Tag: For the NED

  • Is the Business Actually Ready for AI? The Questions a Board Should Ask Management

    Written for the NED.

    When management brings an AI plan, the sharper board question isn’t whether the plan is good — it’s whether the business is ready to execute it. For a non-executive, that’s an assurance question, and it’s the one most likely to protect the investment.

    Sooner or later, management brings AI to the board — a plan, a business case, a request to invest. The natural instinct is to assess the plan on its merits. But a non-executive can add more value by asking a prior question, one management is often too close to the excitement to ask itself: is the business actually ready to get value from this?

    Because the uncomfortable pattern, seen across many organisations, is that enthusiasm for AI runs well ahead of readiness for it. And readiness — not the quality of the plan or the cleverness of the tool — is what usually determines whether the money creates value or evaporates.

    Why readiness is the board’s question

    AI’s core effect is speed. It accelerates whatever process you point it at. That’s only an advantage if the process is sound. Accelerate a business with clean data, working processes and clear ownership, and you compound value. Accelerate one with messy data, undocumented processes and no accountable owner, and you don’t fix those weaknesses — you reach them faster. More speed on weak foundations is not transformation; it’s a quicker route to the existing problems.

    This makes readiness a governance concern, not a technical one. A board doesn’t need to understand the model. It needs assurance that the business can actually absorb and control what it’s being asked to buy — which is squarely within a non-executive’s remit.

    The questions a board should put to management

    A board doesn’t need technical depth to provide real oversight here. It needs to ask the right questions and expect evidenced answers:

    Is our data good enough to rely on? AI built on data we don’t trust produces confident output we can’t trust either.

    Do the processes we’re accelerating actually work today? If we couldn’t do the job well manually, AI won’t do it for us — it will amplify the flaws.

    Who owns AI, day to day? Not as a side project — a named person accountable for managing it, or the initiative will quietly decay.

    Are we buying a tool when we need something else? Sometimes the honest first requirement isn’t software but a policy, a capability, or a leader to own it.

    Have the pilot’s numbers been tested in production? Pilots flatter; production reveals the truth. A business case built on a demo is a business case built on sand.

    None of these needs a technical answer. All are assurance questions about foundations, ownership and evidence.

    The leadership question

    For the board itself: are we assuring ourselves that the business is ready to execute this AI plan — or just that the plan reads well? The second is easy and comforting. The first is where a board earns its keep.

    A prompt to prepare the discussion

    For private, non-confidential board prep:

    “Act as an adviser to a board considering an AI investment management has proposed. Draft the readiness questions we should put to management: about data quality, whether the target processes work, who owns AI day to day, whether we need a tool or something else, and whether the pilot economics have been tested in production. Frame them as assurance questions and flag where we should seek independent verification.”

    What to do next

    When AI investment comes to the board, ask the readiness questions before approving the plan, and expect evidenced answers. Where the honest answers reveal gaps, the board’s steer is often that the first investment should be readiness — ownership, foundations, a capability decision — rather than tools. That guidance protects the money and improves the odds the eventual spend creates value.

    In closing

    A board that assesses only the plan can approve a good plan the business can’t execute. A board that assesses readiness protects the investment and steers management toward value rather than expensive, scattered spend.

    If your board would value a session on the AI-readiness questions to put to management — and how to assure itself on the answers — that’s exactly what Savant and Axulu provide. Where deeper assurance or capability is needed, Savant can connect the board to experienced technology leaders, fractional or permanent, to own the programme.

  • The Cyber, AI and Insurance Questions a Board Should Be Asking Now

    Written for the NED.

    AI is the part of this conversation that gets attention. Cyber resilience is the part that should keep a board awake. For a non-executive, the two are now connected — and most boards haven’t checked the join.

    There’s a question worth putting to any board, almost in passing: if the business had a cyber claim tomorrow, are we confident the policy would actually pay? Most directors assume yes. Then comes the follow-up — could management evidence the specific controls the policy assumes are in place? — and the confidence drains out of the room. For a non-executive, that reaction is the signal that a genuine assurance gap has just surfaced.

    It’s worth being careful and accurate, because insurance is contractual and every policy differs. The general point, though, is one every board should understand: a cyber policy is not an unconditional promise to pay. Many are written on the basis that the insured maintains certain security controls. If, when an incident happens, those controls turn out not to have been in place, a claim can become contested rather than straightforward. The policy’s conditions — not its headline cover — are where that lives, which is exactly the kind of thing a board should assure itself on rather than assume.

    What boards tend to misunderstand

    The misunderstanding isn’t recklessness. As one senior leader put it well, most leadership teams aren’t underestimating cyber risk — they’re competing with other priorities. Revenue, hiring, delivery, reporting deadlines. Cyber resilience sits on the list, rarely at the top, and has quietly become more of an operational board issue than a technical one.

