Adjusting the instruments — strategy, appetite, and the policy cascade

Lesson 3 of 4 in Board-Level AI Governance: ISO/IEC 38507 and Organizational Accountability.

38507 does not ask boards to acquire new powers. It asks them to re-tune four instruments they already hold: strategy, risk appetite, policy, and culture and competence.

Strategy first, because AI is a business-model question before it is a risk question. When a company bets its operations on a model’s predictions, model risk is enterprise risk. Zillow Offers is the cleanest case on record: Zillow’s home-buying arm relied on its Zestimate-adjacent pricing models to purchase houses at scale; in 2021 the models systematically overpaid in a shifting market, and the company wound down the entire division — a write-down in the hundreds of millions and a quarter of the workforce cut. That was not an engineering incident that escalated; it was a board-altitude strategy decision (bet the business on algorithmic pricing) whose risk assumptions nobody at the top had stress-tested. Evaluate, in the EDM sense, never happened with teeth.

Risk appetite second. Most boards inherit appetite statements written for financial and operational risk — silent on the questions AI forces: How much error, affecting whom, in exchange for what? Which decisions may never be fully automated? What harm to non-customers (applicants, data subjects, the public) is acceptable — usually the honest answer must be approaching none, and saying so out loud changes design decisions downstream. An AI-aware appetite statement is the single highest-leverage artifact a board can produce, because every management decision beneath it inherits its boundaries.

The policy cascade — how one appetite sentence becomes a thousand controls

  1. Board: risk appetite & value commitments — Direct — the source document

    Example sentence: We will not deploy AI that makes fully automated adverse decisions about individuals; human review with authority to reverse is mandatory in every such use. One sentence, board-approved. TR 24368’s ethics themes enter governance here — as explicit value commitments, not posters.

  2. AI policy — 42001 clause 5.2 — approved by top management

    The appetite translated into organisational rules: scope of permitted AI use, prohibited uses, mandatory gates (impact assessment before deployment), role accountabilities, commitment to applicable requirements and continual improvement.

  3. AI objectives — 42001 clause 6.2, seeded from Annex C

    Measurable commitments the policy implies: fairness metrics with thresholds, transparency deliverables, robustness targets — each with an owner, a method, and a review date.

  4. Controls & procedures — Annex A controls, operational procedures

    The working layer: lifecycle controls (A.6), data management (A.7), supplier clauses (A.10), oversight workflows. This is where the board’s sentence becomes a reviewer’s Tuesday-morning checklist.

Delegation to AI is a governance decision. Among 38507’s most practical contributions is treating "should this decision be made by an AI at all, and with what human role?" as a question the governing body frames — through the appetite and policy — rather than one engineers answer per project. Walk the logic the way a well-directed organisation would:

Can this decision be delegated to an AI system?

Interactive decision tree — outcomes:

  • Delegate with standard monitoring

    Low-stakes, reversible, observable: automation is appropriate. Management owns monitoring per clause 9.1; the board sees it only in aggregate.

  • Delegate under continuing conditions

    Permitted — with the envelope the board directed: effective human review, performance floors, re-assessment triggers, and escalation thresholds wired into the AIMS. The approval is conditional and continuing, never one-time.

  • Do not deploy as designed

    If oversight can only ever be nominal, the design contradicts the appetite. Either re-scope the system (decision support instead of decision making) or change the decision volume so review is real. Deploying anyway and calling it human-in-the-loop is the rubber-stamp trap with a paper trail.

  • Reserved for human decision

    The board has drawn this line; the project must respect it. AI may still inform the decision (analytics, drafting) — it may not make it.

  • Escalate — governance gap found

    A silent appetite statement is itself the finding. The decision goes up, and the appetite statement gets amended — this is exactly the Evaluate–Direct loop doing its job.

Competence and culture close the loop. A board cannot evaluate what it cannot understand: 38507 expects governing bodies to secure sufficient AI literacy at the top — through recruitment, education, or standing advisors — to ask the second question, not just the first. And culture is what happens to the cascade when nobody is watching: if engineers who raise concerns get sidelined, no reporting channel (control A.3’s concern-reporting mechanism) will surface the truth. The board sets that tone with what it rewards, what it asks about, and what it does the first time bad news arrives.

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.