This is Part 3 of a three-part series on AI governance for UK boards.
In Part 1, we exposed how AI systems produce severe bias—including zero selection rates for Black male candidates—and why your supplier’s assurances don’t protect you under UK law.
In Part 2, we dismantled the myth that human oversight prevents AI discrimination, showing how it often perpetuates bias instead.
Now: what your board needs to do about it.
What Your Board Actually Needs to Do
The problems are clear. AI systems exhibit severe bias. They’re already in use across most organisations. Human oversight doesn’t prevent discrimination.
Now here’s what your board needs to do about it – starting Monday morning.
Monday Morning: The Emergency Audit
Before your next board meeting, commission an independent review. Not by your AI suppliers. Not by your IT department who procured the systems. Independent verification by people who understand both UK equality law and algorithmic bias.
The audit needs to answer:
Where is AI being used? Not just the obvious recruitment tools. Performance management systems. Customer service chatbots. Credit decisioning. Resource allocation. Predictive maintenance that determines who gets equipment upgrades. You need the complete inventory.
What decisions is it influencing? “Influencing” matters as much as “making.” If a manager gets an AI-generated performance score and that shapes their conversation with the employee, AI influenced the outcome even if a human technically made the decision.
What data is it trained on? Historical data from your organisation will replicate historical discrimination. External datasets often contain demographic biases. You need to know what your AI learned and from whom.
What are the actual outcomes? Break down who gets hired, promoted, performance-managed, disciplined, or denied service. By protected characteristics. If you see disparate impact, you need to investigate immediately – not wait for someone to sue you.
Questions to Ask Your Suppliers (And Not Accept Vague Answers)
When you speak to the vendors who sold you these systems, be specific:
“Show us the fairness testing you conducted on UK demographics.” Not US data. Not “we tested for bias generally.” UK-specific testing against UK protected characteristics as defined in the Equality Act 2010.
“What’s your false positive and false negative rate for different demographic groups?” If the system is more likely to wrongly flag certain groups as “high risk” or wrongly exclude them from “high potential,” that’s bias you’re liable for.
“Who in your organisation is accountable when your system produces discriminatory outcomes?” If they say “the algorithm doesn’t discriminate” or “we have robust processes,” push back. You need a named person who will work with you to remediate bias, not marketing language.
“What ongoing monitoring do you provide, and what triggers a review of the system’s fairness?” AI systems drift. They need regular auditing. If your supplier isn’t monitoring for fairness as standard, that’s a red flag.
Building Board-Level Capability
Your board doesn’t need to become data scientists. But you do need AI literacy sufficient to ask these questions and understand the answers.
That means:
Board-level training on AI governance – Not “here’s how algorithms work” but “here’s what good governance looks like, here’s what questions to ask, here’s what red flags to watch for.”
An AI ethics or governance committee – With genuine authority to challenge AI deployments, not a paper exercise. The committee needs teeth: budget, executive sponsor, ability to pause or halt implementations.
Regular reporting on AI outcomes – Not just “we deployed this tool and it saved X hours.” Reports that include: who benefited, who was disadvantaged, what disparate impact analysis shows, what bias testing revealed.
Protection for people who raise concerns – If an employee or manager says “this AI tool seems to be producing biased results,” they need a clear route to raise that concern without career consequences. That needs board-level policy.
What Actually Works: The Long-Term Framework
Emergency audits are critical. But the goal is to build ongoing capability so you’re not perpetually firefighting.
Effective AI governance includes:
Pre-deployment impact assessment
Before any AI tool goes live in a process affecting people, conduct an equality impact assessment. What could go wrong? Who could be disadvantaged? How will we monitor for that? Who’s accountable?
Ongoing monitoring with clear triggers
Don’t wait for a tribunal claim to discover your AI is discriminatory. Set thresholds: if we see X% difference in outcomes between groups, we investigate immediately.
Clear override procedures
Decision-makers need authority to reject AI recommendations, and clear guidance on when and how to do so. They also need protection from being penalised for overriding the system.
Regular algorithmic audits
At least annually, and whenever you update the system or change the data it’s trained on. Independent auditors, not just the people who built or sold the tool.
Documentation of everything
When (not if) you face a legal challenge, you need to demonstrate you took reasonable steps to prevent discrimination. That requires documented policies, audit reports, training records, and evidence of action when problems were identified.
How to Know If It’s Working
You’re making progress when:
Your organisation can articulate its AI governance principles – And they’re not just copied from somewhere else. They’re specific, measurable, and actually guide decisions.
People at all levels can identify where AI is being used – Not just IT. Managers, HR, frontline staff. If people don’t know they’re using AI-assisted tools, they can’t exercise appropriate oversight.
You have evidence of AI recommendations being questioned and overridden – If 100% of AI recommendations are being followed, your “human oversight” isn’t oversight at all.
Bias testing is routine, not exceptional – It’s built into procurement, deployment, and ongoing monitoring. It’s not something you do once when buying a system then forget about.
You can answer the accountability question – For every AI system in use, you can name the person ultimately responsible for its fairness and what happens when it fails.
And that’s not just ethically wrong – it’s legally risky and commercially short-sighted.
The uncomfortable conversations you’re avoiding today become the tribunal cases you’re defending tomorrow. And by then, it’s too late for prevention – you’re into damage limitation.
Start Monday morning. Commission that audit. Ask those hard questions. Build the capability you need.
Because “our supplier says it’s fair” isn’t a defence under the Equality Act 2010.
Read the Complete Series
- Part 1: What Your Board Doesn’t Know About AI Bias
- Part 2: The Myth of Human Oversight
- Part 3: Your Board’s AI Action Plan (you are here)
Your Next Step
Schedule an independent AI equity audit and governance review. Get clear answers about where you’re exposed, what needs immediate action, and how to build long-term capability.
The boards that act now are the ones that avoid the headlines later.
Contact us to see how we can help
References
- Bloomberg Law (2025). “Trump’s Disparate Impact Blow Makes AI Bias Claims Even Tougher.” https://news.bloomberglaw.com/daily-labor-report/trumps-disparate-impact-blow-makes-ai-bias-claims-even-tougher




