NeuryaBook your Discovery
Corporate governance

From the board seat: 4 questions before AI approval

Rubén Galindo-Ávila10 min read

In short: A board doesn't approve technology: it allocates capital. And allocating capital isn't saying yes or no to what reaches the table: it's deciding which of the available paths creates the most value. To do that, it needs four things: the business map, comparative return, the timeline, and the owner.

If your board has an AI project to approve at the next session, the useful question comes before the technology: did anyone do the homework before the item reached the table?

The risk of approving badly rarely ends in an accounting loss. It ends in twelve small initiatives that consume executive attention for a year without moving a single line of the income statement: none failed, none stood out, and the year was gone.

We saw it clearly in the project that did reach production: a leading bottler in Mexico with critical vacancies open for nearly two months, where each unfilled week meant a stopped line and overtime hours. Before automating anything, the entire recruiting process was redesigned; the agents came in later, on filtering, evaluation and coordination. The cycle went from 50 to 10 days. It wasn't the only project brought to leadership that year. It was the only one that arrived with a baseline, a business owner and a return compared against the other initiatives in the portfolio.

This article answers a single question: what is it the board's job to decide, and not to decide, before authorizing an AI project? Four things. And the first one is understanding where its work ends and the organization's begins.

What the board decides and what it doesn't

The board decides capital allocation and risk; architecture belongs to the organization. A technology director can explain how an agent works, and that explanation rarely changes an investment decision. The board faces a different question: what bet is being made with the company's money, and how reversible is it.

Confusing the two roles is the most common way to lose an entire session. Vendors, models and implementation timelines get debated when what needs to be decided is where to place the capital and how much risk to accept in exchange.

What a CEO needs to know about artificial intelligence fits in three questions: which business process moves the number, who is accountable for it, and what happens if the bet doesn't pay off. That is the competence that belongs to the board, and the one no external advisor can exercise in its place.

The four things that have to be on the table

The business map, comparative return, the timeline, and the owner. With those four you can justify an AI investment before the board without appealing to the promise of the technology. Without them, the session becomes a defense of enthusiasm against enthusiasm.

  • The business map: where the company is winning and losing today, by line, by customer, by process. And where the initiative lands within that map. Without this, priorities are set by who defended their project best, not by where the value is.
  • Comparative return: not how much this initiative returns, but how much it returns compared with the one left out.
  • The timeline: when we will know: day 2 or day 30.
  • The owner: who is accountable for the business result, by name.

The business map is the one most often skipped, and the one that orders the other three. Its question is where the initiative lands, and it accepts three answers of very different weight. First: whether it touches the core business, meaning what the company does to make money, or a support process that only accompanies it. Second: whether it changes the business model, the way the company charges and competes, or only accelerates the one already in place. Third: whether it improves the value proposition, whether the customer receives something different at the end, or exactly the same thing a bit sooner.

The order matters because it changes the decision. An initiative that improves a peripheral process may bring a good return and still not deserve the session. One that moves the core business or the value proposition deserves it even if the number takes longer to appear, because what it's moving is the company's position in its market.

With the four on the table, the session stops being a defense of projects and becomes an allocation of capital. Same board meeting, different conversation.

Comparative return: what this initiative is measured against

Comparative return measures each initiative against the one left out of the portfolio. Almost no board compares. It approves what arrives well-prepared and dismisses what wasn't proposed, not what would have paid less. It's a silent bias: the project wins not because it's the best use of available capital, but because it was the only one that showed up with numbers.

Inertia has its own literature, and it isn't the literature of a character flaw. Lovallo, Brown, Teece and Bardolet treated it in the *Strategic Management Journal* as an organizational capability: reallocating resources across units. It's built deliberately and doesn't appear on its own when the session goes well. A board that reallocates capital each year without comparing isn't taking a different decision each time: it's repeating last year's with new names.

What does survive a comparison is easy to recognize. At a financial institution, KYC onboarding dropped 65% in time while maintaining compliance: baseline captured before starting, an owner by name, and a number leadership could verify without depending on how well whoever proposed it had presented it. That is the standard the rest of the portfolio is measured against.

What used to be stopped for failing a minimum (an initiative without a baseline, without a business owner, or promising a result without changing any process) no longer needs to be stopped automatically. It simply loses the comparison: it has nothing with which to compete against the other initiatives in the portfolio. The filter still exists, but stops being a gatekeeper at the door. It becomes a rule of the game inside the room.

