What a board should ask before approving an AI investment
Most AI proposals that reach a Mauritian board arrive in one of two forms: a vendor-led pitch for a customer service assistant, document tool or forecasting module, or an internal initiative from a manager who has been experimenting with a generative AI tool and wants budget to do it properly. Both deserve a fair hearing. Neither deserves approval on the strength of a slide deck.
A board does not need technical expertise to govern an AI investment well. It needs a disciplined set of questions, a clear view of who is accountable, and an insistence on evidence rather than assurance. This guide sets out twelve questions under four headings, explains why each matters and what a weak answer sounds like, summarises what the National Code of Corporate Governance, the MIoD Directors Forum and the Financial Services Commission expect of boards, and closes with a one-page question sheet. It is written for directors of SMEs and mid-sized organisations that may have no data team and no compliance department; where a point applies only to FSC licensees or Code-reporting entities, it says so.
AI needs its own questions because, unlike conventional software, an AI system is probabilistic: usually right, sometimes wrong, and occasionally wrong in ways that are hard to detect. Its behaviour can change as data changes, it may engage the Data Protection Act 2017, and its value depends on whether processes, data and people are ready to use it.
Part one: the problem and the decision
1. What specific problem does this solve, and how do we know it is real?
An AI investment should begin with a business problem, not a technology. Management should describe the process that is slow, costly or error-prone, quantify it from the organisation’s own records, and explain why AI is a better answer than a process fix, a hire or simpler software.
A weak answer sounds like: “Our competitors are using AI and we risk being left behind.” That may be true, but it is not a problem statement.
2. What will the AI actually make or perform, and who remains accountable?
The board should understand exactly where the AI sits in the workflow. Does it draft, recommend, classify, prioritise or decide? Is a person reviewing every output, a sample, or none? Which named role owns the outcome when the AI is wrong?
A weak answer sounds like: “The system will handle customer enquiries.” That does not say whether it answers customers directly, drafts replies for staff, or only routes tickets, and the difference determines the risk profile.
3. What would we do instead, and what happens if we do nothing?
Every investment has alternatives, including doing nothing, doing something smaller, or waiting while the market matures and prices fall. The board should see those alternatives compared honestly.
A weak answer sounds like: “There is no alternative.” A stronger answer shows a smaller pilot with a defined stop point as one of the options.
Part two: readiness and data
4. Is our data good enough, and do we have the right to use it this way?
Management should be able to say where the data lives, how complete and accurate it is, who owns it, and whether it contains personal data. If it does, the organisation needs a lawful basis to process it for this new purpose, grounded in the Data Protection Act 2017 rather than a vendor’s reassurance.
A weak answer sounds like: “The vendor says the system works with any data.” The vendor has not seen your data.
5. Are our processes and people ready to use it?
An AI tool placed on top of an inconsistent process automates the inconsistency. The MIoD publication discussed below makes the point plainly: organisations should assess whether the internal processes that generate their data are fit for AI, and redesign them if not. The board should also ask who will use the system daily, what training they will receive, and how their roles change.
A weak answer sounds like: “Staff will pick it up quickly.” Adoption is the most common point of failure for SME technology projects.
6. What does this cost over three years, including what is not in the quote?
The licence fee is usually the smallest number. Integration, data preparation, staff time, training, monitoring, model updates and eventual replacement are the larger ones. The board should see a three-year total cost of ownership and the assumptions behind the savings.
A weak answer sounds like: “The subscription is only Rs X per month.” A stronger answer shows internal time as a cost line, because it is one.
Part three: risk, law and accountability
7. What can go wrong, how would we know, and what is the plan?
Management should present a short, honest risk register: wrong outputs, biased outputs, data leakage, over-reliance by staff, vendor outage, reputational harm. Each should have a detection mechanism and a response. The FSC guidance, though it applies to licensees, offers useful vocabulary for any organisation: monitoring of inputs and outputs, and the ability to switch the system off under defined conditions.
A weak answer sounds like: “The system is very accurate.” Accuracy is a percentage. Ask what happens in the remaining cases.
8. Does this involve automated decisions about individuals, and has a DPIA been done?
This is the question most likely to expose a legal gap.
Legal requirement. Under section 38 of the Data Protection Act 2017, a data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them. The exceptions are narrow: necessity for a contract, authorisation by law with safeguards, or explicit consent. Where an exception applies, the controller must still inform the person of the processing and its envisaged effects and implement suitable safeguards. Section 38 also prohibits automated evaluation of personal aspects based on special categories of data.
Legal requirement. Under section 34, where processing is likely to result in a high risk to the rights and freedoms of data subjects, a data protection impact assessment must be carried out before the processing begins. The Act specifically lists systematic and extensive evaluation of personal aspects based on automated processing on which significant decisions are based. Section 22 makes performing such an assessment a duty of every controller.
