Diligent — AI Governance: A Guide for Boards, Risk and Audit Leaders (June 2026)
Tag: S-2026-06-22-diligent-board-ai-governance-guide Type: report (vendor thought-leadership guide, via a secondary aggregator) Author(s): Diligent (GRC platform vendor); relayed by AI Governance Institute Date of source: 2026-06-22 (guide publication date per the secondary article) Date ingested: 2026-06-30 Authority weight: low — vendor content marketing relayed by a secondary aggregator; primary guide not fetched directly; useful framing but self-interested, not an independent standard or audit. Raw file: S-2026-06-22-diligent-board-ai-governance-guide.md. External URLs in the raw stub.
What it claims
Diligent — a GRC platform vendor — published “AI Governance: A Guide for Boards, Risk and Audit Leaders” on 22 June 2026, aimed at board directors, chief audit executives and risk leaders. The guide: allocates AI oversight responsibilities across the three lines of defence; specifies what fairness audits and bias-mitigation programmes should include; sets out third-party AI risk assessment; and addresses the formation of cross-functional AI ethics committees and documentation of leadership roles. It explicitly aligns its recommendations to the EU AI Act, NIST AI RMF and OECD AI Principles, presenting itself as a structured implementation reference for organisations subject to EU AI Act high-risk requirements or facing audit-committee scrutiny on AI risk.
The secondary source frames the value as forcing compliance, risk and internal audit “to delineate ownership of AI controls explicitly, exposing gaps where AI risk management currently sits in no one’s formal mandate.”
Notable quotes
“The guide covers how to allocate AI oversight responsibilities across the three lines of defense … It explicitly aligns its recommendations with the EU AI Act, NIST AI Risk Management Framework, and OECD AI Principles.” — AI Governance Institute, 26 Jun 2026.
“The three-lines-of-defense framing forces compliance, risk, and internal audit functions to delineate ownership of AI controls explicitly, exposing gaps where AI risk management currently sits in no one’s formal mandate.” — AI Governance Institute, 26 Jun 2026.
What’s speculative vs. asserted
- Asserted (verifiable): that Diligent (a GRC vendor) published a board/risk/audit AI-governance guide on 22 Jun 2026 using a three-lines-of-defence frame and mapping to EU AI Act / NIST AI RMF / OECD Principles.
- Vendor thought-leadership (label as such): the adequacy, completeness and correctness of the guide’s recommendations — self-interested content marketing, not an independent standard.
- Secondary-source framing: the “exposing gaps where AI risk sits in no one’s mandate” characterisation is the aggregator’s.
- Not in scope here: any FS-sector-specific content or regulated reference customer (the source’s jurisdiction tag is EU, generic). The EBA/ECB 3LoD-anchoring, SS1/23 and SM&CR read-across is the wiki’s inference (see Three Lines of Defence for AI), not a claim in the source.
Topics this feeds
- Three Lines of Defence for AI — a vendor-side reinforcement of the 3LoD-as-anchor frame and board-accountability/effective-challenge expectations; converges with the EBA/ECB supervisory position already documented there.
Open questions raised
- Does a GRC vendor’s 3LoD/EU-AI-Act mapping match the EBA/ECB supervisory expectation that AI risk be CRO-anchored in the 3LoD, or does it reflect a generic corporate-governance lens?
- Would the guide’s “documented board accountability” structures actually satisfy EU AI Act conformity-assessment or SS1/23 expectations, or is it a literacy aid short of evidence?