Data, control and traceability: the non-negotiable minimum

Who sees what, what gets logged, and where the data lives. The governance of artificial intelligence is not a technical chapter delegated to systems. It's part of the same approval file as the business map and comparative return, and more and more boards treat it that way: the 2025 National Association of Corporate Directors survey found that more than 62% of directors already reserve agenda time to discuss AI with the full board, not only in the audit or risk committee.

Before authorizing, the board needs three answers, each one in a single line: who can see what information within the process, what action of the agent is logged and who can audit it, and in what jurisdiction the data it processes lives. The risks of artificial intelligence in companies almost never appear in the model: they appear in the process around it, when no one defined the point where a human confirms before the agent acts.

The board doesn't need to understand the system's architecture. It needs to demand those three answers before signing, and someone with a name to account for them.

What a healthy portfolio looks like at 12 months

Enough initiatives, neither few nor many, approved phase by phase, each with its own business case, and a rationale that explains why those and not others. An AI committee, when it exists formally, or the board itself when it doesn't, has a function that summarizes easily: sustaining that rationale from beginning to end, session after session.

Enough means the ones the company can sustain at the same time without running out of people, without running out of vendor and without running out of executive attention. That number isn't set by an innovation target: it's set by the year's real execution capacity.

And that portfolio spans more than technology: it's a business portfolio with five fronts that get approved together or don't get approved: the technology, the people who will work the new process, the vendors with whom it's executed, the processes and procedures that need to be redesigned before automating anything, and the governance that defines who is accountable for what. An initiative that only brings the first front isn't ready for the table: it's asking permission to buy technology.

This isn't a quirk of ours. The international standard that exists today for this, ISO/IEC 42001:2023, is not written as a technology specification: it's written as a *management system*, with roles, responsibilities, risk assessment and continuous improvement. In other words, with half of the file that most initiatives don't bring when they reach the board table.

Put differently: what the board approves is not the AI strategy. It's the company's strategy, tactics and operations for the next twelve months, with artificial intelligence as the protagonist. When it's approved as a separate chapter, it competes against the business budget instead of ordering it.

It's not about approving loose initiatives that sound good on their own. It's about sustaining a portfolio where each approval is explained in relation to the others. The signal that something went wrong shows up somewhere else: the board approved twelve initiatives in a year and, at the closing session review, no one can explain why those were chosen and not others.

Back to the bottler case: the recruiting cycle went from 50 to 10 days (−80%), with critical positions filled 40 days earlier. The number could be defended before leadership because the baseline and cutoff date existed from the first session, not because the project was technically superior to the others proposed that year.

What to do on Monday

  1. Ask that each AI initiative in the portfolio arrive with its baseline written on a single line.
  2. Ask each one to declare where it lands: the core of the business, the value proposition or a support process.
  3. Ask for the five fronts in the same file: technology, people, vendors, processes and governance.
  4. Require the comparative return and the name of the process owner, not the project owner.
  5. Define the data policy before the next approval, not after.

Before the next board session

The question this article opens with isn't answered in the session. It's answered by having the four things ready before it begins.

Our self-diagnostic is 14 questions and five minutes, and you come out with a read on where your company stands in relation to AI: data maturity and business maturity separately, so you can see the imbalance.

If what's missing on your board is that whoever presents the next cases speaks the same language as whoever approves them, the "AI Train" Academy trains those who lead, not those who program.

And if you already have a concrete initiative on the table, an Agentic Discovery delivers the quantified business case before the board has to decide blindly.

To go deeper:

Frequently asked questions

What should a board review before approving an AI project?

Four things: the business map (where the company is winning and losing today, and what part of the business model the initiative moves), the return compared against the other initiatives in the portfolio, the timeline in which it will show signal, and the name of the business owner accountable for the result. Without all four, the board is opining, not deciding.

Who should present AI to the board?

The owner of the process the investment promises to improve, not whoever builds it. If IT presents, a tool is being approved, not a change in how the business makes money. The technical area accompanies; the business is accountable for the result.

What governance risks does an AI agent introduce?

Three, mainly: who can see what information, what decisions the agent takes without supervision and which require human confirmation, and in what jurisdiction the data is processed. None are solved after implementing: they are defined before approving.

How often should progress be reported to the board?

At the cutoff date set before starting, not when the project "is ready to present". A case without a cutoff date tends to stretch out without anyone noticing, because there's no point where someone has to account for the number.