← All articles

Mark McNamara · 23 July 2026 · Open

The AI Governance Gap: Why Your Board's Risk Register May Be Incomplete

Traditional risk frameworks were not designed for systems that learn, adapt, and make decisions autonomously. Boards need to understand where the gaps are.

risk oversightrisk registerAI governance

The AI Governance Gap: Why Your Board's Risk Register May Be Incomplete

Most boards have a risk register. Most boards update it annually. Most boards are confident it captures the key risks facing their organisation.

If your board has not considered how AI changes the risk landscape, that confidence may be misplaced.

Three Categories Traditional Risk Frameworks Miss

1. Model Risk

AI systems are not static. They are trained on data, and their behaviour can change over time as they are retrained, fine-tuned, or deployed in new contexts. A model that performs well today may produce biased, inaccurate, or harmful outputs tomorrow — without any obvious trigger.

Traditional risk frameworks treat technology as deterministic. If you build it right and test it, it works. But AI models introduce uncertainty into outcomes that cannot be resolved through standard testing alone.

What to ask: Do we have a process for validating AI model outputs on an ongoing basis? Who decides when a model needs to be retested or retired?

2. Data Risk

AI systems are only as good as the data they are trained on. But the data risks go beyond quality. They include:

  • Data provenance. Do we know where the training data came from? Is it lawfully obtained? Are there copyright or intellectual property considerations?
  • Data lineage. Can we trace how data flows through the AI system? Do we know where outputs end up?
  • Data privacy. Does the AI system process personal information? Is that processing compliant with privacy legislation?
  • Data security. Could an attacker manipulate the data to alter the model's behaviour?

Most risk registers capture data security and privacy. Few capture provenance, lineage, or model-specific data risks.

What to ask: Does our data governance framework cover the specific risks introduced by AI training and inference?

3. Accountability Risk

This is the most overlooked category. When an AI system causes harm, who is accountable?

The developer? The deployer? The board that approved the system? The vendor who supplied it?

Traditional risk frameworks assume clear lines of accountability. AI diffuses accountability across multiple actors, supply chains, and decision points. If your risk register assumes a single owner for each risk, it is not equipped for AI.

What to ask: Have we mapped the accountability chain for every AI system in use? Is there a named person responsible for each system's outcomes?

Bridging the Gap

The solution is not to abandon traditional risk frameworks. It is to extend them.

Consider adding an AI-specific risk annex to your existing risk register. This should cover:

  • Strategic risks. Reputational harm, competitive disadvantage, regulatory action
  • Operational risks. Model failure, data quality, vendor dependency
  • Compliance risks. Breach of privacy, discrimination, consumer protection, intellectual property
  • Ethical risks. Fairness, transparency, explainability, human oversight
  • Systemic risks. Concentration of AI vendors, supply chain dependencies, single points of failure

A Practical Exercise for Your Next Board Meeting

Ask your risk committee or management to produce a short report identifying:

  1. All AI systems currently in use (including shadow AI)
  2. The risks each system introduces, mapped to the categories above
  3. The existing controls in place for each risk
  4. A gap analysis — what is not being controlled

Review this report at the board level. Then decide whether your risk register adequately captures the AI landscape.

If it does not, you have found the gap. Closing it is the next step.