Gate:ROILens:Conflicted AssumptionsSeat:CFO & FinanceType:Buy-Side Decision Audit

Who wrote the numbers in your board pack?

Something changed for boards this year, quietly, and the change was in accountability rather than in information.

In February the Central Bank of the UAE issued guidance on the responsible adoption of AI by licensed financial institutions. Governance and accountability sits first among its five principles, and the accountability described attaches to the institution and its board — not to the vendor who built the system.

Delaware’s courts have been moving in the same direction from a different angle. The duty of oversight has been read, case by case, to require that a board maintain a functioning system for surfacing risk in its mission-critical operations. Not that directors get every judgment right — that they not be structurally blind. Practitioner commentary through 2026 has argued, with increasing confidence, that AI is the natural next application. No court has yet decided it.

Both developments assign the board responsibility. Neither changes what the board is shown.

Both developments assign the board responsibility. Neither changes what the board is shown.

A paper in which every number traces back to the party being paid means the board approved a decision using measures the counterparty authored.

Governance Asymmetry

The reporting line that did not move

In most institutions, the AI update reaching the board is prepared by the team deploying AI, using figures supplied by the vendor selling it. This is not a governance failure in any deliberate sense — it is the ordinary flow of information in any organisation, and it works acceptably for most subjects.

It works less well here for a specific reason. In most board reporting, the numbers describe something that already happened and can be independently reconstructed: revenue, headcount, incidents, capital ratios. In AI reporting, the numbers frequently describe a counterfactual — what would have happened without the system — and counterfactuals cannot be reconstructed. They can only be modelled, and the model has an author.

Diagnostic Check 1

A fifteen-minute check requiring no technical knowledge

Take the last board paper that proposed or reported on an AI initiative. For every quantified claim in it — projected saving, efficiency gain, benchmark, payback period, adoption rate — trace where the number came from.

Not whether it is plausible. Where it came from.

Three origins account for nearly all of them:

Origin 1

Vendor's own material, reproduced

A figure from a sales deck or a case study, carried across without re-derivation.

Direct Counterparty Figures
Origin 2

Institution's business case, built on vendor assumptions

One step removed, and considerably harder to see, because the figure now carries your institution's logo and formatting. The assumptions underneath — adoption rate, baseline, attribution — usually came from the vendor.

Indirect Counterparty Assumptions
Origin 3

Something the institution measured itself

Rare. Figures derived independently from internal baselines and validated measurement clauses.

Institutionally Verified

The ratio is the finding. A paper in which every number traces back to the party being paid is not a dishonest paper. It is an ordinary one. But it means the board approved a decision using measures the counterparty authored, which is a materially different act from the one it appeared to be.

Diagnostic Check 2

The adjacent check, ten minutes

The number problem has an ownership counterpart: if nobody on the board is formally responsible for testing these figures, the ratio above will not change on its own. Open your board’s committee charters and search all of them for artificial intelligence.

Four possible results, each meaning something different:

Structurally Coherent

Audit Committee

Already responsible for internal controls, third-party risk and the integrity of reported numbers, making it structurally the most coherent home.

Defensible

Risk or Technology

Defensible, though it frames AI as a thing that might go wrong rather than as a set of numbers that might be wrong.

Patchwork Problem

Several Committees

Oversight distributed across multiple committees until nobody explicitly holds single-point accountability.

Common Case

None

The most common result: means the board is accountable for something no committee has been asked to look at.

Whatever the answer, it is a fact about your governance rather than an opinion about AI.

Synthesis

What follows

Neither check tells a board to stop, and neither requires anyone to understand how a model works.

What they establish is whether the institution possesses an independent view of its own AI programme, or only a well-formatted version of the vendor’s view. Those feel identical in a board meeting. They differ entirely when the numbers are tested.

Diagnostic Closing Test

If nothing in the last paper originates on your side of the table:

The useful question is not whether the figures are correct. It is what it would take to produce your own — and how long that would take, and who would own it.

An institution that cannot author its own metrics has effectively outsourced the definition of success to the party selling the system.

“Distinguishing vendor-supplied assumptions from institutionally verified figures when boards evaluate AI business cases, tracing whether reported numbers originate from the counterparty being paid.”