Informd
Please verify you’re human to continue.
AI Risk Appetite: Board Policy Template and Briefing
ICO AI Code | EU AI Act | FCA AI Principles | FRC Expectations | All Sectors
FCA, ICO, and FRC expectations all point to board-level AI governance as a requirement in 2026. Boards that cannot articulate their AI risk appetite — and evidence board-level oversight — face increasing scrutiny from regulators, investors, and auditors.
What This Pack Contains
- AI risk taxonomy — the six AI risk categories every board should understand
- Full board-ready AI risk appetite statement template (ready to adopt)
- AI governance framework — roles, responsibilities, and escalation
- High-risk AI identification guide — how to apply the EU AI Act categorisation
- ICO AI Code readiness checklist
- Implementation roadmap for boards establishing AI governance for the first time
- 10 board questions on AI risk and governance
AI Risk Taxonomy
The pack introduces a six-category AI risk taxonomy for board-level discussion:
- Algorithmic bias and discrimination: AI systems producing outcomes that are systematically unfair to protected groups — particularly acute in credit, insurance, and hiring
- Data quality and governance: AI outputs are only as good as the data they are trained on — poor data quality, biased training data, or data drift creates material outcome risk
- Explainability and accountability: Where AI makes or materially influences decisions affecting individuals, firms must be able to explain those decisions
- Cybersecurity and adversarial attacks: AI systems can be manipulated through adversarial inputs — prompt injection, model poisoning, and data poisoning are emerging threat vectors
- Third-party AI risk: Many firms use AI systems built by third parties (including LLMs) — firms remain responsible for outcomes regardless of the vendor
- Operational and concentration risk: Over-reliance on single AI systems or vendors creates operational resilience risk
High-Risk AI Identification Guide
| Risk Category | Examples | Board Governance Required |
|---|---|---|
| Unacceptable risk (prohibited) | Social scoring by public authorities; real-time biometric surveillance in public spaces | Not applicable — prohibited use |
| High risk | AI in credit scoring, insurance underwriting, CV screening, safety-critical infrastructure | Board approval required; risk assessment; human oversight; audit trail; ongoing monitoring |
| Limited risk | Chatbots and virtual assistants; AI-generated content (where disclosed) | Transparency obligations only |
| Minimal risk | AI-powered spam filters; AI recommendation engines (non-customer-facing) | Standard change management; no specific AI governance requirement |
10 Board Questions on AI Risk and Governance
- Does the board have a formally approved AI risk appetite statement, and when was it last reviewed?
- What AI systems does the firm currently use in customer-facing activities, and have they been assessed for regulatory compliance?
- Are there any AI systems in use that would qualify as high-risk under the EU AI Act or FCA guidance?
- How does the firm identify and manage algorithmic bias risk — and has bias testing been conducted on customer-facing AI?
- Where AI influences decisions affecting individual customers, can those decisions be explained to the customer and to regulators?
- What third-party AI systems does the firm use (including LLMs), and how are those vendors overseen?
- Has the firm conducted a data protection impact assessment for its AI systems that process personal data?
- What is the firm’s approach to AI cybersecurity risk — including prompt injection and adversarial attack scenarios?
- Is AI risk included in the firm’s operational resilience framework and impact tolerance assessments?
- Has the board received a briefing on the ICO AI Code and the steps needed to achieve readiness before it takes effect?
This pack is included in the INFORMD Executive Team plan (£299/month) and available as a standalone download. Contact us for enterprise or multi-firm access.
