TechNews Namibia: Namibia’s Top Tech & Startup News
  • AI
  • Cybersecurity
  • Ecommerce
  • Features
    • Reviews
  • Fintech
  • Technology
  • Telecommunication
  • Forum
  • Jobs
    • Job Dashboard
    • Post a Job
No Result
View All Result
SUBSCRIBE
TechNews Namibia: Namibia’s Top Tech & Startup News
  • AI
  • Cybersecurity
  • Ecommerce
  • Features
    • Reviews
  • Fintech
  • Technology
  • Telecommunication
  • Forum
  • Jobs
    • Job Dashboard
    • Post a Job
No Result
View All Result
TechNews Namibia: Namibia’s Top Tech & Startup News
No Result
View All Result
Home Technology

Your AI policy is more than an IT document: It is a board accountability instrument

by reporter
July 22, 2026
in Technology
58
0

BY Chisom Obiudo

Ask to see your organisation’s AI policy and observe where the request is directed. In many organisations, it goes straight to the IT department because IT prepared the policy.

That is where the governance gap begins. The policy may answer questions within IT’s remit: which tools are technically secure, how access is managed and which security settings are required.

Yet it may leave unanswered the questions that ultimately belong to the governing body: what level of AI risk the organisation is prepared to accept, which decisions must remain subject to human judgement, who has authority to approve a high-risk use case and who is accountable when an AI-assisted decision causes harm.

IT plays an essential role in assessing technical security, access, infrastructure and resilience. However, governance extends beyond its mandate.

Some documents describe how systems operate and are primarily the responsibility of the specialists who manage them. Others allocate authority, set risk boundaries and assign accountability.

These are governance instruments, regardless of which department prepared them. A document’s governance character is determined by its function, not by the department that drafts or maintains it.

A delegation of authority framework remains a governance instrument even when a management function maintains it. The same principle applies to an AI policy drafted by IT.

Once the policy sets out who may decide, which risks may be accepted, and who is accountable for the outcome, it becomes a matter for the governing body.

The limitation is structural rather than a reflection of competence. A department tasked with preparing a policy will naturally focus on matters within its mandate and control.

IT can establish access controls, security standards and approved technical configurations.

It cannot, acting alone, determine the organisation’s risk appetite, assign accountability across business functions, or decide which effects on customers, employees and other stakeholders the organisation is prepared to accept.

Those matters require board-approved direction and coordinated implementation across management, legal, risk, compliance, procurement, human resources, data protection and IT.

King IV remains a recognised corporate governance benchmark in Namibia.

Under Principle 12, the governing body is responsible for governing technology and information in a manner that supports the organisation’s objectives.

King V, which superseded King IV in South Africa for financial years beginning on or after 1 January 2026, builds on this principle by expressly addressing data, emerging technologies and artificial intelligence.

It calls for ethical and trustworthy AI, human oversight proportionate to the level of risk, and ongoing oversight of systems that can change their behaviour.

For Namibian boards, King V does not automatically replace King IV, but it signals the direction in which leading governance practice is evolving.

The board is not expected to operate the technology or understand every detail of a model’s architecture. It is expected to set direction, approve policy, require effective reporting, and satisfy itself that appropriate governance arrangements are in place.

It may delegate aspects of the work, but it remains accountable for the exercise of its responsibilities.

An AI policy developed solely within IT, without the board’s consideration, may leave the governing body unable to demonstrate that it has discharged its oversight responsibility effectively.

This concern is also consistent with directors’ general duties of care, skill and diligence, subject to the law applicable to the organisation. A board cannot demonstrate informed oversight of a material risk it has not examined.

What, then, should a board-grade AI policy address? A practical board-level stress test begins with four questions. Each section addresses a governance decision rather than a technical setting.

Approval of tools and use cases is the first control.

Who may introduce a new AI tool or approve a new use case, and on what criteria? The same tool may pose a low risk when used to draft an internal agenda and a high risk when used to screen job applicants or assess creditworthiness.

In many organisations, however, publicly available AI tools can be accessed without going through procurement or formal approval. Where a policy fails to establish an approval route, the decision may be made informally, often by someone who lacks the authority or information needed to assess its consequences.

The handling of confidential data is a significant source of day-to-day risk.

What information may never be entered into a public or unapproved AI tool? The list may include client files, personal data, unpublished financial information, price-sensitive information and legally privileged material.

For example, a staff member may paste a client’s contract into a free chatbot to obtain a quick summary.

If the tool has not been assessed, the information may leave the organisation’s controlled environment and be processed, retained or transferred under contractual terms that have not been reviewed.

If the client asks whether confidentiality was preserved, the organisation may be unable to provide a reliable answer.

If a regulator asks which AI-specific control the staff member breached and the policy is silent, the board may be unable to identify a clear rule governing that conduct. Such silence indicates a governance gap the organisation should have anticipated.

Human oversight distinguishes AI-supported decision-making from fully automated decision-making.

Where AI output may affect a person’s finances, employment, credit, access to services, or legal rights, the policy must identify the accountable decision-making role and the required level of human review.

Consider a lender whose screening tool disproportionately declines applicants from a particular area, or an employer whose shortlisting tool disadvantages older candidates.

When an affected person asks for an explanation, ‘the system said so’ is not a responsible answer to a regulator, a court or the public.

The policy should identify the role responsible for each consequential decision, the information to be examined, and the circumstances under which the system’s recommendation may or must be overridden.

Accountability arrangements must be established before an incident occurs.

Who investigates when an AI-assisted decision produces a harmful or erroneous outcome? Who has the authority to suspend the system? Who must be informed, how quickly must the matter be escalated to the board, and who determines whether customers, affected individuals or regulators must be notified?

