The Operating Brief

What Your Board Should Ask Before Buying AI

An operating team brings the board an AI proposal. The demonstration is convincing, the vendor can explain the technology, and the slide on potential savings is easy to understand. The unresolved question is whether anyone has explained what the business is actually committing to operate.

For a service operator, I would review the proposal as an operating investment with a software component. Ask for the outcome, the evidence behind the expected benefit, the people responsible after release and the practical cost of changing course. The questions below are a decision framework, not legal or accounting advice and not a substitute for the relevant specialists' review.

Board directors asking questions along a boardroom table
Illustration: board directors asking questions along a boardroom table.

Name The Decision Being Funded

“Deploy AI across operations” is too broad to evaluate. A proposal should identify the triggering event, the workflow that changes, the people affected and the decision the first release makes possible. It should also say which requests remain outside the initial scope.

Adoption figures cannot supply those answers. The Census Bureau broadened its survey wording to AI use in any business function, as explained in its 2026 account of business adoption (Census Bureau, 2026). Treat a market statistic as context, then require evidence about your own operation before committing the budget.

Ask the sponsor to complete this statement: we are funding this bounded change because this recurring problem has this observed consequence. If the answer depends on a future company-wide transformation, separate that ambition from what the initial commitment will actually buy. A proposal becomes easier to challenge and easier to approve when its first decision has a clear boundary.

Ask Where The Benefit Appears

Potential hours saved, faster invoicing, fewer errors and additional sales are different kinds of benefit. They may overlap, and each depends on a chain of operational behavior. Require the sponsor to show the assumptions in that chain rather than adding every attractive number into one return estimate.

For example, completing an invoice packet sooner does not automatically establish that the customer pays sooner. The contractual billing cycle, disputed charges and collection process can all affect what follows. Measure the part the system changes directly and keep downstream effects as hypotheses until the evidence supports them.

The following review table is intentionally small. It gives directors a way to distinguish a measured condition from a proposed intervention without pretending a score can resolve every judgment. Ask management to bring the underlying records when an answer changes the investment decision.

Review questionEvidence before commitmentEvidence after release
What is happening today?Representative records and a baselineComparable records under the new process
Who changes their behavior?A named process owner and adoption planActual usage, workarounds and feedback
What can go wrong?Failure scenarios and recovery responsibilitiesExceptions, incidents and corrections
What does it cost to operate?Delivery, vendor and internal effort assumptionsActual spend and attention required
How do we change course?Access, handover and termination termsA usable export and tested recovery path

Separate Delivery From Operation

A successful demonstration is evidence that a behavior can be shown. A production release also needs access, integration, testing, user adoption and an agreed support boundary. Ask who owns each dependency and what happens when the client cannot supply it on time.

After release, someone must review exceptions, maintain integrations and decide whether another feature deserves investment. Make those responsibilities explicit in the proposal. “Support included” is incomplete without coverage hours, response definitions and a distinction between maintaining the agreed system and delivering new work.

The accountability framework organized around governance, data, performance and monitoring is a useful reference for this discussion (GAO, 2021). It was developed for federal agencies and other entities; citing it does not certify a vendor. Its practical value here is keeping operational responsibility visible alongside technical performance.

Check The Human Decision Path

Require one demonstration of a difficult case. Ask what happens when evidence conflicts, a model is uncertain, or a reviewer disagrees with a proposed action. The person handling that case should receive enough context to make a decision and a clear route to stop or correct the action.

The voluntary AI risk-management framework provides context for evaluating systems across their lifecycle (NIST, 2023). Apply the principle to the specific consequences in your workflow: routing a draft note and releasing a consequential action should not share an unexplained approval policy.

Ask whether the reviewer can see the original record and the relevant rule. Then ask whether the system records the reviewer's decision or only the final output. An organization needs to understand how a result was reached when a customer or internal owner later disputes it.

Buy An Exit You Can Use

A repository is only one part of a handover. The business may also need deployment instructions, account access, data exports, configuration, dependency licenses and a runbook. Ask what a replacement operator would need to restore the service and whether those materials are updated as the system changes.

Commercial review should distinguish custom deliverables, the client's existing material and third-party components. Have the responsible advisers review the actual agreement; a broad marketing statement about ownership does not settle every license or obligation. The engineering provider should make the inventory understandable enough for that review to be efficient.

The secure software development recommendations help frame questions about maintaining and protecting software throughout development (NIST, 2022). Ask the supplier to show how its practices apply to the delivered system. Good documentation should reduce dependence on an individual remembering how production works.

Require A Decision After Release

Set a recurring review that can result in expansion, adjustment or stopping. Bring usage, exception patterns, reliability and actual operating effort into the discussion. A calendar full of completed engineering tasks is useful delivery evidence, but it does not establish that the business should fund every item in the next queue.

The AI RMF playbook's adaptable guidance can help structure that continuing review (NIST, 2023). Choose the questions that fit the workflow and its consequences, then assign responsibility for answering them. A framework should help management make decisions, rather than become another report nobody uses.

An Unowned Outcome Cannot Compound

If the sponsor cannot name the person who owns adoption and the resulting process, defer expansion. The supplier can deliver functioning software while the operating team continues working elsewhere. Resolve the missing authority or capacity before adding more features to the commitment.

Also challenge proposals whose first release cannot be separated from a major unresolved migration. The board should understand which investment is a dependency for the other. An explicit dependency can be planned; an unstated dependency becomes an explanation after the commitment is already made.

First Steps

  1. Ask management for the baseline records, the bounded first release and the named operating owner.
  2. Review one difficult case and one recovery scenario with the proposed engineering provider.
  3. Put the operating review, support boundary and usable handover into the documents being approved.

Fund A Reviewable Operating Mandate

Approve a mandate with a clear boundary, observable acceptance conditions and a continuing decision process. Make the price, dependencies and responsibility explicit enough that both management and the supplier can recognize a change in scope. That gives the board something concrete to review after the demonstration has ended.

An ongoing relationship can be appropriate when the business needs active development and operation across a prioritized roadmap. The AI engineering partnership sets out that model, including the initial commitment, delivery boundary and handover terms, so the proposal discussion can begin with the actual operating arrangement.

References

  1. U.S. Census Bureau. Large Firms With at Least 20 Employees Biggest AI Users. 2026.
  2. U.S. Government Accountability Office. Artificial Intelligence: An Accountability Framework. GAO-21-519SP, 2021.
  3. Tabassi, E. Artificial Intelligence Risk Management Framework 1.0. NIST, 2023.
  4. Souppaya, M., Scarfone, K., and Dodson, D. Secure Software Development Framework Version 1.1. NIST SP 800-218, 2022.
  5. National Institute of Standards and Technology. AI RMF Playbook. Companion to AI RMF 1.0, 2023.
NEXTTO PRODUCTION

Bring the decision you need to make.

A short conversation about your workflow, its consequences and what useful progress would look like.

15 minutes · no charge · with Omar