A weak answer sounds like: “It only makes recommendations, a human always signs off.” If so, the board should ask for evidence that the review is real rather than a rubber stamp. As a comparator only, the UK Information Commissioner’s Office has taken the position that human involvement must be meaningful for a decision to fall outside the solely automated category. No published position from the Mauritian Data Protection Office on nominal human involvement was found at the time of writing, so the board should not assume either leniency or strictness.
9. Who is accountable for this system across its life?
Responsibility for an AI system often starts with whoever bought or built it and drifts, as the FSC guidance observes, to business units as the system evolves. The board should insist on a named executive owner, a description of how ownership transfers when roles change, and a statement of which committee will receive reports on it.
A weak answer sounds like: “IT will look after it.” IT may host it. Someone in the business must own its outcomes.
Part four: vendor, exit and measurement
10. What do we know about the vendor, and what have they committed to?
Most SMEs will buy rather than build. The board should know where the vendor and the organisation’s data will be located, whether that data will be used to train the vendor’s models, what security certifications the vendor holds, and what the contract says about liability, service levels and audit rights. The FSC guidance notes that third-party AI often comes with limited access to code or training data provenance, and that firms should secure documentation and assurances about model behaviour.
A weak answer sounds like: “They are a well-known company.” Well-known companies still have standard terms that favour them.
11. How do we get out, and what would it cost?
The board should ask what happens to the organisation’s data and configured workflows if the contract ends, the vendor fails, or the organisation wants to switch. Export formats, transition assistance and notice periods matter more than they appear to at signing.
A weak answer sounds like: “We do not expect to leave.” The question is whether the organisation can.
12. How will we measure whether it worked, and when do we scale, fix or stop?
The board should approve the measurement plan alongside the investment: a few metrics tied to the original problem, a baseline taken before go-live, a review date, and explicit criteria for scaling, remediating or stopping. The MIoD publication says boards should be prepared to scale successful initiatives and discontinue those that do not deliver value.
A weak answer sounds like: “We will review it in a year.” A stronger answer names the metric, the baseline, the review date and the result that would lead to stopping.
What the National Code of Corporate Governance expects of boards
The National Code of Corporate Governance for Mauritius (2016) is not a statute. It applies on an apply-and-explain basis: entities within its scope are expected to apply all eight principles and explain in their annual report how they have done so. The Code states that law and regulation take precedence over it where they conflict.
Who it covers. The Code applies to public interest entities as defined in the Financial Reporting Act 2004 and to public sector organisations listed in that Act’s Schedule; other companies are encouraged to consider it where relevant. Many SMEs are not obliged to report against it, but its guidance on technology is a sound benchmark for any board.
Code principle, apply-and-explain. Principle 4 (Director Duties, Remuneration and Performance) states that the Board is responsible for the governance of the organisation’s information, information technology and information security. The implementation guidance asks boards to oversee information governance, to ensure that IT systems lead to business benefits and create value, to delegate to management a framework for information, IT and information security governance, and to monitor and evaluate significant investments in information technology. It encourages an IT steering group with business and IT representation, and suggests boards consider independent assurance on their information governance. The reporting guidance asks for a description of how the board oversees information governance and monitors significant IT expenditure.
Code principle, apply-and-explain. Principle 5 (Risk Governance and Internal Control) states that the Board should be responsible for risk governance, ensure a comprehensive and robust system of risk management, and maintain a sound internal control system.
For a reporting entity, an AI investment is therefore a board matter twice over: as a significant IT investment to be monitored and evaluated, and as a source of risk to be governed.
What the MIoD publication on AI covers
In December 2025 the Directors Forum of the Mauritius Institute of Directors, in collaboration with PwC Mauritius, published Position Paper No. 10, “Artificial Intelligence Promotion and Governance”. The publication page describes it as a strategic perspective on the promotion and governance of AI, offering boards a guide to its opportunities and to the ethical, legal and operational risks involved.
The paper covers opportunities, risks, AI governance, the role of the board and an implementation guide for directors. On risks it addresses bias in training data, cybersecurity exposure, data privacy, and governance mismatches where AI oversight is siloed from finance, risk and sustainability. On governance it proposes that oversight extend across the three lines of defence, that organisations conduct algorithmic impact assessments before deployment, and that boards consider the environmental footprint of AI infrastructure. It presents a four-stage maturity model (ad hoc, reactive, proactive, strategic), drawn from the California Management Review. The implementation guide lists education, strategic alignment, talent, regulatory compliance, operational readiness and stakeholder engagement as areas a board must monitor, and recommends that boards assess their own AI knowledge and fill gaps through training, AI-literate directors or advisers and regular briefings.
It is a position paper, not a code or regulation. Its value is as a structured checklist from a local body that understands the Mauritian governance context.
What the FSC guidance expects of licensee boards
This section applies only to FSC licensees.
In September 2025 the FSC published Fintech Series Guidance Notes No. 4, “Principles for the Responsible Use of Artificial Intelligence in Financial Services”, addressed to insurance, wealth management and non-banking financial institutions. It states that its nine principles are non-binding, that it is not a prescriptive or exhaustive checklist, and that it is not legal advice. It is to be read with the relevant Acts and the Data Protection Act 2017.
