Skip to main content
Can You Govern AI Without an Advisory Board?Trustworthy AI Principles
6 min readFor AI Governance Leaders

Can You Govern AI Without an Advisory Board?

Over the past six months, I've been asked the same question by governance teams: "We're building our AI oversight structure. Should we form an advisory board, or is that just governance theater?"

This question became more pressing in September 2023 when the UK's Centre for Data Ethics and Innovation (CDEI) let its Advisory Board's term end. The CDEI had relied on this group of external experts to guide projects like the Algorithmic Transparency Recording Standard and the UK-US Privacy-Enhancing Technologies prize challenge. Now they're moving to what they call "an agile way" of seeking expert input.

This shift highlights a challenge every governance leader faces: How do you maintain rigorous external oversight without creating a structure so formal it can't keep pace with your deployment speed?

Here are the questions I'm hearing most often, with practical answers drawn from what works (and what doesn't) in the field.

Do We Actually Need External Experts, or Can Internal Teams Handle Governance?

You need both, but they serve different functions.

Your internal teams, model risk, legal, compliance, product security, understand your systems, data flows, and business constraints. They can assess whether a model meets SR 11-7 requirements or whether your Technical Documentation satisfies Annex IV of the EU AI Act.

External experts bring what your internal teams can't: perspective on emerging risks you haven't encountered yet, credibility with regulators and auditors, and the ability to ask uncomfortable questions without career consequences.

The CDEI's Professor Neil Lawrence put it clearly: "Diverse expertise from academia, industry, government, and third sector needs to be convened to ensure that the challenges are understood from all perspectives." Your internal compliance team won't tell you that your fairness metrics are solving the wrong problem. An external researcher might.

The key isn't whether you formalize this as an "advisory board." It's whether you've built systematic channels for external challenge. That might mean:

How Do We Keep Expert Input Relevant When AI Changes Every Quarter?

This is where the CDEI's shift from a standing board to "agile" engagement makes sense, if you execute it correctly.

A standing advisory board with annual terms works well for stable governance domains. AI governance in 2024 isn't stable. The General-Purpose AI Code of Practice under the EU AI Act didn't exist when the CDEI's board started its term. Your oversight structure can't wait 12 months for formal guidance on systemic risk obligations.

What works better: modular expert engagement tied to specific governance functions.

When you're defining your AI RMF Profile for a new high-risk system, bring in experts who've implemented NIST AI RMF 1.0 in similar contexts. When you're building Post-Market Monitoring for a General-Purpose AI Model, consult with practitioners who've operationalized continuous evaluation at scale. When you're designing your Impact Assessment process under ISO/IEC 42005, get input from teams who've done it badly and learned what to fix.

The risk with "agile" engagement is that it becomes ad hoc, you only seek external input when you're already in trouble. Prevent that by scheduling expert reviews at lifecycle gates: before model provisioning, during validation evidence review, and at your annual AI Management System audit.

What Happens to Public Trust When There's No Visible Oversight Body?

This question matters more than most governance leaders realize.

The CDEI's Professor Marion Oswald noted that "trust cannot be taken for granted" and highlighted the Algorithmic Transparency Recording Standard as a tool for building it. Transparency standards only work if someone credible is validating that you're using them correctly.

Your stakeholders, regulators, customers, civil society groups, don't trust your internal governance team to police itself, no matter how rigorous your controls are. They trust external verification.

If you dissolve a formal advisory structure, you need to replace its trust function with something equally visible. Options include:

  • Publishing external audit reports from your AI assurance reviews
  • Documenting Stakeholder Engagement in your System Cards
  • Submitting to third-party certification against ISO/IEC 42001:2023
  • Participating in industry-wide responsible disclosure programs

The UK government says the CDEI will "continue to seek expert views." That's fine, but unless those views are documented and their influence is visible, the public has no way to verify that external challenge is actually happening.

Can We Use Our Existing Risk Committee Instead of Creating a Separate AI Board?

Yes, if your existing committee has the right expertise and meets frequently enough.

Most enterprise risk committees meet quarterly and focus on financial, operational, and compliance risks they already understand. AI governance requires domain-specific knowledge: how Bias Mitigation works in practice, what Reproducibility means for model validation, how to assess Vendor Model Risk when your foundation model provider won't share training data.

If your risk committee includes members who can evaluate those questions, and if they're reviewing AI systems at every lifecycle stage, not just at annual planning, then adding a separate AI advisory board is redundant.

If your committee doesn't have that expertise, you have two options: add AI-literate members to the existing committee, or create a separate technical advisory group that reports into it. The second option works better when you're deploying models faster than your quarterly committee cycle.

Where Do We Find Experts Who Understand Both the Tech and the Governance?

This is harder than it should be, because the skillset is rare.

You need people who can read a Model Card, understand what Aggregation Bias looks like in your training data, and also map your controls to Annex A of ISO/IEC 42001. Most ML researchers don't know the standards. Most compliance professionals don't know the technical risks.

Start with practitioners who've implemented AI Management Systems in regulated industries: financial services teams who've extended SR 11-7 to LLMs, healthcare organizations that have operationalized algorithmic transparency, public sector teams that have run AI System Impact Assessments.

Then look for academics who consult outside their research, they understand emerging risks before they hit production systems. The CDEI's board included Professor Mimi Zou, whose work spans AI ethics and labor law, exactly the kind of cross-domain expertise that catches risks your model risk team won't see.

Don't overlook civil society organizations. They won't help you optimize your validation process, but they'll tell you whether your Instructions for Use actually make sense to affected communities.

How Do We Prove to Auditors That We're Getting Sufficient External Input?

Document everything, and make the influence visible.

Your ISO/IEC 42001 auditor or your banking regulator doesn't care whether you call your external experts an "advisory board" or "subject matter consultants." They care whether you can demonstrate that:

  • External challenge happened at decision points (not after the fact)
  • Expert recommendations were documented
  • You either implemented the recommendations or documented why you didn't
  • The process repeats on a defined schedule

Keep records of:

  • Expert review sessions tied to specific models or policy decisions
  • Written recommendations with your response
  • Changes to your governance framework that resulted from external input
  • Evidence that leadership considered expert advice before approving high-risk deployments

The CDEI's shift away from a formal board doesn't mean less oversight, it means oversight needs to be documented differently. If you're moving to a more flexible model, your evidence trail needs to be more rigorous, not less.

What's the Minimum Viable Structure for External AI Oversight?

For most organizations: quarterly technical reviews plus annual governance audits.

Quarterly: Bring in 2-3 external experts to review your highest-risk deployments from the past 90 days. They should evaluate whether your validation evidence is sufficient, whether your Risk Tiering makes sense, and whether your Post-Market Surveillance is catching the right signals. Document their findings and your response.

Annually: Have an independent party audit your AI Management System against ISO/IEC 42001 or your AI RMF Profile. This audit should include interviews with external stakeholders and a review of whether your governance framework is actually being followed.

If you're deploying General-Purpose AI Models or systems that trigger the EU AI Act's high-risk categories, add pre-deployment reviews by domain experts before you provision any new model.

The CDEI built credibility through projects like the Algorithmic Transparency Recording Standard and the Fairness Innovation Challenge. Your organization builds credibility the same way: by showing that external experts reviewed your work and that you acted on what they found.

You don't need a formal advisory board. You do need a system that ensures external challenge happens before you deploy, not after something breaks.

You Might Also Like