Attestation Is Not Oversight
What Deloitte's AI governance roadmap gets right, and what its questions cannot ask.
Deloitte’s Center for Board Effectiveness has published Strategic Governance of AI: A Roadmap for the Future, and copies are now crossing NED desks. The document applies Deloitte’s general governance framework to AI across six areas: strategy, risk, governance structure, performance, talent, and culture. Each section sets out the board’s role, the activities to oversee, and a bank of questions for directors to put to management. It is one of the better entries in a crowded genre, which is exactly why it deserves a proper review. Its central weakness is not a Deloitte weakness. It is the weakness of the genre, and directors who understand it will read every framework that lands on their desk differently.
The roadmap’s most useful pages are two illustrative committee structures: one for organisations with limited AI integration, where the full board holds the strategy, and standing committees absorb the pieces, and one for organisations further along, where a dedicated risk or technology committee takes primary ownership. Making that structural choice contingent on AI maturity is a genuine decision aid, and the allocation tables spelling out what the audit and compensation committees would each own give boards something concrete to argue with. The document also devotes a full section to the board’s own governance, covering skills, refreshment, education, and self-assessment, the territory addressed by my own Principles for Responsible AI Use by Directors, and it prompts directors to weigh the risks of not deploying AI alongside the risks of deploying it. These are real contributions, and boards will get value from them.
For me, the problem sits in the question banks. Read them closely, and a pattern emerges: does management have a strategy for AI adoption; does management have a process to identify and assess risks; has management properly defined the organisation’s risk appetite; does management have an inventory of AI use. Almost every question is an existence test, and an existence test can only ever confirm that a thing exists. It cannot tell a board whether the strategy is any good, whether the process would catch the failure that matters, or whether the risk appetite was chosen rather than inherited. A board that works through the roadmap diligently will collect fifteen yeses and a warm sense of thoroughness. What it will have produced is an attestation record. Attestation is not oversight.
The tell is what the questions never ask for. Nowhere in the document is management asked for a number, a threshold, or a trigger. In the two places the roadmap approaches one, it retreats: it asks what metrics and KPIs should be used to measure AI success, and what events should trigger a board update outside the regular cycle, then leaves both as open questions for the reader. The judgements boards most need help with are handed straight back to them. The gap this leaves is measurable. In Grant Thornton’s survey of 950 business leaders this spring, 78% said they lacked strong confidence that their organisation could pass an independent AI governance audit within 90 days. Most of those organisations could answer yes to every existence question in the roadmap. Adequacy is where they would fail, and adequacy is what the question banks never reach.
It is worth being fair about why the genre converges here. Existence questions are safe to publish: they apply to any client in any sector, they require no knowledge of the company, and they commit the author to no judgement that could later look wrong. A question with a threshold in it is a position; a question without one is a prompt. Professional services firms produce prompts for structural reasons, not cynical ones. But the consequence for boards is the same either way, and the correction is straightforward. Treat every question bank as raw material, and rewrite the questions until each one demands a number, a name, or a date.
Four rewrites from the roadmap’s own pages show what that means. “Does management have a strategy for AI adoption and integration?” becomes: which two or three business processes carry most of our AI investment, what cost or margin effect is each committed to deliver, and by which reporting period? “Has management properly defined the organisation’s risk appetite regarding AI initiatives?” becomes: what is the largest loss an AI system could cause tomorrow without breaching a control, and did we choose that number or discover it? “What metrics and KPIs should be used to measure the success of AI initiatives?” becomes: which AI initiatives missed their targets last quarter, and which have we stopped as a result? And “what events will trigger an update to the board outside of regular updates?” becomes a named standard: any system granted write access to payments, customer data, or external communications comes to the committee before deployment, and any incident above a stated materiality threshold comes to it within 48 hours. Each rewrite can only be answered by someone who knows the company’s numbers, which is the entire point.
So keep the roadmap. The committee structures are worth borrowing, the board-governance section is a useful mirror, and the document will structure a good discussion. Just do not mistake completing it for governing. The test to apply, to this framework and to every one that follows it, is simple: if the board’s questions could be answered truthfully by a management team that had never seen the company’s accounts, they are the wrong questions.
If this is the kind of scrutiny you want applied to what lands on board desks, subscribe to AI in the Boardroom. I write for directors, executives, and advisers who need AI governance that changes decisions, controls, and reporting demands rather than producing paperwork, and future posts will keep testing the frameworks and regulations that reach the boardroom against that standard.



