Explainer
    Perspective
    Perspective

    Part of The company brain: where your organization's knowledge lives

    Five questions a supervisory board can ask about AI every quarter

    Overseeing AI takes no technical knowledge, just the right questions. Five quarterly questions for the supervisory board, what a good answer looks like and when to probe further.

    Max van Genderen5 min read
    Share on
    Five questions a supervisory board can ask about AI every quarter

    A supervisory board does not need to understand how a language model works to oversee AI well. What it needs are five fixed questions every quarter. The answers show whether AI delivers value, whether someone is accountable, and whether the organisation can stop when things go wrong.

    Oversight of the annual accounts works the same way. You don't have to do the bookkeeping yourself to see whether the numbers add up. You need to know which questions to ask and what a good answer looks like.

    These five questions come from our AI governance framework: value, ethical boundaries and stop rules, built on a foundation of cybersecurity and data sovereignty. Read the full framework in AI governance for executive and supervisory boards: value, ethics and stop rules.

    01RegisterWhat runs, and who owns it02ValueResults against the business case03Stop rulesWas a threshold hit, what was decided04IncidentsReported within the legal deadline05ControlData in the EU and under your controlFive fixed questions every quarter, from register to control.

    1. Which AI applications are running, and who owns each one?

    Why this question: you cannot oversee what you cannot see. In many organisations nobody knows exactly which AI is running. There's a chatbot here, a Copilot licence there, and a pilot that was never formally stopped.

    A good answer: a one-page AI register. For each application it shows what it does, its status (pilot, in use, stopped) and who the business owner is. An owner is a person, not a department.

    Probe further if:

    • the answer is "IT" or "the data team". Then ownership is unclear;
    • the register hasn't been updated since last quarter;
    • employees use AI tools that aren't in the register.

    2. What have they delivered compared with the business case?

    Why this question: AI projects are often started on enthusiasm and continued out of habit. Without measurement, nobody knows whether an application is worth its cost.

    A good answer: a business case for each application, written before the start, with a baseline and a target. Next to it is the current state. For example: hours per week spent checking figures, the percentage of AI answers rated correct, and the number of active users.

    Probe further if:

    • benefits are described rather than measured ("employees are enthusiastic");
    • there is no baseline, because then every improvement is an assumption;
    • running costs are unknown. With AI, they grow with usage. See also An agent's bill is set before it runs.

    3. Has a stop criterion been hit, and what was decided?

    Why this question: this is the question most often missing, and perhaps the most important. An application without stop rules keeps running simply because it has started.

    A good answer: every application has stop criteria that were set before go-live. They cover thresholds for quality, usage, cost, data quality, privacy and bias. The answer also states whether a threshold was hit and what the executive board decided: continue, adjust or stop.

    Probe further if:

    • a criterion is never hit, because that may mean nobody is measuring;
    • thresholds were moved after the fact;
    • nobody can say how to stop an application technically, and how quickly.

    4. Were there incidents, and were they reported within the deadlines?

    Why this question: the Dutch Cyber Security Act (the national implementation of NIS2) and the GDPR set fixed reporting deadlines, and the clock starts at the moment of discovery.23 Executives carry final responsibility. Reporting late is a second incident on top of the first.

    A good answer: an overview of incidents and near misses, showing for each when it was discovered, reported and resolved. Also an escalation ladder with fixed deadlines, tested every year.

    Probe further if:

    • there are never any near misses. A healthy organisation does see them;
    • the supervisory board only hears about a significant incident afterwards;
    • the last disaster recovery test was more than a year ago.

    5. Does all data stay in the EU and under our control?

    Why this question: every new connection with customers, partners or an AI model is a new route through which data can leak. Customers and regulators are also becoming more critical about where data is stored and who can access it.

    A good answer: every data connection goes through the same checks. Data stays in the EU, a data processing agreement is in place before the first data flow, the purpose is recorded, access runs through one identity with minimal rights, and there is an exit strategy.

    Probe further if:

    • the answer is "we're in an EU region" and nothing more. With American vendors, that does not fully rule out access under US law;
    • there are connections without a recorded purpose;
    • nobody knows how long switching to another vendor would take.

    A GOOD ANSWERPROBE FURTHER IFOne person owns each applicationThe answer is "IT" or "the datateam"Benefits measured against abaselineBenefits are described, notmeasuredThresholds set before go-liveA threshold is never hitNear misses are seen and reportedThere are never any near missesAn exit strategy per vendor"We're in an EU region" andnothing morePer question: what a good answer looks like and when to probe further.

    How to organise this in practice

    The five questions work best as a standing agenda item, with a one-page dashboard on which the executive board answers them. The dashboard contains:

    • the AI register with owners and status;
    • benefits against costs per application;
    • stop criteria that were hit and the decisions taken;
    • incidents and reporting deadlines;
    • the status of cybersecurity and NIS2.

    Once a year, the supervisory board reviews the framework itself: are these still the right questions? Schedule a short AI literacy session for the supervisory board at the same time. The AI Act requires AI literacy from those who work with AI, and oversight is part of that.1

    Such a dashboard does ask something of your data. If every application has its own definitions and logging, filling it in takes days every quarter. If everything runs through one layer, it's an export. See Connect once, not per agent.

    Frequently asked questions

    Does the supervisory board have to approve AI applications? No. The executive board decides on new applications. The supervisory board oversees the framework and is involved in significant incidents.

    How much time does this take per quarter? With a one-page dashboard and fixed questions, it's a fifteen-minute agenda item. Without a dashboard, it becomes an endless discussion.

    What if we don't have any AI applications yet? Ask the questions anyway. The answer to question 1 is often surprising, because there is usually more AI running than the board thinks. And the agreements are easier to make before the first application than after.

    Where do you start? With question 1. A complete AI register with owners is the basis for the other four. Request a foundation scan.

    Sources

    Every claim in this article can be checked at the source.

    1. 1
      Verordening (EU) 2024/1689 (AI-verordening), artikel 4

      EUR-Lex

      AI-geletterdheid voor wie AI inzet of gebruikt.

      Back to the text
    2. 2
      Cyberbeveiligingswet (NIS2)

      NCSC

      Meldplicht en verantwoordelijkheid van bestuurders.

      Back to the text
    3. 3
      Datalek melden

      Autoriteit Persoonsgegevens

      Meldtermijn van 72 uur onder de AVG.

      Back to the text

    Next step

    Want to see what's already inside your organization?

    Leave your details. We'll reach out and plan a scan. Within thirty days you'll see one concrete result.

    No newsletter, no reselling. Just this conversation.

    Comments

    Comments are reviewed by the editors before they appear.

    Use your Google or Apple account, or your business email address.

    Sign in to comment