Skip to main content

    Board-Level Briefings

    The Board's Role in AI Vendor Selection

    AI vendor selection decisions often carry strategic risk that warrants board involvement, particularly for enterprise-scale deployments, mission-critical systems, or vendors with access to sensitive data. This guide outlines when boards should engage in vendor decisions, what governance questions to ask, and how to assess vendor risk profiles beyond commercial and technical capabilities. Key considerations include data sovereignty, vendor lock-in risk, regulatory compliance alignment, security postures, and contractual protections-all critical factors in Australian contexts where Privacy Act compliance and data residency matter significantly.

    In short

    Executive Summary

    • Boards don't pick AI vendors. They set the guardrails that prevent management from picking the wrong ones.
    • E.A.R. applies to vendor selection: does this vendor help us eliminate, automate, or reallocate? If the answer is unclear, the evaluation is incomplete.
    • Every AI vendor contract creates a dependency. Boards must demand exit strategies and data portability provisions before approving strategic vendor relationships.
    • The Privacy Act makes vendor data handling a board-level concern. If your AI vendor processes personal information offshore with no contractual protections, you've got a governance failure.

    Detail

    Overview

    Boards should not be selecting AI vendors. That's management's job. But boards should absolutely be setting the framework that governs how vendors are evaluated, contracted, and monitored.

    The E.A.R. lens applies directly. When management presents a vendor recommendation, the board should ask: Does this vendor help us eliminate unnecessary work? Does it automate a process that's currently manual? Does it reallocate human effort to higher-value tasks? If the vendor pitch is about "capability" and "potential" without a clear E.A.R. connection, the business case isn't ready.

    Board involvement should be triggered by thresholds, not by every procurement decision. Define the triggers: annual contract value above $250K, multi-year commitments, vendors accessing customer or employee data, vendors providing business-critical capabilities, and any vendor creating single-point-of-failure risk. Below those thresholds, management operates autonomously within approved governance frameworks.

    For vendors that meet the threshold, boards should require five things from management. First, alternatives analysis: show at least three evaluated options with scoring against defined criteria. No sole-source justifications without exceptional circumstances. Second, data sovereignty assessment: where does data go, who can access it, and how does this comply with the Privacy Act? Third, lock-in analysis: what's the switching cost after 12 months, 24 months, and 36 months? Can data be exported in usable formats? Fourth, exit strategy: if this vendor fails, doubles their price, or gets acquired, what's the plan? Fifth, contractual protections: liability provisions, audit rights, data deletion on termination, and prohibition on using your data for model training.

    The Australian context adds specific requirements. The Privacy Act places data handling obligations on your organisation, not your vendor. If an AI vendor breaches privacy obligations while processing your data, you're liable. APRA-regulated entities face additional vendor risk management requirements. ASX continuous disclosure obligations may be triggered by material AI vendor dependencies or failures.

    Boards should maintain a strategic AI vendor register showing all vendors above the threshold, their risk ratings, contract terms, and dependency assessments. This gets reviewed alongside the Board AI Risk Register on a quarterly cadence.

    Commercial impact

    Why It Matters for Organisations

    AI vendor decisions create dependencies that can last years. The switching costs in AI are higher than traditional software because your data, your workflows, and your team's skills all become tied to a specific platform. A poor vendor choice doesn't just waste money. It constrains your AI strategy for the life of the contract.

    The data sovereignty risk is the one most boards underestimate. Many AI vendors process data through overseas infrastructure. Some use customer data to train their models. Some retain data after contract termination. If your board hasn't reviewed the data handling provisions in your AI vendor contracts, you may already be in breach of Privacy Act obligations.

    Vendor concentration creates strategic vulnerability. One organisation I work with discovered that 80% of their AI capability ran through a single vendor. When that vendor raised prices by 40% at renewal, they had no negotiating position. The switching cost was estimated at $1.5M and 12 months of disruption. A board-level review would have identified and addressed this concentration risk years earlier.

    The competitive implications are significant. AI vendor choices affect what capabilities you can deploy, how quickly you can innovate, and whether you can differentiate or are limited to the same tools as every competitor. Boards that treat AI vendor selection as routine procurement miss the strategic dimension.

    The regulatory trajectory makes this more urgent. OAIC enforcement is increasing. The ADM Transparency deadline (10 December 2026) requires organisations to explain automated decisions to affected individuals. If your AI vendor can't support that transparency, you've got a compliance problem that's now the board's problem.

    Only 14% of organisations are seeing AI-driven revenue. Vendor selection that prioritises capability, governance, and exit provisions over price alone is one reason the 14% are succeeding where others aren't.

    Podcast

    Listen to how Australian executives are applying AI

    Use the podcast to pressure-test the ideas in this article against real operator conversations. Each episode focuses on what leaders are shipping, where the friction is, and what actually lands.

    The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.

    In practice

    Examples or Practical Context

    A board required alternatives analysis for a proposed $400K annual AI analytics platform. Management's initial recommendation was the most expensive option from a global vendor. The alternatives analysis revealed a local provider with equivalent capability, Australian data hosting, and 40% lower cost. The local provider also offered contractual guarantees that data would never be used for model training. The board approved the local option.

    An ASX-listed company's audit committee reviewed an AI vendor contract and found a clause granting the vendor rights to use aggregated customer data for model improvement. Board intervention removed the clause and added annual audit rights. When the vendor later experienced a data breach affecting a different client, the audit rights enabled verification that the ASX-listed company's data wasn't compromised.

    A mid-market insurer signed a three-year AI contract without board review because it fell below the threshold ($180K annually). By year two, the vendor had become embedded in claims processing. When the vendor doubled their price, the insurer had no exit strategy and no data portability. Migration cost estimate: $600K and nine months. The board subsequently lowered the review threshold to $100K for AI vendors specifically.

    A healthcare provider's board required data sovereignty assessment for all AI vendors processing patient information. The assessment revealed that their preferred vendor routed data through Singapore-based infrastructure. While technically compliant, the board determined this created unnecessary risk given Australian-hosted alternatives. They selected a vendor with domestic data hosting at a 15% price premium, which the board considered appropriate risk mitigation.

    One board I work with applies E.A.R. at the vendor review stage. Their standard question: "Show me which E.A.R. category this vendor serves and the projected dollar impact." Two vendor proposals were rejected in the past year because management couldn't answer that question clearly.

    What to do

    Key Takeaways

    • Define clear thresholds that trigger board involvement in AI vendor decisions: contract value, data access, business criticality, and dependency risk.
    • Require alternatives analysis, data sovereignty assessment, lock-in analysis, exit strategy, and contractual protections for every vendor above threshold.
    • Apply the E.A.R. test to vendor proposals. If the vendor doesn't clearly help eliminate, automate, or reallocate, the business case needs more work.
    • Maintain a strategic AI vendor register with risk ratings and dependency assessments. Review quarterly alongside the Board AI Risk Register.
    • Set lower thresholds for AI vendors specifically. The switching costs and data risks are higher than traditional software procurement.

    Newsletter

    Get the Executive Brief each week

    Stay ahead of the next board question with short, practical analysis built for Australian executives. It cuts past recycled AI news and focuses on the decisions that matter now.

    The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.

    Assessment

    Run the AI Readiness Assessment

    Pressure-test oversight, accountability, and decision rights before risk shows up in the wrong place. Governance and decision control is one of the five dimensions the assessment scores.

    The trusted source for Australian executives navigating AI strategy, governance, and adoption. I translate technical complexity into practical business outcomes — growth, margins, and time-to-value.