Board Oversight & Agentic AI: From Framework to Practice

By David Seibert

A year ago, approving an AI governance framework felt like getting ahead of the curve. Today it’s the floor, not the ceiling. AI is no longer a pilot project sitting off to the side of the credit union; it’s inside the core decisions members feel directly, from loan underwriting and fraud alerts to the chatbot answering a member’s first question. Nearly two-thirds of credit unions now plan to use AI in credit decisioning alone, and that number will only grow. The framework your board approved was step one. The harder, ongoing job is oversight, and that job doesn’t end when the policy gets a signature.

Where the Gap Shows Up

Most AI governance frameworks were written and approved once, then filed away as evidence the board did its job. That’s a problem, because the AI itself doesn’t stay still. Vendors update underlying models without always notifying the credit union, let alone the board. A tool approved for one narrow use, like drafting member service responses, quietly expands into adjacent decisions nobody brought back for a second look. Meanwhile, examiners have shifted their posture. They’re moving past “do you have a policy” and asking “can you show me how you’re overseeing what’s actually running today.” A framework document answers the first question well. It doesn’t answer the second at all, and that’s the gap most boards haven’t closed yet.

Three Questions Boards Should Be Asking Now

  • What’s in production, and has it changed? An AI inventory is only useful if it’s refreshed on a set cadence. Scope creep, a tool quietly doing more than it was approved to do, is the most common way oversight lapses without anyone deciding it should.
  • Who’s accountable when the model is wrong? Much of the AI touching your members arrives embedded in a vendor’s loan origination system, core platform, or contact center software. Third-party risk management needs to name AI-embedded vendors explicitly, not assume a general IT vendor review already covers them.
  • What does “unacceptable” look like? This is a risk appetite question, not just a technology question. Override rates, model drift, and disparate impact in lending decisions all deserve a defined threshold and a named owner, the same way capital and liquidity metrics do.

Why This Belongs at the Board Level

It’s tempting to treat AI oversight as a management-level detail, something that surfaces in board packets only when something goes wrong. That instinct is exactly backward. AI decisions now sit at the intersection of member trust, fair-lending exposure, and reputational risk, three areas boards already hold as core fiduciary territory. Delegating the framework to management is appropriate. Delegating the ongoing question of whether that framework still matches reality is not.

From Framework to Practice

Closing the gap doesn’t require a new committee or a specialized subcommittee most boards don’t have the bandwidth for. It requires treating AI oversight as a recurring agenda item with real substance behind it, not a once-a-year checkbox:

  • A living AI inventory, reviewed at least semiannually, that tracks what’s in production, who owns it, and how each use case has changed since it was last approved.
  • AI-specific key risk indicators, tied to your existing risk appetite statement, covering model performance and fair-lending outcomes rather than just system uptime and vendor SLAs.
  • An explicit AI flag in third-party risk reviews, so vendor-embedded AI gets the same scrutiny as AI the credit union built or bought directly, rather than riding in unnoticed inside a broader software contract.
  • A defined escalation trigger, tied to a specific threshold, so the board hears about a breach before an examiner or a member does, and knows in advance what happens next.

The board’s job was never to approve a policy once and move on. It’s to keep asking whether the AI in front of members today still matches the AI the board signed off on, and to make sure someone owns the answer between meetings. That’s the difference between having a framework and practicing oversight, and it’s the difference examiners, and members, will notice.

David Seibert is Strategy, Risk, and Assurance Partner with Rochdale.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.