Tier 1: Foundation controls
AI risk appetite and tolerance
Board-approved boundaries that define which AI risks are acceptable, which are constrained, and which are not permitted, with measurable thresholds for decision-making.
Board-defensible evidence
- Board or committee-approved risk appetite statement that explicitly addresses AI harms (safety, discrimination, privacy, security, financial reporting impact), including approval date and reviewing body.
- Operational tolerance thresholds translated into measurable limits (error rates, drift thresholds, false positive rates, bias metrics, latency or uptime requirements), including who set each threshold and the rationale.
- Decision logs showing how appetite and tolerance were applied to approve, reject, or constrain specific AI use cases, including escalation paths when risks exceeded tolerances.
- Exception register documenting each override, who approved it, what compensating controls were required, and when the exception expires or is re-evaluated.
- KRIs and reporting pack evidence showing how leadership monitors adherence to appetite over time, including trend reporting and remediation when limits are breached.
Why this matters
In enforcement or litigation, the gap between stated appetite and actual approvals becomes discoverable evidence of oversight failure.
How ready is your board on foundation controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.