The policy should also address the preservation of records, remediation and lessons learned. No responsible policy should assume that an AI system will never fail.

These four questions are a starting point rather than a complete policy framework. Depending on the organisation’s context, a board-grade policy should also address scope and definitions; an inventory of AI systems and use cases; risk classification; prohibited uses; procurement and vendor due diligence; pre-deployment testing; staff responsibilities and training; monitoring and record-keeping; exceptions; periodic review; and assurance.

The level of detail should be proportionate to the organisation’s size, activities and exposure, but the policy should leave no ambiguity about where authority and accountability lie.

The board need not draft the policy itself. Its role is to examine the document as a regulator, a court or an affected stakeholder might, with particular attention to gaps, ambiguities and unallocated responsibilities.

An approved AI tool can support a preliminary structural review by checking whether the document addresses the organisation’s material governance questions. The board may ask management, supported by the company secretary, legal adviser and the functions responsible for technology or risk, to conduct the review and table the findings at the next meeting.

Before conducting the review, remove all confidential, privileged and personal information from the policy unless the AI environment has been expressly approved to process such information. The person conducting the review must also use an AI tool approved by the organisation. Otherwise, the review may itself create the risk the policy is intended to prevent.

If your organisation already has an AI policy, use the following prompt in your preferred AI tool (ChatGPT, Claude or Gemini) to support that preliminary review:

Review this draft AI policy from a corporate governance perspective. Assess whether it addresses approval of AI tools and use cases; confidential and personal data; human oversight of consequential decisions; and incident accountability, escalation and remediation. Identify gaps in the AI inventory, risk classification, prohibited uses, vendor due diligence, testing, training, monitoring, record-keeping, exceptions, review and assurance. For each gap, explain its significance to the board, assess the risk, identify the responsible function and propose plain-language wording. Do not invent facts.

Because the output is preliminary, the organisation must validate any identified gaps against its legal obligations, operating context and risk appetite. Responsibility for final policy decisions remains with the governing body and cannot be delegated to IT or an AI tool.

Following the preliminary review, the board should ask management one question: If a staff member entered a client’s file into a free AI tool this morning, which clause of our policy would apply, who would be notified, and what action would follow? If management cannot give the board a clear and prompt answer, the policy is not yet functioning as an effective governance instrument.

Some organisations have an AI policy, but far fewer have one designed to withstand scrutiny following a serious incident. When an AI system produces a discriminatory outcome or causes a data leak, the policy and records of its implementation should help demonstrate to regulators, courts and the public that the board had already set appropriate boundaries, assigned decision-making authority and established effective oversight.

A basic policy shows that the organisation is aware of AI. A governance-ready policy shows that the board has governed its use. The difference becomes apparent when something goes wrong, but the necessary arrangements must be in place and operating long before the incident occurs.

 

Chisom Obiudo is an admitted legal practitioner of the High Court of Namibia specialising in corporate governance and AI governance. She facilitates AI governance training for boards and delivers AI professional skills training. She also serves on the National Artificial Intelligence Technical Advisory Committee established by the National Commission on Research, Science and Technology (NCRST), with a focus on law and governance. She can be contacted at chisomokafor11@gmail.com

Recommended For You

MTC expands 5G coverage to 17 locations across Namibia

MTC expands 5G coverage to 17 locations across Namibia

by reporter
September 28, 2026
0

MTC’s 5G network now covers 17 towns and locations across Namibia after the telecommunications operator connected Grootfontein, Mariental, Okahandja, Otjiwarongo and Tsumeb under the second phase of its...

Standard Bank Namibia bets on AI to drive digital banking innovation

Standard Bank Namibia bets on AI to drive digital banking innovation

by reporter
September 24, 2026
0

Standard Bank Namibia is stepping up its focus on artificial intelligence as it looks to use emerging technologies to improve digital banking, expand financial inclusion and develop solutions...

60 Namibians selected for Bloomberg data-driven journalism programme

60 Namibians selected for Bloomberg data-driven journalism programme

by reporter
September 22, 2026
0

Sixty Namibian professionals have been selected from more than 800 applicants for a seven-month Bloomberg Media Initiative Africa (BMIA) programme aimed at strengthening data analysis and digital financial...

Namibia reports 535,204 cyber vulnerabilities in Q4

Cyber threats surge 57% as Namibia’s digital footprint expands

by reporter
September 17, 2026
0

Namibia recorded a 57% increase in cyber threat events during the second quarter of 2026, highlighting growing security risks as more consumers and businesses connect to digital services....

Big changes coming to FNB Namibia’s eWallet

Big changes coming to FNB Namibia’s eWallet

by reporter
September 13, 2026
0

Major changes are coming to FNB Namibia’s eWallet, with the bank working on a “reimagination” of the mobile money service that is expected to significantly expand what customers...

Related News

Your website is now a source, not a destination

Your website is now a source, not a destination

September 2, 2026
Shadow AI, Agentic AI, and the work Namibian boards haven’t started

AI can copy your voice. How can Namibia protect creative livelihoods?

September 24, 2026
Group of eight professionals in business attire on a stage beside an easel with a DigiNam sign, posing for a photo at a formal event.

Namibia legally recognises electronic signatures under new framework

August 31, 2026

Browse by Category

  • AI
  • Cybersecurity
  • Ecommerce
  • Features
  • Fintech
  • Technology
  • Telecommunication
  • Jobs
  • Job Dashboard
  • Post a Job
  • Register
  • Log In

Welcome Back!

Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
OR

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Jobs
  • Job Dashboard
  • Post a Job
  • Register
  • Log In

Skip to toolbar
  • About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
  • Log In
  • Register