Guidance, not statute. The governance section states that AI should not change existing supervisory expectations: boards should continue to ensure a clearly defined and documented governance framework with effective separation between oversight and management. Accountability should be defined across the whole lifecycle, from design and procurement to decommissioning, possibly through a responsibility matrix with a structured handover. Where AI is used in critical decisions, board members and senior management should understand its risks and limitations well enough to assess its outputs critically, and where AI significantly affects consumers there should be sufficient expertise at board level. Because third-party AI limits what oversight can see, licensees should consider system redundancy, mechanical monitoring of inputs and outputs, and kill switches.
Legal requirement (restated in the guidance). The guidance also restates the licensee’s obligations under sections 34 and 38 of the Data Protection Act 2017: a DPIA before any AI system likely to present a high risk, and for automated decisions, disclosure, meaningful information on the logic, and a route to human intervention. Those obligations come from the Act, not the guidance. A licensee board should expect to be asked how it satisfied itself on expertise, accountability and oversight; the question sheet below is a starting point for that record.
The evidence management should bring to the board
Consultaix recommendation. Management should table:
- A one-page problem statement with baseline figures from the organisation’s own records.
- A workflow diagram showing where the AI acts and where humans review.
- A data inventory: sources, quality, personal data flagged, lawful basis stated.
- A DPIA, or a documented conclusion that one is not required.
- A three-year total cost of ownership including internal time.
- A short risk register with detection and response for each item.
- A vendor summary: location, data and training terms, security posture, liability, exit terms.
- A named executive owner and the committee that will receive reports.
- A measurement plan with metrics, baseline, review date and stop criteria.
If management cannot produce these, the right decision is usually a bounded pilot, conditional on the missing evidence being produced before any wider commitment.
One-page question sheet
| # | Question | Evidence to request |
|---|---|---|
| 1 | What specific problem does this solve, and how do we know? | Problem statement with baseline data |
| 2 | What will the AI make or perform, and who is accountable? | Workflow diagram, named owner |
| 3 | What are the alternatives, including doing nothing? | Options comparison |
| 4 | Is our data good enough, and may we use it this way? | Data inventory, lawful basis |
| 5 | Are processes and people ready? | Process review, training plan |
| 6 | What is the three-year cost, including internal time? | Total cost of ownership schedule |
| 7 | What can go wrong, how would we know, what is the plan? | Risk register with detection and response |
| 8 | Are there automated decisions about individuals? Is a DPIA done? | DPIA or reasoned exemption |
| 9 | Who owns this across its life, and who reports to the board? | Responsibility matrix, reporting line |
| 10 | What do we know about the vendor and what have they committed to? | Contract summary, data terms |
| 11 | How do we get out, and at what cost? | Exit and data export terms |
| 12 | How will we measure it, and when do we scale, fix or stop? | Metrics, baseline, review date, stop criteria |
Record the answers at the approval meeting and revisit the sheet at the review date.
Where Consultaix fits
Boards that want standing, independent advice on AI decisions rather than a one-off review can engage Consultaix through the Fractional Advisor model, which places an adviser alongside the board and executive on a retained basis to challenge proposals, review evidence and attend the meetings where AI investments are decided. Our AI Governance Advisory service helps organisations build the accountability, risk and data protection arrangements these twelve questions assume. Where a board is unsure whether the organisation is ready to invest at all, the AI Readiness Assessment gives a structured answer.
Sources
- The National Code of Corporate Governance for Mauritius (2016), National Committee on Corporate Governance, 2016: https://www.nccg.mu/ and https://www.nccg.mu/sites/default/files/2021-01/the-national-code-of-corporate-governance-for-mauritius_2016.pdf
- Publication No 10: Artificial Intelligence Promotion and Governance, MIoD Directors Forum in collaboration with PwC Mauritius, December 2025: https://www.pwc.com/mu/en/publications/miod-publication-no-10.html
- Fintech Series Guidance Notes No. 4, Principles for the Responsible Use of Artificial Intelligence in Financial Services, Financial Services Commission Mauritius, September 2025: https://www.fscmauritius.org/media/206401/guidelines-on-responsible-use-of-ai.pdf
- Data Protection Act 2017 (Mauritius), sections 22, 34 and 38: https://www.fscmauritius.org/media/105843/the-data-protection-act-2017.pdf
- Automated individual decision-making, Data Protection Office Mauritius: https://dataprotection.govmu.org/Pages/Data%20Subjects/Automated-Individual-decision-making.aspx
- Data Protection Impact Assessment and high-risk operations, Data Protection Office Mauritius: https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Document%20%26%20Forms/Data-Protection-Impact-Assessment-and-High-Risk-Operations.aspx
- Minimum Viable AI Governance Framework for SMEs, Faaleh M. Sookye, faaleh.com (starting point reading): https://faaleh.com/insights/minimum-viable-ai-governance-framework-for-smes