EAAPLEnterprise AI Architecture Pattern Library

Board Governance

Board AI Governance Check

10 questions that reveal your organisation's actual AI governance posture. Each question maps to a specific regulatory obligation. Takes 2 minutes. Share the result with your board.

Q01

Does your organisation maintain an inventory of all AI systems in production, including who owns them and what decisions they make?

APRA CPS230 §15, ISO 42001 §8.4
Q02

For AI systems that affect customer outcomes — credit decisions, claims, welfare assessments — can you reconstruct exactly what the system decided and why, for any individual, within 24 hours?

Privacy Act APP 3 & APP 5, APRA CPS230 §15(d)
Q03

Has your board been briefed on your three highest-risk AI systems in the past 12 months — including their failure modes and the regulatory exposure each represents?

APRA CPS230 §22 (board accountability), ISO 42001 §5.1
Q04

Do you have a documented process for detecting when an AI model's outputs have degraded or shifted — with defined thresholds that automatically trigger human review before the degradation reaches the customer?

APRA CPS230 §15, ISO 42001 §9.1
Q05

When your AI systems make high-stakes decisions — credit approval, fraud flags, claims processing, welfare payments — is there a human checkpoint before the decision takes effect on the customer?

EU AI Act Article 14, APRA CPS230 §23
Q06

Has your organisation ever tested what happens when an AI system receives adversarial or manipulated inputs — inputs deliberately designed to produce incorrect or harmful outputs?

ISO 42001 §6.1, OWASP LLM Top 10
Q07

Do you have a documented AI incident response plan — tested within the last 12 months — with defined escalation paths and notification timelines to the board and regulators?

APRA CPS230 §52, Privacy Act breach notification obligations
Q08

Can you demonstrate to APRA or the OAIC that AI systems procured from third-party vendors meet your organisation's risk classification, governance, and data handling requirements?

APRA CPS230 §25 (third-party risk), ISO 42001 §8.4
Q09

Does your organisation have a defined approval process for new AI use cases — including risk classification, ethics review, and documented sign-off authority before deployment?

ISO 42001 §8.2, APRA CPS230 §15(b)
Q10

In the event of a material AI failure today — incorrect outputs at scale — could your technical team roll back to a previously validated model version within 4 hours without data loss?

APRA CPS230 operational resilience, ISO 42001 §10.2