    The hidden problem is that many businesses have grown more operationally fragile than they realise — more systems, suppliers, people and remote access, with controls that haven’t kept pace. And the thing assumed to catch them if it goes wrong, the insurance, is the thing whose conditions have often never been read against the actual setup. For a board, that’s an assurance question hiding in plain sight.

    Where AI changes the picture

    The textbook fraud has long looked like this: a supplier’s mailbox is compromised, an invoice arrives looking normal but with changed bank details, the payment goes to the attacker, and a painful argument follows about who carries the loss — often not the party that was breached. That dependency and liability risk is sobering on its own.

    AI sharpens it. The main defence against that fraud used to be human instinct — this doesn’t quite sound like them; I’ll pick up the phone. AI erodes exactly that instinct: writing style, tone and increasingly voice can be imitated well enough to clear the “that doesn’t feel right” bar. The attack isn’t new; what’s new is that the cues we relied on to catch it are becoming forgeable. For a board, this is the real shape of the AI-and-security story — not the exciting demos, but the consequence that the same technology makes social-engineering fraud harder to detect.

    The oversight questions that follow

    A board doesn’t need to become expert to get ahead of this. It needs to ask management the right questions and expect evidenced answers:

    Could we evidence our security controls to an insurer tomorrow — with what’s actually in place, not what we intended? What does our policy assume or require of us, and are those conditions? How does our cover treat social-engineering and “we were tricked into paying” fraud, as opposed to a technical breach? And where are we still relying on a human noticing that “something doesn’t sound right” as a control, now AI can imitate the people we trust?

    None of these needs a technical answer. All are governance questions about resilience, dependency and evidence.

    To be clear: no review guarantees a payout, and no board discussion can promise a regulatory or insurance outcome. The aim is assurance — that the controls the business relies on genuinely exist, and could be proven.

    A prompt to frame the discussion

    For a private, non-confidential board prep:

    “Act as an adviser to a board audit and risk committee. Draft the questions we should put to management about our cyber and AI resilience: what our cyber policy assumes we have in place, what evidence we could produce after an incident, how exposed we are to supplier and payment fraud, and how AI changes that exposure. Frame them as assurance questions, and flag where we should seek independent verification.”

    What to do next

    Put AI and cyber resilience on the board agenda as an assurance item, not a technical one. Ask management to map the business’s actual controls against what the cyber policy requires, and to report where they don’t line up. That mapping — the kind a structured cyber-policy or IT defensibility review makes systematic — turns “we think we’re covered” into “we can evidence that we are.”

    In closing

    AI is the attraction; cyber resilience is the consequence sitting right behind it. A board that assures itself on the exciting AI story while leaving the insurance and controls assumptions untested is overseeing in exactly the wrong direction.

    If your board would value a clear-eyed session on where AI, fraud and cyber insurance now intersect — and the questions to put to management — that’s a conversation Savant and Axulu are built for, with the defensibility and security depth to back it up.

  • What Every Board Should See AI Do Before the Next Strategy Discussion

    Written for the NED.

    A non-executive can’t oversee well what they’ve never seen. Before the next strategy discussion, a board benefits from watching AI work on real material — not to operate it, but to ask sharper questions and give better assurance.

    Boards are increasingly expected to have a view on AI — its opportunities, its risks, management’s plans. Yet most non-executives are forming that view from the same sources as everyone else: headlines, hype, and the occasional alarming anecdote. That’s a thin basis for the two things a board owes the business on any material topic: informed encouragement and informed challenge.

    The gap isn’t technical knowledge. A NED doesn’t need to operate AI any more than they need to run the finance system. What helps is having seen what it genuinely does — because oversight of something you’ve only read about tends to be either credulous or unduly fearful, and neither serves the company.

    Why seeing changes the quality of oversight

    There’s a specific reason abstract AI briefings leave boards no wiser: they ask non-executives to imagine the leap from “clever tool” to “consequential in our business,” and that leap is exactly where judgement is needed. Watching AI work on recognisable material closes the gap. The board stops debating a concept and starts assessing a capability — which is the proper posture for oversight.

    What a board benefits from seeing

    A short, board-grade demonstration uses the kind of material non-executives actually handle:

    A financial model, stress-tested live. An assumption changed in plain language, with upside, base and downside moving together — showing how management could interrogate numbers faster, and prompting the question of how that changes the quality of what reaches the board.

    A long report reduced to its risks. The genuine obligations, exposures and deadlines pulled from a dense document in seconds — and the immediate governance question of who validates that extraction.

    Two documents compared. Changes and risks between contract or policy versions surfaced instantly.

