The board wants AI governance evidence by Friday. Can you produce it?

Marino Software has a track record in partnership with enterprise and organisations in regulated sectors. This is the second post in our AI governance scenarios series - where we look at the pressure points AI is creating inside organisations, and what real and workable answers look like.

The most searching board-level questions are often deceptively simple and helpfully direct. A common this month and last: how do we know our AI use is governed? The answer is not the policy, but the reality - and that includes the evidence for the board that policy is defined, understood, appropriate… and then living in the real world i.e. being followed, system by system, decision by decision. This is an action item for the CIO, who of course has responsibility for both the policy definition and its implementation. 

This is happening more often. Grant Thornton's 2026 AI Impact Survey found that 62% of insurers say they're scaling AI across multiple functions, yet less than a quarter are very confident they could pass an independent governance review with centralised evidence inside 90 days. Three out of four organisations are effectively telling a regulator, an auditor, or their own board "trust us," when what's being asked for is "show us."

Why "we have a policy" isn't the answer

A policy describes what should happen: which systems get reviewed, who signs off on high-risk use cases, how often models get re-tested. None of that tells a board member what actually happened last quarter, because a policy is a promise about behaviour rather than a record of it. For Marino Software, our approach to strategy and partnership is implementation-led. This is because we understand, through years of experience in regulated sectors, that the only thing that matters really is the follow-through - the implementation. Everything else is just slides - rigour theatre.

Evidence of implementation is what matters. It's the record that a specific use case was risk-assessed before it went live, that a named person reviewed a specific automated decision, that a vendor's model was checked against your own risk criteria, before procurement signed off. A policy is what you intended to do, and evidence is what you can prove you did.

High-performing boards understand the difference, largely because regulators already do. Logicalis's 2026 CIO Report found that 85% of CIOs describe governance as a barrier to AI adoption, and 76% say unchecked AI remains a serious concern. These aren't organisations without a policy sitting somewhere in a shared drive. They're organisations that have started to suspect a policy on its own won't survive scrutiny.

What a real governance evidence pack should contain

When a board or an auditor actually asks for proof, a useful answer typically has five parts to it:

  1. A use-case register: listing every AI system in production, who owns it, and what it's used for. Not the systems procurement happens to know about. All of them.
  2. A risk tier per system: because a chatbot answering FAQ queries and a model influencing a credit decision are not the same, and your evidence should show that distinction was made deliberately.
  3. Decision logs: so that for any system materially affecting a customer, employee, or regulatory outcome, there's a record of what it decided, on what basis, and when.
  4. A human oversight record: proving that a person actually reviewed the decisions that needed reviewing
  5. Vendor documentation: model details, data provenance, and the vendor's governance claims.

Put together, that's roughly what "governed" looks like once someone asks you to show it, rather than simply describe it.

What best practice looks like

Best practice in our view is about visibility on reality: the CIO’s dashboard. Every AI system in production is listed there - with its risk tier attached, and against the highest-risk system, a credit decisioning model, sits a complete log of every decision it made last quarter, the human reviews attached to the ones that required one, and the vendor's latest model documentation, timestamped and version-controlled. The CIO exports a report, checks it against the board's specific question, and sends it before the end of the day, without reconstructing anything or chasing down five different teams.

The difference between that CIO and the one starting from a spreadsheet isn't effort or diligence. It's whether the evidence was assembled continuously, as a natural by-product of how AI gets deployed and reviewed, or whether it has to be rebuilt from scratch every single time someone asks.

The real fix is continuous, not reactive

Most organisations that get caught out by this question aren't actually short on governance. What they're missing is a layer that keeps the evidence for that governance assembled as it happens, rather than scattered across five tools and stitched back together under pressure whenever someone asks.

That's the problem Evident, Marino's AI governance platform, is built to solve. It sits across your AI use cases as a single evidence layer, keeping the use-case register, risk tiers, decision logs, oversight records, and vendor documentation assembled as you go, so that "can you prove it's governed" gets answered with a report you already have - rather than a project you now have to start. If your organisation is one board question away from finding out whether your evidence would hold up, it's worth finding that out before the question actually gets asked.

This is Post 2 in Marino Software's AI Governance Scenarios series. Read Post 1 on how to address shadow AI in your organisation.

Sources

Grant Thornton, 2026 AI Impact Survey Report (insurance insights): https://www.grantthornton.com/insights/survey-reports/insurance/2026/insurance-insights-2026-ai-impact-survey-report 

Grant Thornton, 2026 AI Impact Survey (cross-industry hub page): https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey 

Logicalis, 2026 CIO Report (UK/Ireland edition, 85% governance-as-barrier stat): https://www.uki.logicalis.com/cio-report/2026 

Logicalis, 2026 CIO Report press release (76% unchecked-AI-serious-concern stat): https://www.prnewswire.com/news-releases/logicalis-2026-cio-report-cios-navigate-surging-ai-investment-amidst-growing-governance-concerns-302702222.html

Image author: Anne Fehres and Luke Conroy & AI4Media / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/

!@THEqQUICKbBROWNfFXjJMPSvVLAZYDGgkyz&[%r{\"}mosx,4>6]|?'while(putc 3_0-~$.+=9/2^5;)<18*7and:`#
A man presenting sticky notes on a whiteboard

Let's talk

Have a project in mind, or just starting to think one through? We’re good at both.

Get in touch