AI Risk Appetite Board Policy Template 2026 | INFORMD

Informd

Please verify you’re human to continue.

AI Risk Appetite: Board Policy Template and Briefing
ICO AI Code | EU AI Act | FCA AI Principles | FRC Expectations | All Sectors

← Back to all Board Packs

FCA, ICO, and FRC expectations all point to board-level AI governance as a requirement in 2026. Boards that cannot articulate their AI risk appetite — and evidence board-level oversight — face increasing scrutiny from regulators, investors, and auditors.

What This Pack Contains

  • AI risk taxonomy — the six AI risk categories every board should understand
  • Full board-ready AI risk appetite statement template (ready to adopt)
  • AI governance framework — roles, responsibilities, and escalation
  • High-risk AI identification guide — how to apply the EU AI Act categorisation
  • ICO AI Code readiness checklist
  • Implementation roadmap for boards establishing AI governance for the first time
  • 10 board questions on AI risk and governance

AI Risk Taxonomy

The pack introduces a six-category AI risk taxonomy for board-level discussion:

  • Algorithmic bias and discrimination: AI systems producing outcomes that are systematically unfair to protected groups — particularly acute in credit, insurance, and hiring
  • Data quality and governance: AI outputs are only as good as the data they are trained on — poor data quality, biased training data, or data drift creates material outcome risk
  • Explainability and accountability: Where AI makes or materially influences decisions affecting individuals, firms must be able to explain those decisions
  • Cybersecurity and adversarial attacks: AI systems can be manipulated through adversarial inputs — prompt injection, model poisoning, and data poisoning are emerging threat vectors
  • Third-party AI risk: Many firms use AI systems built by third parties (including LLMs) — firms remain responsible for outcomes regardless of the vendor
  • Operational and concentration risk: Over-reliance on single AI systems or vendors creates operational resilience risk

High-Risk AI Identification Guide

Risk CategoryExamplesBoard Governance Required
Unacceptable risk (prohibited)Social scoring by public authorities; real-time biometric surveillance in public spacesNot applicable — prohibited use
High riskAI in credit scoring, insurance underwriting, CV screening, safety-critical infrastructureBoard approval required; risk assessment; human oversight; audit trail; ongoing monitoring
Limited riskChatbots and virtual assistants; AI-generated content (where disclosed)Transparency obligations only
Minimal riskAI-powered spam filters; AI recommendation engines (non-customer-facing)Standard change management; no specific AI governance requirement

10 Board Questions on AI Risk and Governance

  • Does the board have a formally approved AI risk appetite statement, and when was it last reviewed?
  • What AI systems does the firm currently use in customer-facing activities, and have they been assessed for regulatory compliance?
  • Are there any AI systems in use that would qualify as high-risk under the EU AI Act or FCA guidance?
  • How does the firm identify and manage algorithmic bias risk — and has bias testing been conducted on customer-facing AI?
  • Where AI influences decisions affecting individual customers, can those decisions be explained to the customer and to regulators?
  • What third-party AI systems does the firm use (including LLMs), and how are those vendors overseen?
  • Has the firm conducted a data protection impact assessment for its AI systems that process personal data?
  • What is the firm’s approach to AI cybersecurity risk — including prompt injection and adversarial attack scenarios?
  • Is AI risk included in the firm’s operational resilience framework and impact tolerance assessments?
  • Has the board received a briefing on the ICO AI Code and the steps needed to achieve readiness before it takes effect?

This pack is included in the INFORMD Executive Team plan (£299/month) and available as a standalone download. Contact us for enterprise or multi-firm access.

← Back to all Board Packs