AI Governance Is a Board Responsibility: Nine Principles for New Zealand Directors

Key takeaways

  • AI should be treated as a strategic governance issue, not delegated solely to management or the technology team.
  • Boards need sufficient AI literacy to assess opportunities, challenge risks and oversee decisions supported by AI.
  • Responsible adoption requires clear governance of data, people, suppliers, privacy, security and stakeholder trust.

Artificial intelligence can improve productivity, decision-making, customer service and innovation, but it can also create privacy breaches, inaccurate outputs, bias, intellectual property risks and reputational damage. The Institute of Directors’ A Director’s Guide to AI Board Governance sets out nine principles for boards overseeing AI. Its central message is that directors do not need to become technology experts, but they must understand enough to ask informed questions, set direction and ensure their organisations use AI responsibly.

AI governance is therefore not simply about approving a policy. It requires AI to be incorporated into strategy, risk management, organisational culture and the board’s own practices.

The nine principles at a glance

The Institute of Directors recommends that boards:

  1. Take action from a strategic perspective: align AI adoption with organisational values, strategy and long-term objectives.
  2. Seize the opportunities: identify where AI can improve productivity, services, decisions and innovation.
  3. Categorise and address the risks: assess each use according to its potential legal, operational, ethical and reputational impact.
  4. Build board capability: develop enough AI literacy to question management and make informed decisions.
  5. Select the right board structure: decide whether oversight belongs with the full board, an existing committee or a dedicated group.
  6. Oversee AI use and data governance: approve policies, monitor performance and ensure data is reliable, secure and appropriately used.
  7. Look after your people: consider workforce impacts, communication, wellbeing and skills development.
  8. Proactively build trust: prioritise transparency, fairness, accountability and engagement with stakeholders.
  9. Embrace AI as part of governance practice: explore how AI can support board work without replacing directors’ judgement.

Together, these principles provide a framework for pursuing AI opportunities while maintaining responsible oversight and human accountability.

AI belongs in the organisation’s strategy

The first two principles are to take action from a strategic perspective and seize the opportunities. AI initiatives introduced without board-level direction can become fragmented, fail to support organisational goals and create risks that may not be identified early enough. The board’s role is to ensure AI aligns with the organisation’s values, long-term strategy and risk appetite.

This means identifying where AI could create genuine value rather than adopting it simply because competitors are doing so. Potential uses include automating manual tasks, supporting decisions, personalising services, improving risk management and assisting product development. Boards should also consider whether the organisation is ready, as effective adoption depends on suitable systems, reliable data, workforce capability and a culture that is prepared to learn.

Procurement requires particular attention. Before approving an AI system, the organisation should consider whether it supports a defined business objective, the supplier’s governance and security practices, contractual and data-protection arrangements, regulatory and professional obligations, implementation requirements, expected costs and benefits, and whether the organisation has the capability to use it properly. The board should understand not only what is being purchased, but how the supplier governs, tests and supports the tool, what data protections apply and how its performance will be monitored.

Categorise risks instead of treating every use the same

The guide recommends that boards categorise and address AI risks according to the nature of each use. A tool used to summarise a non-sensitive internal document presents different risks from an AI system used in recruitment or another process that could materially affect people. Controls should reflect the importance of the decision, the sensitivity of the data and the harm that could result from an error.

The guide identifies risks including privacy and confidentiality failures, inaccurate or misleading outputs, bias and discrimination, intellectual property infringement, cybersecurity threats, poor transparency, operational failure, workforce disruption and reputational damage. Generative AI creates a particular accuracy risk because it may produce plausible but incorrect information, so boards should ensure review requirements are proportionate to the use and that people remain responsible for important decisions.

Data governance is central to this oversight. Boards should know what information the organisation holds, why it is collected, where it is stored, how it moves between systems and which external parties can access it. Poor data can also produce unreliable AI results. If training or input data is incomplete, inaccurate or unrepresentative, a system may reproduce existing errors or disadvantage particular groups.

The guide suggests considering established frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001:2023 when designing an organisation’s governance approach.

