34 questions8 themesMapped to ISO/IEC 42001

The Director's AI Question Bank

A director's job is not to build the AI management system — it is to test whether one exists and works. This is the instrument for that: 34 questions to put to management, each mapped to the ISO/IEC 42001 clause it interrogates, the director duty it serves, and the red flag to watch for.

Included with every engagement · available as a licensed standalone for boards and networks.
How to use it

Ask for evidence, owners, and dates — not reassurance

Ask these at the risk or audit committee. A confident, evidenced answer is assurance; a vague one is a finding. The skill is asking at the right altitude — governance, not implementation — and refusing to accept “it's fine” in place of an artefact. Each question below is deliberately phrased to demand something concrete.

Below the eight themes is the short set to reach for when you only have five minutes.

Weak vs strong
Weak: “Is our AI safe?” invites a yes.

Strong: “Show me the impact assessment for our highest-risk AI system, who signed it, and what it changed.”
The bank · 8 themes

A · Do we know where our AI is?

Clause 4 — Context
  1. What is our complete inventory of AI systems — built, bought, and embedded in vendor products?
  2. Where is "shadow AI" (unsanctioned tools staff use) most likely, and how would we know?
  3. Which AI systems are in scope of our AI management system, and what did we deliberately leave out?
  4. Which of our AI uses would a regulator or the public consider high-risk?

Red flag: no current inventory, or "we don't use much AI" with no evidence.

B · Who owns this, and does leadership stand behind it?

Clause 5 · A.2, A.3
  1. Who is the accountable executive for AI governance — a named person, not a committee?
  2. Do we have a board-approved AI policy, and when was it last reviewed?
  3. How do AI responsibilities map across the three lines (business, risk, internal audit)?
  4. What is our stated AI risk appetite, and how does management operate against it?

Red flag: diffuse accountability, an aspirational policy, or an undefined risk appetite.

C · How do we find and treat AI risk?

Clause 6 · A.4, A.5
  1. What is our process for AI risk assessment, and how often does it run?
  2. Do we perform AI system impact assessments on affected people and society — before deployment, not after an incident?
  3. Show me the risk treatment plan for our highest-risk AI system. What did we accept, and who signed off?
  4. How do we assess bias, fairness, and potential for discriminatory outcomes?
  5. What resources (data, compute, skills, tooling) are documented as required — and are they adequate?

Red flag: impact assessments absent, retrospective, or only done for systems that already failed.

D · Are the controls real, across the lifecycle?

Clause 8 · A.6, A.7
  1. Can we see the Statement of Applicability — which Annex A controls we adopted and why we excluded any?
  2. How is data quality, provenance, and appropriate use managed for our AI systems?
  3. What controls govern the AI lifecycle — design, verification, validation, deployment, and retirement?
  4. How do we manage models that drift or degrade after go-live?
  5. What is our position on generative AI and third-party foundation models specifically?

Red flag: controls exist on paper (the SoA) but management can't evidence them operating.

E · Can we see how the AI is performing?

Clause 9 — Evaluation
  1. What does our AI governance dashboard show the board, and how often?
  2. What are our leading and lagging indicators for AI risk (incidents, drift, coverage of assessments)?
  3. When did internal audit last review the AI management system, and what did it find?
  4. What surfaced in the last management review of AI, and what changed as a result?

Red flag: no board-level reporting cadence, or reporting that is all green with no near-misses.

F · Third parties and the supply chain

A.10 — Third parties
  1. Which vendors embed AI in the products we rely on, and what have we asked them to attest?
  2. How are AI responsibilities allocated in our supplier and customer contracts?
  3. If a vendor's AI causes us a harm or breach, what is our recourse and who is liable?

Red flag: vendor AI is a blind spot; contracts predate the organisation's AI exposure.

G · When it goes wrong

Clause 10 · A.8
  1. What is our AI incident response plan, and who invokes it?
  2. How would we detect, disclose, and remediate an AI-caused harm — and on what timeline?
  3. How do we inform affected users and regulators, and who decides what "material" means?
  4. What have we learned from AI near-misses, and how did that change controls?
  5. Have we ever rehearsed an AI incident at board or executive level?

Red flag: no incident plan, no disclosure trigger, and no rehearsal.

H · Regulation and director exposure

Duties: s180–181
  1. Where does the EU AI Act reach our organisation, and are we ready for the obligations that apply?
  2. How do APRA CPS 230 / CPS 234 (or our sector's equivalent) intersect with our AI use?
  3. What is our path to independent assurance or ISO/IEC 42001 certification, and is it resourced?
  4. If challenged, could we demonstrate that this board exercised care and diligence over AI?

Red flag: "we'll deal with regulation when it lands" — the defence of ignorance is closing.

If you only have five minutes

The five to ask

  1. What is our complete inventory of AI systems, including vendor-embedded AI?
  2. Who is the single accountable executive for AI governance?
  3. Show me an AI system impact assessment for our highest-risk use.
  4. What does the board see about AI performance, and how often?
  5. If challenged, could we prove this board exercised care and diligence over AI?

Want the full bank for your board?

The complete question bank is included with every engagement, and can be licensed as a standalone board asset or for a director network. Ask about licensing and co-branding.

Enquire about licensing →
Where it's taught

Educational aid on ISO/IEC 42001:2023 — not legal advice and not a substitute for the official standard.