The board of directors of Pinnacle Asset Management is establishing an AI governance framework following guidance from the SEC and FSB on algorithmic risk oversight. Which board-level structure most effectively discharges the board's oversight obligation for AI risk in an investment management firm?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Folding AI into the existing tech committee is like adding a jet engine to a bicycle — the oversight structure isn't built for the risk. AI in investment management touches model risk, fiduciary duty, ethics, and regulatory compliance simultaneously. Those dimensions need cross-functional board-level attention, not a subcommittee that's already stretched across IT infrastructure. A dedicated AI committee with an independent expert is the governance architecture regulators expect to see.
Full explanation below image
Full Explanation
Board-level AI governance in investment management requires a purpose-built oversight structure because AI risk has characteristics that distinguish it from conventional technology risk. AI models introduce model risk (distributional shift, overfitting, hallucination), ethical risk (bias, fairness, explainability), fiduciary risk (human judgment displacement), and systemic risk (correlated AI strategies amplifying market stress). A technology committee focused on cybersecurity and IT infrastructure is neither structured nor staffed to evaluate these dimensions rigorously.
A dedicated AI Risk and Ethics Committee (option B) addresses this through: cross-functional membership that brings investment, risk, legal, and independent AI expertise to the same table; a specific mandate covering material AI deployments (preventing ad hoc AI proliferation below the governance radar); and a model risk incident review process that creates board-level visibility into AI failures before they become regulatory events.
Option A — absorbing AI into the technology committee — creates coverage gaps. Most technology committees lack investment domain expertise and ethics frameworks needed to evaluate AI risk holistically. The SEC's 2023 AI guidance and the FSB's reports on AI in financial services both expect boards to demonstrate specific AI risk competency, not generic technology risk oversight.
Option C — delegating to the CAIO with annual board review — creates an accountability gap. Annual review cycles are insufficient given the pace of AI deployment and model drift. The board cannot discharge its oversight duty if it examines AI risk only once per year with no standing committee accountable between reviews.
Option D — distributing audit reports to the full board — lacks governance structure. Distributing reports without a designated committee to own the response creates diffuse accountability. In a breach scenario, regulators will ask which board member or committee was responsible for reviewing the AI risk report. 'The whole board received it' is not an acceptable answer.