Boards need capability and an appropriate oversight structure

Boards may rely on management and specialist advisers, but directors retain responsibility for oversight and must critically assess the information and advice on which they rely. Directors do not need to understand every technical detail, but they should be able to discuss AI’s implications for strategy, risk, ethics, privacy and organisational performance.

This may require regular briefings, structured training, external advice and periodic assessment of the board’s capability gaps. AI and relevant regulatory developments should appear regularly on the board agenda rather than being considered only when a major project seeks approval.

Boards must also decide how oversight will be structured. A large organisation with complex AI systems may establish a dedicated AI committee or technical advisory group, while other organisations may include AI within an existing audit, risk or technology committee. For a smaller organisation, oversight by the full board may be more appropriate. There is no single correct structure, but responsibility should be visible, decision rights should be clear and AI should receive regular attention.

An effective governance framework should define the respective responsibilities of the board and management, principles for responsible use, acceptable and prohibited uses, approval processes, privacy controls, testing and review expectations, incident escalation and training requirements. Boards may also request an AI dashboard covering accuracy, security and privacy incidents, efficiency, customer impact, financial value and identified risks. More formal audits may be appropriate where AI is used extensively or affects important decisions.

Responsible AI depends on people and trust

AI adoption may change roles, alter skill requirements and create uncertainty about job security. Boards should ensure workforce implications are considered as part of the strategy rather than treated as consequences to manage after implementation. Clear communication and practical training are essential, and employees should understand why AI is being introduced, how it supports organisational objectives and what safeguards apply. Organisations should also provide opportunities for employees to build new skills and participate in identifying useful applications.

Trust is equally important. Customers, employees, regulators and other stakeholders may want assurance that AI is being used fairly and safely, so boards should consider transparency, human oversight, bias testing, privacy and the wider effects of the organisation’s decisions. This may include engaging with diverse perspectives and considering Māori interests in data governance and data sovereignty.

Boards should also consider using AI in their own governance work. Potential applications include summarising board papers, identifying issues, generating questions, supporting scenario analysis and improving administrative workflows. However, AI should support rather than replace directors’ judgement. Confidential board information must be protected, outputs must be checked and responsibility for decisions remains with the board.

What this means for your organisation

Organisations should put AI on the board agenda and establish a regular process for discussing opportunities, risks, projects and relevant developments. They should identify where employees, suppliers and existing software are already using AI, as unapproved or hidden use may create risks before the board considers a formal programme.

Each use case should be categorised according to the information involved, its potential effect on people, the consequences of an error and the level of human review available. The board should then approve an AI policy or framework that defines responsibilities, acceptable use, data protections, review requirements, monitoring and escalation.

Capability should also be built across the organisation. Board education should focus on strategic oversight and informed questioning, while employee training should address safe use, privacy, verification, professional judgement and the reporting of concerns.

Conclusion

AI governance is not a technical responsibility that boards can hand entirely to management. Directors remain responsible for setting direction, assessing risk, protecting stakeholders and ensuring that important decisions remain subject to human judgement.

The Institute of Directors’ nine principles provide a practical starting point. Boards should approach AI strategically, pursue appropriate opportunities, categorise risks, build capability, establish clear oversight, protect data and people, build trust and consider how AI can improve governance itself.

The organisations best placed to benefit from AI will not necessarily be those that adopt it first. They will be those whose boards create the conditions for AI to be used deliberately, responsibly and in support of long-term value.

Sources and qualification

The principal guide was published in July 2024. Since then, New Zealand has released a national AI strategy and voluntary responsible-AI guidance for businesses, while the Institute of Directors has issued further guidance on AI use in boardrooms. Organisations should confirm current legal, privacy, contractual and regulatory requirements when implementing or reviewing AI systems.

About the author

Campbell McKenzie is a Director at Incident Response Solutions, a New Zealand firm experienced in cyber incident response, digital forensics, investigations and technology risk. Through KiwiGen.AI, Campbell helps professional services firms adopt generative AI safely, with practical governance and controls.