
The most searching board-level questions are often deceptively simple and helpfully direct. A common this month and last: how do we know our AI use is governed? The answer is not the policy, but the reality - and that includes the evidence for the board that policy is defined, understood, appropriate… and then living in the real world i.e. being followed, system by system, decision by decision. This is an action item for the CIO, who of course has responsibility for both the policy definition and its implementation.
This is happening more often. Grant Thornton's 2026 AI Impact Survey found that 62% of insurers say they're scaling AI across multiple functions, yet less than a quarter are very confident they could pass an independent governance review with centralised evidence inside 90 days. Three out of four organisations are effectively telling a regulator, an auditor, or their own board "trust us," when what's being asked for is "show us."
A policy describes what should happen: which systems get reviewed, who signs off on high-risk use cases, how often models get re-tested. None of that tells a board member what actually happened last quarter, because a policy is a promise about behaviour rather than a record of it. For Marino Software, our approach to strategy and partnership is implementation-led. This is because we understand, through years of experience in regulated sectors, that the only thing that matters really is the follow-through - the implementation. Everything else is just slides - rigour theatre.
Evidence of implementation is what matters. It's the record that a specific use case was risk-assessed before it went live, that a named person reviewed a specific automated decision, that a vendor's model was checked against your own risk criteria, before procurement signed off. A policy is what you intended to do, and evidence is what you can prove you did.
High-performing boards understand the difference, largely because regulators already do. Logicalis's 2026 CIO Report found that 85% of CIOs describe governance as a barrier to AI adoption, and 76% say unchecked AI remains a serious concern. These aren't organisations without a policy sitting somewhere in a shared drive. They're organisations that have started to suspect a policy on its own won't survive scrutiny.
When a board or an auditor actually asks for proof, a useful answer typically has five parts to it:
Put together, that's roughly what "governed" looks like once someone asks you to show it, rather than simply describe it.
Best practice in our view is about visibility on reality: the CIO’s dashboard. Every AI system in production is listed there - with its risk tier attached, and against the highest-risk system, a credit decisioning model, sits a complete log of every decision it made last quarter, the human reviews attached to the ones that required one, and the vendor's latest model documentation, timestamped and version-controlled. The CIO exports a report, checks it against the board's specific question, and sends it before the end of the day, without reconstructing anything or chasing down five different teams.
The difference between that CIO and the one starting from a spreadsheet isn't effort or diligence. It's whether the evidence was assembled continuously, as a natural by-product of how AI gets deployed and reviewed, or whether it has to be rebuilt from scratch every single time someone asks.
Most organisations that get caught out by this question aren't actually short on governance. What they're missing is a layer that keeps the evidence for that governance assembled as it happens, rather than scattered across five tools and stitched back together under pressure whenever someone asks.
That's the problem Evident, Marino's AI governance platform, is built to solve. It sits across your AI use cases as a single evidence layer, keeping the use-case register, risk tiers, decision logs, oversight records, and vendor documentation assembled as you go, so that "can you prove it's governed" gets answered with a report you already have - rather than a project you now have to start. If your organisation is one board question away from finding out whether your evidence would hold up, it's worth finding that out before the question actually gets asked.
This is Post 2 in Marino Software's AI Governance Scenarios series. Read Post 1 on how to address shadow AI in your organisation.
Grant Thornton, 2026 AI Impact Survey Report (insurance insights): https://www.grantthornton.com/insights/survey-reports/insurance/2026/insurance-insights-2026-ai-impact-survey-report
Grant Thornton, 2026 AI Impact Survey (cross-industry hub page): https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey
Logicalis, 2026 CIO Report (UK/Ireland edition, 85% governance-as-barrier stat): https://www.uki.logicalis.com/cio-report/2026
Logicalis, 2026 CIO Report press release (76% unchecked-AI-serious-concern stat): https://www.prnewswire.com/news-releases/logicalis-2026-cio-report-cios-navigate-surging-ai-investment-amidst-growing-governance-concerns-302702222.html
Image author: Anne Fehres and Luke Conroy & AI4Media / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/

Have a project in mind, or just starting to think one through? We’re good at both.
Get in touch