by Alexander Larsen, CFIRM, Deputy Chair of the IRM Energy and Renewables Committee and IRM Saudi Arabia Committee member

Artificial Intelligence (AI), digital transformation, automation and cloud computing (and other technologies) have quickly become fundamental to modern business strategy. Organisations across nearly every sector are adopting these technologies at pace, pursuing greater efficiency, improved customer experience and lower costs.

However, one of the challenges of rapid adoption is ensuring sufficient coordination and governance. Without it, organisations can quickly find themselves dealing with fragmented initiatives, strategic misalignment, flawed AI-driven decisions, cyber incidents and poor data governance. Traditional committee structures are not always well positioned to manage this complexity. The question therefore becomes whether existing governance arrangements are enough. Many organisations continue to oversee AI through existing risk, audit or technology committees, particularly while adoption remains relatively limited. A dedicated committee usually becomes necessary once AI adoption widens, risk exposure increases, or oversight starts falling between multiple committees.

Digital Risk Has Become Enterprise Risk
Digital risk has become enterprise risk. Technology now sits at the centre of strategy, financial performance, operational resilience, regulatory compliance and reputation. So when digital fails, it is rarely just an “IT issue” anymore — it can quickly turn into a full enterprise crisis.

Recent examples show how wide this exposure has become: ransomware halting operations, AI errors distorting decisions, cloud outages disrupting critical services and data breaches triggering regulatory penalties. At the same time, AI adds another layer. Many organisations are rolling out generative AI across customer engagement, decision support and data analysis, often faster than their governance can keep up — bringing risks such as hallucinated outputs, intellectual property exposure, data leakage, weak explainability and regulatory uncertainty that did not exist a few years ago. That uncertainty is increasingly giving way to expectation. The EU AI Act’s requirements for high-risk systems are phasing in, AI-specific regulation is emerging across parts of the United States, and countries such as Saudi Arabia are continuing to formalise their AI frameworks and regulatory expectations. For organisations, the direction of travel is becoming clear. This means organisations need to move towards demonstrating how AI is governed, not simply assert that governance exists. Digital change has moved faster than many governance arrangements. Oversight tends to be split across committees — cybersecurity here, technology investment there, data privacy and innovation somewhere else again — which can lead to gaps in accountability, duplication of effort and inconsistent decision-making.

However, dedicated AI or Digital Committees are becoming more important. Done well, they bring these responsibilities together, connect technology risk back to strategy, and give boards a clearer way to manage one of the fastest-moving areas of risk they face.

What an AI and Digital Committee Is There to Do
An AI or Digital Committee isn’t there to run technology day-to-day — that remains firmly with management. Its role is to provide oversight, challenge and strategic direction, ensuring digital and AI initiatives align with the organisation’s objectives and risk appetite. These committees can operate at either Board or Executive level. Board committees typically focus on strategic oversight, challenge and assurance, while Executive committees are generally more concerned with prioritisation, delivery oversight and escalation.

In practice, the remit is broad. One of the committee’s primary responsibilities is ensuring digital and AI investments genuinely support business priorities rather than simply chasing the latest technology trend; maintaining visibility over cybersecurity, data governance, AI controls and third-party dependencies; and overseeing governance and ethical considerations such as transparency, accountability and data privacy as stakeholder and regulatory expectations continue to evolve.

At the same time, technology is often not the real constraint. Whether transformation succeeds usually depends on organisational readiness — leadership, skills and culture — which is every bit as much the committee’s responsibility as the technology itself. Ultimately, the committee should monitor whether digital initiatives are delivering their intended outcomes by tracking performance, adoption and control maturity, while ensuring risks remain understood and appropriately managed.

Getting the Right Voices in the Room
Effective committees are multidisciplinary, bringing together business, technology, cybersecurity, risk, legal, compliance, data governance and strategy expertise. This diversity of perspectives helps break down organisational silos, promotes more balanced decision-making and enables the committee to champion responsible AI principles such as accountability, transparency, fairness and appropriate human oversight.

Risk representation is particularly important. Digital and AI initiatives are often driven by innovation and speed—which is entirely appropriate—but without risk involvement from the outset, committees can become overly focused on technology opportunity and insufficiently challenge downside exposure, interconnected risks and whether initiatives remain within the organisation’s risk appetite. In practice, this means maintaining visibility of key technology-related risks, including cyber resilience, AI model risk, data governance, regulatory compliance, third-party dependency and reputational exposure. It also means ensuring AI systems can be properly documented and explained — their purpose, performance and limitations — as regulators and auditors begin to expect this as standard evidence of oversight, not simply good intention.

Why Some Committees Work, and Others Don’t
Setting up the committee is the easy part — making it effective is considerably harder and comes down to a few disciplined habits. It starts with clear terms of reference: scope, authority and interaction with other governance bodies. Reporting should then be concise and decision-focused, covering both value realisation and risk indicators so members can determine whether initiatives are delivering value and operating within appetite, rather than simply creating activity.

One of the practical examples for effective oversight is the AI inventory — a clear, current record of what AI systems are in use, where, and at what level of risk. Without it, committees end up overseeing in the abstract rather than the specific, and this is something regulators are starting to expect organisations to demonstrate, rather than merely describe. And because this landscape moves quickly, continuous learning is essential. Committee members need to stay current on AI capability, cybersecurity developments and regulatory expectations; otherwise, their oversight risks lagging behind the very technologies they are meant to oversee.

Conclusion
Not every organisation needs a dedicated AI or Digital Committee. However, where AI adoption is widening, and oversight is becoming fragmented, a well-run committee can be difficult to substitute for.
One of the biggest misconceptions is that committee effectiveness comes from having more members or the longest terms of reference; they are the ones that can evidence what they oversee — the AI inventory, the risk indicators and how AI systems reach and justify their outputs — rather than simply describe it.
Innovation without governance creates exposure. Too much control kills the very transformation it is meant to protect. Ultimately, the committees that get this right are the ones that can hold both at once.