brings its own distortions. Any one result may have been shaped by a strong practitioner, a senior sponsor’s intervention, a commercial case that changed for unrelated reasons, or people reconstructing a cleaner sequence once they know the outcome. Directors learn what happened in that decision, not what the same operating model will reliably produce next time.

The trace gives the board the history of one decision; rehearsal lets it see what management does with the next one before that history has already been written.

Rehearsal Tests The Decision While It Is Still Open

The cyber world has made boards familiar with tabletop exercises because an incident response plan isn’t much comfort if nobody has tested how the organisation behaves when facts are incomplete, time is short and consequence is real. AI governance needs a related discipline, but earlier in the cycle.

Rehearse the decision before the organisation has committed to the use, not the crisis after the harm.

A good rehearsal puts management into a plausible AI decision with enough detail to prevent a comfortable abstract discussion. The facts should be incomplete, because real facts usually are. The benefit should be credible, because weak benefits make the exercise too easy. The privacy, data, legal, risk, technology and business questions shouldn’t line up neatly, because they rarely do when the decision is worth escalating.

The exercise shouldn’t trap people; it should show what the organisation reaches for under pressure. Does management ask for the evidence behind the claimed benefit, or accept the business case because the use sounds innovative? Does privacy arrive early enough to affect the shape of the decision, or only late enough to record concern? Can the people in the room challenge each other in terms the decision owner can use, or does each function retreat to its own lane? And can someone say “not yet” without the room treating that as obstruction, or does risk challenge on paper while the residual exposure drifts into a committee because nobody wants to own the call?

Those behaviours are hard to see in a policy. They become visible very quickly in a rehearsal.

The First Gap Is Usually Ownership

A tool sits inside technology while its output changes how a business team treats customers. The system owner answers for configuration and the sponsor for benefit, yet the actual call falls between them once human consequence and residual exposure enter the discussion. Privacy challenges and risk escalates, but neither function owns the business decision.

Ownership matters because AI governance doesn’t fail only when someone makes a reckless decision. It also fails when the organisation can’t say who had authority to proceed, narrow, pause, escalate or accept the exposure on behalf of the business. If the residual risk belongs everywhere, it belongs nowhere useful.

Boards need not approve every AI use case, but they do need evidence that management knows where the decision sits, what standard of evidence is required, who can challenge the use, and who is allowed to accept the answer when the challenge hasn’t been resolved.

A rehearsal gives directors a better signal than a role description. It shows whether the role description still holds once a decision arrives that people actually want to make.

A Smooth Exercise May Be The Warning

There’s a temptation to run a rehearsal as a polished governance event. The scenario is tidy, the facts are available, the roles are clear, the decision is obvious, the outputs are actions, and everyone leaves reassured.

A run-through like that may be useful for familiarising people with the process. It’s not enough for board assurance.

AI governance has friction, so a rehearsal should introduce enough of it to make the decision genuinely difficult: a credible business reason to proceed, a data use that isn’t obviously forbidden but is still hard to defend, a supplier assurance gap that can’t be fixed in the meeting, an affected group whose interests are easy to underweight, and timing pressure that makes escalation inconvenient. Otherwise the exercise is a walkthrough of the framework, run under conditions chosen to let it pass.

The board should be wary of comfort that comes from removing the very conditions that make AI decisions hard.

The output should include actions, but the board gains more from the account of the decision path: where ownership blurred, where evidence was assumed, where challenge arrived too late, where the risk appetite statement didn’t help, and where directors would need different information before accepting the same decision in practice. That account shows how management makes a difficult decision, not merely that an exercise occurred.

The Board Needs More Than One Kind Of Evidence

Policies, inventories and governance forums tell a board how management intends AI governance to work. What remains untested is how people use that design when a difficult decision arrives, and another document cannot supply the answer.

The board should expect management to trace a material decision that has already happened, including the point at which governance entered and what effect it had, then rehearse a plausible decision with enough benefit, ambiguity, ownership tension and pressure to expose what people do when the answer is not obvious.

The trace gives directors evidence of how one real use was governed. Rehearsal exposes whether management can recognise the next decision, slow it down when needed, challenge the evidence, keep the people affected in view, allocate ownership, and leave a record that would still make sense later to a regulator, employee, customer, journalist or director who wasn’t in the room.

Neither should be oversold. Hindsight distorts a trace, and one rehearsal captures behaviour once against a scenario somebody chose. A good result may reflect a strong individual or a convenient scenario rather than a well-designed operating model. Rehearsal doesn’t replace the design work either: where ownership is unresolved, it exposes the gap but does not close it.

If directors have seen neither a real decision traced nor a plausible one rehearsed, the board paper is evidence of management’s design, not its behaviour.

A board should ask what happened to the last material AI decision, then watch what management does with the next one before the organisation has to defend it for real.