Which board members need the deepest AI literacy?
Not every board member needs the same depth of AI literacy. The Chair, the Risk Committee Chair, the Audit Committee Chair, and any board members holding formal regulatory accountability (such as under the Senior Managers Regime) need deep AI literacy — enough to challenge management, interpret model risk reporting, and answer to regulators. Other non-executive directors need strong working literacy, sufficient to participate meaningfully in board discussions and escalate concerns.
Key takeaways
- AI literacy at board level is not one-size-fits-all; it should be mapped to accountability.
- The Chair, Risk Committee Chair and Audit Committee Chair typically require the deepest literacy.
- Regulatory accountability (e.g. Senior Managers Regime holders) increases the required depth of understanding.
- Working literacy is sufficient for other non-executives, provided they can engage critically and know when to escalate.
- This differentiation should be reviewed regularly as the organisation's AI use matures.
Boards are under growing pressure to show they can genuinely oversee how AI is used across their organisation.
Whether it is underwriting triage, credit decisioning, trading support or customer service automation, AI is now embedded deep enough into financial services operations that regulators expect senior accountability for it.
The instinctive response from many boards is to commission a single AI briefing for all directors and consider the governance gap closed.
That approach misses an important point: board members do not all carry the same accountability for AI-related outcomes, so they should not all be expected to reach the same depth of understanding.
Some directors need to be able to interrogate model governance reporting and answer directly to a regulator. Others need enough understanding to ask sharp questions and know when to escalate. Treating both groups identically either wastes time on directors who do not need technical depth, or — more dangerously — leaves accountable individuals under-prepared.
Why boards are facing this question now
AI oversight has moved from a technology question to a governance question.
Regulatory attention on AI use in financial services has intensified, and initiatives such as the UK's AI Compact place explicit expectations on organisations to demonstrate senior-level accountability for how AI systems are developed, deployed and monitored.
Existing supervisory frameworks, including FCA and PRA expectations around senior management responsibility, already require accountable individuals to understand the risks within their remit well enough to challenge them. AI is simply the latest area where that expectation is being tested.
At the same time, AI adoption inside firms is accelerating faster than most board education programmes. Underwriting teams, trading desks and customer operations are adopting AI-assisted tools well ahead of many boards formalising what oversight of those tools should look like.
This combination — rising regulatory expectation and faster internal adoption — is why boards are now being forced to ask a more precise question than "do our directors understand AI?". The real question is: which directors need to understand it deeply, and which need enough understanding to challenge and escalate?
The traditional approach to board skills development
Boards have faced comparable questions before. When cyber security and, more recently, ESG rose up the governance agenda, many boards responded the same way: a uniform briefing, typically annual, delivered to the whole board regardless of committee role.
This approach has some genuine advantages. It is efficient to organise, it ensures a shared baseline vocabulary across the board, and it avoids singling out individual directors in a way that could seem uncomfortable or political.
However, it under-serves the reality of how board accountability actually works. Committee structures exist precisely because certain directors carry deeper responsibility for certain risk domains. A Risk Committee Chair is expected to understand model risk and control frameworks more deeply than a Remuneration Committee Chair. An Audit Committee Chair is expected to understand the auditability of controls more deeply than a director without that remit.
When AI literacy is treated as a single uniform topic, this natural differentiation disappears. The result is that the directors who will actually be asked hard questions by regulators, auditors or the full board are left with the same general-awareness briefing as everyone else — not the assurance-level understanding their role requires.
Where a differentiated literacy framework helps
A more effective approach maps depth of AI literacy to the accountability each board role actually carries.
In practice, this typically means:
- The Chair needs deep literacy to set the tone for board discussion, ensure appropriate time and expertise is allocated to AI oversight, and represent the board's understanding externally.
- The Risk Committee Chair needs deep literacy to interpret model risk reporting, challenge bias testing and monitoring approaches, and provide credible assurance to the full board.
- The Audit Committee Chair needs deep literacy to confirm that AI-related controls are auditable and that assurance processes are fit for purpose.
- Executives with Senior Managers Regime accountability for AI-affected business areas need deep literacy proportionate to their personal regulatory accountability.
- Other non-executive directors need strong working literacy — enough to follow assurance reporting, ask informed questions, and recognise when an issue needs to be escalated or investigated further.
This is not about creating a hierarchy of importance among directors. It is about recognising that deep literacy and working literacy serve different governance functions, and both are necessary for the board to function as a whole.
Structured, role-specific learning — rather than a single generic AI training session — allows this differentiation to be built deliberately rather than left to chance. Directors with deeper accountability can be given more substantial, ongoing engagement with real AI use cases inside the firm, while the wider board maintains a solid, current working understanding.
Building and maintaining board-level AI literacy
A differentiated framework only works if it is treated as an ongoing governance activity rather than a one-off training exercise.
Three practical considerations matter most.
First, literacy requirements should be reviewed periodically, not set once and forgotten. As the firm's use of AI expands — for example, moving from customer service automation into underwriting or credit decisions — the depth of literacy required by accountable directors is likely to increase accordingly.
Second, deep literacy should not be confused with technical expertise. A Risk Committee Chair does not need to be able to build or audit a model personally. They need the ability to ask the right challenging questions, interpret assurance reporting critically, and recognise when management's explanation does not hold up to scrutiny.
Third, board development activity should be documented. Given the direction of regulatory expectation — including the accountability signalled by the AI Compact — boards will increasingly need to evidence that AI literacy has been deliberately built and maintained, not assumed.
Getting this right protects against the two most common failure modes: under-preparing the directors who will be held accountable, and over-investing training time in generic content that does not reflect how board accountability actually works.
Example
A London-based specialty insurer introduces an AI-assisted underwriting triage tool.
The Risk Committee Chair is required to present assurance to the full board on model governance, bias testing and escalation procedures, drawing on detailed reporting from the underwriting and model risk teams.
The Audit Committee Chair, separately, must confirm that the controls around the tool are auditable and that assurance evidence will satisfy both internal audit and external regulators.
Other non-executive directors are not expected to interpret the underlying model validation reports themselves. Instead, they need enough understanding to question the pace of rollout, the customer impact of triage decisions, and whether the assurance presented by the two committee chairs is proportionate and credible.
By structuring literacy this way, the board avoids a governance gap. The two committee chairs hold deep, assurance-level AI literacy, while the wider board holds working literacy sufficient to challenge management appropriately — satisfying both fiduciary duty and regulatory expectations.
FAQs
-
Does every board member need to understand how AI models work technically?
No. Deep AI literacy at board level is about governance and challenge capability, not technical or data science expertise. Directors with elevated accountability need to be able to interpret assurance reporting, ask the right challenging questions and recognise weak explanations — not build or validate models themselves.
-
How often should board AI literacy be reassessed?
It should track the pace of AI adoption within the firm and the pace of regulatory development, rather than following a fixed cycle. In practice, most boards will need to reassess literacy requirements at least annually, and sooner if the firm expands AI use into a new area of the business.
-
Is the CEO or CFO expected to have deep AI literacy as board members?
Where the CEO, CFO or other executive directors hold formal regulatory accountability — for example under the Senior Managers Regime — for business areas materially affected by AI, they typically require deep literacy alongside the Chair and the relevant committee chairs.
Get fit for AI
Book a conversation to explore how you can level up your people with the right AI skills.