[Governance]

Risk Committee playbook

Model risk, autonomy, and third-party exposure.

A reference agenda for the signals, instruments, and reporting cadence a Risk Committee needs as AI deployment expands.

Record type
Reference playbook
Effective
28 July 2026
Scope
Board committee use
Review basis
AGS v4.1

Question one

What this committee oversees.

The Risk Committee oversees enterprise exposure created by AI systems, including autonomy, model behavior, resilience, concentration, third-party dependence, and incident readiness.

Risk owns exposure and response. Audit owns the assurance process and disclosure controls. Technology owns the technical architecture unless the board charter assigns those duties differently.

Reference boundary reviewed 28 July 2026. Committee authority remains subject to each company's governing documents.

Question two

What it should review.

SignalAlpha surfaceCadenceWorkflow state
Agentic autonomy exceeding approved limitsTerminal · System registerWeeklyReview
Model inventory drift against the approved registerTerminal · Model inventoryWeeklyMonitor
Third-party AI exposure in the vendor baseRatings · Supplier viewMonthlyReview
Incident and near-miss volume with time to containmentTerminal · Incident logWeeklyMonitor
Conformity gaps against NIST AI RMF and ISO/IEC 42001Standard · Criteria mappingQuarterlyReview
Concentration across model providersTerminal · Provider mixQuarterlyEscalate

Workflow states indicate reference review priority. They are not live client data or a statement about any company.

Question three

What Alpha surfaces for it.

Exposure register

Material AI systems, owners, autonomy limits, dependencies, controls, and current exceptions.

Incident record

Events and near misses connected to containment time, decision owners, and corrective action.

Provider concentration view

Operational and contractual dependence across model, infrastructure, and data providers.

Question four

What it receives.

DeliverableCadenceFormatChannel
Risk exception packQuarterlyBoard briefBoard package
Threshold breach alertContinuousAlertTerminal
Incident reviewOn eventDecision recordCommittee portal
Provider positionQuarterlyBenchmarkCommittee portal