    A decision pressure-tested by a panel. This is the one that resonates most with a governance mind. AI can convene named expert personas — a risk reviewer, a commercial sceptic, a red-teamer whose only job is to find the flaw — to challenge a proposal from several angles. Used this way, AI is a challenge instrument, not a chatbot.

    The move a NED should notice

    The most important thing to observe isn’t the speed. It’s that how you frame a request to AI determines whether you get an honest answer or a flattering one. “Show me why this plan is right” produces a confident echo; “argue the strongest case against this plan and tell me what we’re not seeing” produces something useful. That distinction — comfort versus challenge — is a governance instinct rendered in software, and it reframes AI from a productivity toy into something a board should care about how management uses.

    The oversight questions that follow

    Once you’ve seen it, the right questions become obvious: Where is management already using AI, and do they know where? Who owns the outputs, and who is accountable when they’re wrong? What data must never go near these tools? And are we accelerating a process that works — or one that’s quietly broken? That last question matters, because AI applied to a flawed process doesn’t fix it; it reaches the failure faster.

    A short board prompt

    For a private, non-confidential trial of the challenge instinct:

    “Act as a sceptical non-executive director. Here is a strategic proposal management has put forward: [describe it, no sensitive detail]. Argue the strongest case against it, identify the assumptions that haven’t been tested, and list the three questions a board should ask before approving it. Do not reassure me.”

    It’s a small demonstration of AI as an aid to assurance rather than a threat to it.

    What to do next

    Ask for a short, board-level AI session before the next strategy discussion — one that shows what AI does on real material and equips the board with the questions to put to management. Assurance improves markedly when the board has seen the thing it’s being asked to oversee.

    In closing

    A board that has watched AI work gives better assurance and asks sharper questions than one working from headlines. The point isn’t to make non-executives operators; it’s to make their oversight informed.

    If your board would value a session pitched at exactly this level — what to see, and what to ask — that’s something Savant and Axulu provide for boards. Where deeper assurance is needed, Savant can also connect boards to experienced technology and security leaders who can advise on AI oversight.

  • Prompting for Executives: How to Get Useful Work Out of AI in 30 Minutes

    Most executive disappointment with AI is a prompting problem in disguise. A small set of techniques — learnable in half an hour — is the difference between a novelty and a genuinely useful tool. And the most important of them is really a governance skill.

    There’s a common, quiet verdict among senior people who’ve tried AI: “It was fine. Not the revolution I was promised.” Almost always, the tool wasn’t the problem. The request was. AI mirrors the quality of the instruction it’s given, and most first attempts are vague, so the answers are vague. The encouraging part is how quickly that’s fixed — the core techniques take about thirty minutes to learn and change the experience entirely.

    This isn’t about becoming a “prompt engineer.” It’s about a handful of habits that turn a flat tool into a sharp one — and one principle that matters more than all the techniques combined.

    The shift: from question to instruction

    The beginner’s mistake is treating AI like a search box — short, vague queries that get generic, hedge-everything answers. The fix is to treat it like a capable colleague you’re briefing: give it a role, context, the specific output you want, and the standard it’s being held to. Compare “what do you think of this plan?” with “act as a sceptical CFO; here is the plan and the numbers; identify the three weakest assumptions and what would have to be true for it to fail.” Same tool, completely different value.

    A few techniques that change everything

    Assign a role. Telling AI who to be sharpens everything it does. “Act as a cautious legal reviewer,” “act as a commercial sceptic,” “act as a risk analyst.” The role focuses the response far more than any amount of polite phrasing.

    Refuse to be flattered. This is the big one, and it’s worth dwelling on. Ask AI “show me why I’m right about this” and it will dutifully build your case — a confident, useless echo. Ask it “argue the strongest possible case against this decision, then tell me what I’m not seeing,” and you get something genuinely valuable. The model didn’t get smarter between those two prompts. You framed it to be honest rather than agreeable. The lesson generalises: a loaded question gets a loaded answer.

    Convene a panel. For any real decision, ask several roles at once: “Review this as a CFO, then as a legal reviewer, then as a red-teamer whose only job is to find what breaks.” You get a rounded critique instead of a single flat take — closer to a good leadership team than a chatbot.

    Make it check itself. AI can be confidently wrong. Adding “now verify that answer, show your reasoning, and flag anything you’re not sure about” catches a surprising amount of nonsense before it reaches your decision.

    Spot what should become a script. If you find yourself giving AI the same judgement task repeatedly with the same rules, that’s a signal it should become a fixed, repeatable process rather than a fresh ask each time — more reliable, and no longer dependent on the model’s mood.

    The principle that matters most: prompting is governance

    Here’s the idea that elevates all of this from technique to discipline. How you frame a request to AI doesn’t just shape the style of the answer — it shapes its honesty. “Show me why I’m right” and “show me why I might be wrong” are not two phrasings of one question. They’re a choice between comfort and truth.

