top of page
James F. Kenefick Website Icon

JAMES F.

   KENEFICK

The 2026 AI Governance and Control Checklist for Boards

  • 15 minutes ago
  • 5 min read

Every board I sit with these days eventually asks a version of the same question: are we actually in control of the AI systems we have approved? The instinct behind the question is sound. What is missing, in most cases, is a checklist that turns that instinct into evidence.

AI has moved from a technology decision to an operating model decision, and the boards that treat it otherwise are the ones discovering gaps only after an incident forces the issue. The data on where enterprises stand in 2026 is sobering. Only about 39 percent of Fortune 100 boards have explicit AI oversight mechanisms such as a board committee, a director with AI expertise, or a dedicated governance sub board, according to McKinsey's research on how boards can evolve their AI governance. Meanwhile, BetterWorld Technology's risk assessment practice sees the same pattern across mid market clients that boards do: governance conversations happen, but the control evidence behind them does not exist yet.


Executives reviewing AI governance and risk data during a boardroom meeting.

Why It Matters


The gap between AI adoption and AI governance is now the central operating risk for most organizations, not a side issue for the technology committee. Stanford HAI's 2026 AI Index found that the share of organizations with no responsible AI policy fell from 24 percent in 2024 to 11 percent in 2025, while AI specific governance roles grew 17 percent year over year, which tells us the paperwork is catching up. What has not caught up is enforcement. Even where policies exist, McKinsey's most recent State of AI survey found that only 28 percent of organizations put the CEO directly in charge of AI governance oversight and only 17 percent give that role to the board, which means accountability is still diffuse at the exact moment regulators are removing the ambiguity from that question.


Regulation is the forcing function boards can no longer defer. Organizations using AI in employment, credit, law enforcement, or critical infrastructure now face mandatory human oversight and accountability requirements, and under Article 99 of the EU AI Act, fines for the most serious violations can reach 35 million euros or 7 percent of a company's worldwide annual turnover, whichever is higher. That is not a compliance footnote. That is enterprise value exposure, and it belongs on the same board agenda as cyber risk and financial controls, a point Working Excellence's operational governance work reinforces with every client that treats AI oversight as an afterthought rather than a standing discipline.


The Core Framework: Eight Control Areas


A governance and control checklist only works if it forces specific evidence rather than general reassurance. Eight areas belong on every board's checklist for 2026.


Business value. Can the organization show which AI use cases are tied to a measurable business outcome, and which are running without one? BetterWorld Technology's managed IT and security practice treats this as the first filter, because ungoverned AI usually starts as ungoverned spend.


Data readiness. Is the data feeding AI systems classified, access controlled, and quality tested before it reaches a model? Most control failures trace back to this stage, not to the model itself.


Governance structure. Is there a named owner, a documented policy, and a standing review cadence, or does AI oversight live informally with whoever happens to be closest to the deployment? Framework adoption is following the same trajectory Stanford HAI tracks in its 2026 AI Index, with 36 percent of organizations reporting use of ISO IEC 42001 and 33 percent using the NIST AI Risk Management Framework, and NIST's AI Risk Management Framework remains the most widely referenced starting point for building that structure because it treats governance, not compliance, as the foundation the other three functions depend on.


Security. Can the organization isolate an AI system from the broader network, terminate a misbehaving agent, and enforce purpose limitations on what an agent is allowed to touch? Gartner has predicted that by 2030, half of AI agent deployment failures will trace back to insufficient governance platform enforcement of capabilities and multisystem interoperability, which means the controls most organizations report lacking today are the same controls that will define which deployments fail tomorrow.


Accountability. When an AI decision causes harm, is there a documented decision rights chain showing who authorized deployment, who can modify it, and who can shut it down?


Human oversight. Is there a human checkpoint built into every high risk workflow, or does the workflow run end to end without one? BetterWorld Technology's incident response services exist precisely because this checkpoint is the difference between a contained issue and an escalated one.


Adoption. Is AI usage across the organization visible to leadership, or is shadow AI running in functions no governance program has reached yet? BetterWorld Technology's compliance services overview treats visibility as the precondition for every other control on this list, because a system leadership cannot see is a system leadership cannot govern.


Measurement. Is there a defined set of metrics the board reviews on a schedule, or is AI performance reported only when something goes wrong?


The Governance Section: What the Board Must Be Able to Answer


A board does not need to run the AI program day to day, but it does need to be able to answer four questions on demand. What is the board's role in AI oversight, and is that role written down anywhere. What risks has the organization actually assessed, versus assumed. What metrics does the board review, and how often. What oversight mechanism exists to intervene before a deployment causes damage rather than after. McKinsey and the National Association of Corporate Directors put strengthening governance and accountability first on their list of priorities for effective board oversight of AI, ahead of balancing innovation with risk and building real time risk management capabilities.


Without that clarity, questions of responsibility become impossible to answer when something goes wrong. This is where BetterWorld Technology's SOC 2 compliance practice and James F. Kenefick's board oversight commentary converge on the same recommendation: build the evidence trail before you need it, not after a regulator or an insurer asks for it.


The urgency is not theoretical. High risk AI systems under the EU AI Act carry obligations around data governance, technical documentation, human oversight, and post market monitoring, and Article 99's penalty structure makes clear that the fines scale with worldwide turnover, not local revenue, which is why global enterprises are treating this as a board level exposure rather than a regional compliance task.


Executive Actions


Executives should treat this checklist as a working document, not a one time audit. Assign a single named owner for AI governance rather than leaving it distributed across whoever deployed the system first. Classify every AI use case by risk tier before debating its business case, because the classification determines which controls apply. Build the kill switch and isolation capability before the deployment, not after an incident forces the question. Put AI on the board agenda on a fixed schedule, following the pattern of organizations that treat AI governance as a standing decision rather than an annual review. Gartner forecasts that spending on AI governance platforms will reach 492 million dollars in 2026 and surpass 1 billion dollars by 2030, which signals that the market has already priced in how much operational discipline this now requires, and boards that wait to budget for it will be buying urgency at a premium later.


For organizations weighing where to start, BetterWorld Technology's AI security insights and Working Excellence's operational excellence framework both point to the same entry point: start with the control that is missing today, not the framework that looks most complete on paper.


Final Thoughts


The organizations separating themselves in 2026 are not the ones with the most AI ambition. They are the ones whose boards can produce evidence, not just policy, when the question of control comes up. A governance and control checklist is not paperwork if it is built and maintained correctly. It is the operating discipline that lets an organization move faster with AI because every decision behind it is already de risked and audit ready. That is the standard James F. Kenefick's governance advisory work holds every board to, and it is the standard 2026 is now enforcing whether boards are ready for it or not.

Comments


bottom of page