Skip to main content

    Board education

    AI for Boards: Director Training Australia

    Board directors in Australia have specific AI governance obligations under Section 180 of the Corporations Act. ASIC Report 798 found nearly 50% of financial services licensees lacked basic fairness policies for AI. Directors who can't demonstrate reasonable care over AI systems face personal liability. AI training for boards isn't about understanding algorithms. It's about asking the right questions, governing the right risks, and building evidence that your board took reasonable steps.

    Why Board Directors Need AI Training

    The regulatory environment has shifted. Directors can no longer delegate AI to the CTO and call it governed.

    ASIC's position is technology-neutral: existing laws apply equally to AI-driven decisions. If your credit scoring algorithm discriminates, it's the same liability as if a person discriminated. The difference is that AI discrimination is harder to detect and easier for regulators to prove once they look.

    Many Australian firms have no AI governance procedures. 53.4% of C-suite executives hide their AI use because they don't understand it. If your board can't answer these five questions, you have a governance gap:

    1. What AI systems does our organisation currently use?
    2. Which of those systems make decisions affecting customers or employees?
    3. Do we have fairness and bias policies for each system?
    4. Who is accountable for AI outcomes?
    5. Can we explain our AI decisions in plain English to a regulator?

    I've asked these questions in board meetings. Most boards can answer the first one. Almost none can answer all five.

    What the Training Covers

    Module 1: The Regulatory Environment

    What ASIC, OAIC, and APRA require of directors regarding AI. The ADM transparency deadline (10 December 2026) and what it means for your privacy policies. APRA's human accountability position: AI can be a co-pilot, never an autopilot. This module gives directors the regulatory vocabulary to have informed governance discussions.

    Key distinction: APRA requires human accountability for AI systems, not human review of every AI decision. Banks think "human-in-the-loop" means reviewing every decision (impossible at scale). APRA actually requires a person responsible for the algorithm, its operations, and the outcomes it drives. Understanding this nuance is what separates competent boards from exposed ones.

    Module 2: The Question Framework

    Directors don't need technical knowledge. They need a question framework that exposes risk and validates management claims.

    Five questions for every AI initiative management presents:

    1. What's the measurable ROI in dollar terms?
    2. How do we know this system is fair (not "the vendor says so")?
    3. What happens when this system is wrong?
    4. Who is accountable for this system's outcomes?
    5. Can we explain this decision to a customer in plain English?

    When management says "our vendor guarantees fairness," the follow-up is: "Can you provide independent bias testing documentation, or are we relying on vendor claims?" ASIC doesn't accept vendor assertions as governance evidence. Neither should your board.

    Module 3: The Evidence Package

    What your board needs to demonstrate reasonable care if ASIC investigates:

    • Board minutes showing AI governance discussions
    • Board-approved AI governance framework
    • Risk assessment for each AI use case
    • Policies for fairness, transparency, and accountability
    • Documentation of human oversight mechanisms
    • AI risk register reviewed quarterly

    This module walks through each component with real examples. One board I worked with had approved AI budget in six consecutive meetings without a single governance discussion in the minutes. That gap would have been devastating in an ASIC review.

    Module 4: Risk Scenarios

    Practical walkthroughs of what goes wrong and how boards should respond:

    Scenario 1: AI denies a customer credit. Customer alleges discrimination. ASIC investigates. What evidence demonstrates your board exercised reasonable care?

    Scenario 2: An employee uses an agentic browser (28% of enterprises downloaded OpenAI Atlas within one week) with full access to customer data. Privacy breach occurs. What governance should have been in place?

    Scenario 3: 10 December 2026 passes. Your privacy policies haven't been updated for ADM transparency. OAIC enforcement notice arrives. What's the remediation path and what's the cost?

    Who This Is For

    • Non-executive directors on ASX-listed boards
    • Board chairs responsible for governance committee oversight
    • Audit and risk committee members
    • Government board members
    • Any director whose organisation uses automated decision-making

    This training is designed for directors, not technologists. Zero technical background required. The content is governance-focused, risk-focused, and specifically Australian.

    What You Get

    • Half-day board training session (in-person Melbourne or virtual)
    • AI Governance Question Framework (board-ready document)
    • Evidence Package template with implementation guide
    • AI Risk Register template pre-loaded with common AI risk categories
    • Post-training follow-up session (60 minutes, 30 days after training)

    Related Resources

    Your board has governance obligations for every AI system in your organisation. Most boards can't list those systems. Start there. Book a board training session to close the gap before ASIC or OAIC does it for you.

    Related Topics

    Explore This Pillar

    Go deeper with the matching master pillar and the most relevant supporting topics for this page.