Faculty of law blogs / UNIVERSITY OF OXFORD

Board Oversight of AI: Why Process Controls May Not Be Enough

Posted:

Time to read:

3 Minutes

Author(s):

Eva M Erpenbach
Founder and Scientific Director of the Erpenbach Institute. Her work focuses on governance, accountability and decision structures in human-AI systems

Companies deploying artificial intelligence have built a recognisable governance apparatus around it. There are usage policies, approval workflows, model inventories, audit trails, risk management functions and requirements for human oversight. Regulatory expectations, from the EU Artificial Intelligence Act to sectoral supervisory guidance, reinforce this architecture and give boards a clearer checklist for responsible deployment. This is necessary work. It is not, on its own, sufficient.

The reason is that procedural continuity and operational continuity can come apart. A system reviewed for a defined purpose may keep its approval, documentation and place on the risk register while its practical role quietly changes. The change can come from a model update pushed by a provider, a new data source, a retention feature, an integration with other tools, a change of vendor or simply the way the system becomes embedded in a workflow and relied upon downstream. From the governance process's point of view, nothing may appear to have been added. In practice, the system may no longer be doing the same thing.

The consequences are concrete. A tool introduced as decision support can become, in practice, the decision, because the people around it defer to its output and the human in the loop signs off as a formality. Elsewhere, a model adopted to summarise documents is repurposed to rank or screen them, a different act with different legal exposure. And a provider's routine update can alter how the system behaves without triggering re-review, because the formal process still points to the original authorisation. In each case, the paperwork may be in order while the activity being governed has moved.

This is why board oversight has to reach beyond the moment of approval. The useful question is not only whether a system was authorised, but whether it is still operating in the same role, within the same risk profile and in the same decisional context that was reviewed. That question cannot be answered once. It has to be asked again whenever the conditions that made the original approval meaningful may have changed, which, with these systems, may happen more often than traditional governance cycles assume.

It also reframes what transparency should deliver. The current transparency conversation tends to concentrate on inputs and provenance: the model name, the provider, the training data, the existence of an audit report and the technical safeguards in place. Those matter. But they describe the system largely as procured or reviewed, not necessarily as operating. Transparency that serves oversight has to locate where the decision-relevant effect now arises, so that a board can see which decisions the system is actually shaping and whether that has changed since it was last examined.

The accountability point follows. Responsibility for a decision is not discharged by delegating it to a system, and it is not discharged by documenting that delegation cleanly. A clean process is evidence of diligence, not a substitute for it. If the role under oversight has changed without being recognised, accountability can survive on paper while losing much of its content, because those answerable for the decision may be answering for a system that no longer performs the role they reviewed. A recent contribution on this blog on AI and central banks made a related point in the public-law setting, stressing that institutions remain responsible for their decisions even when their AI tools err. The same logic applies to corporate boards and their oversight duties.

None of this argues against procedural controls. Approval workflows, audit trails and human oversight remain the backbone of responsible AI use, and firms that lack them are not well placed to address this additional problem. The argument is that process controls need to be paired with functional continuity review: periodic confirmation that the system being monitored is still shaping the same decision, carrying the same risk and answerable to the same duty as the one that was signed off. A process control asks whether the steps were followed. Functional continuity review asks whether they were followed in respect of the right thing.

For boards, this suggests a few practical habits. Treat material model updates, provider changes and new workflow integrations as events that may reopen approval, not merely as maintenance. Ask, at review, not only whether policies were observed, but what the system is now doing and who is now relying on it. Require transparency reporting to identify the decisions the system currently influences, rather than only its technical specification. And record, each time, whether the role under oversight is still the one that was approved.

AI governance has invested heavily, and rightly, in making the process visible. The next step is making sure the process is still pointed at the decision it was built to protect.

Eva M. Erpenbach is Founder and Scientific Director of the Erpenbach Institute. Her work focuses on governance, accountability and decision structures in human-AI systems.