    For a decision-maker, that’s not a writing tip. It’s governance. The framing you habitually use determines whether AI functions as a yes-man that launders your existing opinions, or as an honest adviser that improves your decisions. The problem people call “AI bias” is, in practice, very often just poor objective framing. Learn to frame for honesty and you’ve learned the single most valuable AI skill there is.

    The leadership question

    When you put a real decision to AI, ask yourself first: am I framing this to be challenged, or to be confirmed? If it’s the latter, you’ll get a comfortable answer and learn nothing.

    Try these prompts

    Three you can use today. For an honest critique:

    Act as a sceptical, experienced [CFO / operations director / legal reviewer]. Here is a decision I’m leaning towards: [describe it]. Argue the strongest case against it, identify the assumptions I haven’t tested, and tell me what would have to be true for this to go badly. Do not reassure me.

    For a rounded review:

    Review this from three perspectives in turn — a commercial sceptic, a risk and compliance reviewer, and a red-teamer whose only goal is to find the flaw. Give me each view separately, then the single biggest concern overall.

    To catch confident errors:

    Now verify your previous answer. Show your reasoning, identify anything you’re uncertain about, and flag any claim I should independently check before acting on it.

    What to do next

    Spend thirty minutes putting one real decision through those three prompts. The experience tends to convert sceptics faster than any demo, because the value is immediate and it’s on their own problem. For many teams the natural next step is a short, hands-on prompting session so the whole leadership group shares the same habits — particularly the framing-for-honesty discipline, which is too important to leave to chance.

    In closing

    AI isn’t underwhelming. Most people just haven’t been shown the half-hour of technique that makes it sing — and the one principle, that prompting is governance, that makes it trustworthy.

    If your leadership team would value that half-hour as a practical, hands-on session, Savant and Axulu can run it. It is low-friction, immediately useful, and often the gateway to the bigger conversation about doing AI properly.

  • The Cyber Insurance Question: Would Your Policy Pay If AI Caused the Breach?

    AI is the part of this conversation that gets people in the room. Cyber resilience is the part that keeps the board awake. The two are now connected — and most firms haven’t checked the join.

    There’s a question I’ve put to a lot of business owners, almost in passing: if you had a cyber claim tomorrow, are you confident your policy would actually pay? Most say yes without hesitation. Then I ask whether they could evidence the specific controls their policy assumes are in place — and the confidence drains out of the conversation.

    Insurance is contractual and every policy differs, so this needs care. A cyber policy is not an unconditional promise to pay. Many are written on the basis that the insured maintains certain security controls. If those controls turn out not to have been in place, a claim can become contested rather than straightforward.

    What most businesses misunderstand

    The misunderstanding isn’t that businesses are reckless about cyber risk. Most SME leadership teams are competing with other priorities: revenue, hiring, delivery, reporting deadlines and margin management.

    The hidden problem is that many firms have become more operationally fragile than they realise. Systems, suppliers, people, remote access and dependencies have multiplied, while the controls have not always kept pace.

    Where AI changes the picture

    For years, the textbook fraud has looked like this: a supplier’s mailbox is compromised, an invoice arrives looking normal except the bank details have changed, the payment goes out, and the money is gone before anyone notices.

    AI makes that harder to catch. The old defence was often human instinct — this email doesn’t quite sound like them. Writing style, tone and increasingly voice can now be imitated well enough to clear that bar.

    The attack isn’t new. What’s new is that the cues we relied on to catch it are becoming forgeable.

    The leadership question

    If you had to evidence your security controls to an insurer tomorrow, could you — today, with what is actually in place, not what you intended to put in place?

    And where are you still relying on a human noticing that “something doesn’t sound right” as a control?

    Three questions to take to your broker

    • What controls does our policy assume or require us to maintain, and are those written as conditions?
    • If we had a claim, what evidence would we need to produce to show those controls were in place at the time of the incident?
    • How does our policy treat social-engineering and authorised-push-payment fraud, as opposed to a technical breach?

    What to do next

    Read the conditions and requirements section of your cyber policy, and map your actual, current controls against it. Where they don’t match, you’ve found your priority list.

    No review guarantees a payout, and no article can promise a regulatory or insurance outcome. The aim is more grounded: make sure the controls your business is relying on actually exist, and that you could prove it.

    In closing

    AI is the attraction. Cyber resilience is the consequence sitting right behind it. A business that races to adopt AI while leaving its security foundations and insurance assumptions untested is moving fast in exactly the wrong direction.

    If your leadership team would value a clear-eyed session on where AI, fraud and cyber insurance now intersect, Savant and Axulu can help you check whether your controls match your cover.