St Paul's Cathedral seen from the Millennium Bridge, the crowd in motion around it

Boards are deciding about AI before anyone can be certain.

The AI Risk Dialogue is a thematic, board-level review of AI uncertainty, dependency and control, led personally by Richard Anderson.

St Paul's from the Millennium Bridge

The questions only the board can answer

Boards are approving AI tools, partnerships and investments while the consequences for judgement and accountability are still emerging. Directors may agree that AI risks are “controlled” without sharing an understanding of what that means in practice, or of the dependencies they are taking on.

The real question is whether your organisation is taking on exposure faster than you and your people can understand it, challenge it and keep control of it.

Policies, inventories and technical reports have their uses, but they rarely show where authority really sits, or which dependencies are becoming hard to undo. Those answers live in the conversations around the board table.

AI risk isn’t one thing, either. Some of it you already feel directly: errors, poor customer outcomes, fraud. Some can be settled with evidence: model performance, bias, security, data quality. And some is genuinely unresolved. Force all three into one risk score and you get the appearance of control, not the reality of it.

A layered, multiple-exposure photograph of the Shard and surrounding buildings at dusk
The Shard, composite

What do we actually know?

For each significant use of AI, separating what you have experienced directly, what evidence can settle, and what remains genuinely uncertain. Then asking what evidence would change your decision.

Do the right conversations happen?

Who holds the knowledge, who challenges it, and whether bad news reaches the people who can act on it. Whether your risk and technology teams mean the same thing by the same words, and whether challenge survives a commercial push to say yes.

What could you not undo?

Where your AI capability really depends on models, cloud platforms, data and specialist suppliers, and whether you could cope if one changed its terms tomorrow. The aim isn’t zero dependency, but dependency you could still walk away from.

A session or a full review

It can start with a single board session, or run as a three-to-four-week review built around your board’s actual concerns: a scoping conversation, a look at what is already on paper, confidential interviews with directors and executives, and a board workshop to test the findings. You are left with a clear view of what is known and still uncertain, where challenge gets stuck, what you depend on, and a practical 90-day action plan.

It is for boards moving from AI experiments to AI that actually matters, especially where supplier concentration, agentic AI or hard-to-rebuild capability is a concern. It is not model testing, cyber assurance or legal advice: where those are needed, I will say so plainly and help you find the right specialist.

Evening crowds moving through St Martin's Court under a lit canopy
St Martin's Court, Covent Garden

A personal service

To me it’s all about delivering a highly personal service. At AndersonRisk I am not building a big, global consulting practice. I’m not leveraging juniors, and I’m not fixated on utilisation rates or timesheets.

I work with boards that see risk as a boardroom topic, and who value a service delivered by me, sometimes alongside one or two trusted people I have worked with for years. The questions that interest me need conversations with the board, the executive and people further into the organisation, where discussion matters more than quantification, and the nuances of governance matter more than numbers and spreadsheets.

I also advise boards on strategic risk and board-level risk governance.

I encourage my clients to view risk through a completely different lens. Rather than start with risk registers and other backward-looking tools, we look at risk through a set of finely balanced considerations. This often leads to the discovery of significant risks which were not even previously in view.
Richard Anderson
Portrait of Richard Anderson

Richard Anderson

I advise boards on AI risk governance, helping directors examine the judgements and dependencies that technical assurance alone cannot resolve.

I am not an AI engineer. My perspective comes from two places. As a non-executive director, I have been part of boardroom discussions about AI and AI risk, including how it fits within the board’s risk appetite. And I have built with it: at RiskMetrica, my co-founder has led the technical development while I have worked on turning ideas about risk into technology a business can use, and at DigiCheques we have tested strategy through conversations across several AI models. That experience has changed the questions I ask: at what point does a useful capability become a dependency, who understands it well enough to challenge it, and does the board know what it would take to change course?

I am an experienced board chair, committee chair and non-executive director, with a background as a Chartered Accountant and risk consultant. My board work has been largely in payments, fintech and banking, often in regulated and critical-infrastructure organisations going through major change, working closely with regulators and government.

I was a partner at Coopers & Lybrand and then PwC from 1993 to 2001, and led the strategic risk practice in EMEA. I chaired the Institute of Risk Management from 2011 to 2014, the Pay.UK Risk Committee from 2018 to 2021, and Banking Competition Remedies from 2020 to 2023.

I wrote a 2009 report for the OECD on risk management and corporate governance in banks, and was principal author of the Institute of Risk Management’s guidance on risk appetite and tolerance (2011), and co-authored its guidance on risk in the extended enterprise (2014). My work on risk appetite and risk culture has taken me to conferences from the UAE to Colombia. I have worked with large global corporations, small start-ups, INGOs and not-for-profit organisations, in the UK and across many countries.

Writing and the podcast

I write about risk appetite, uncertainty and AI on Substack, and talk with people who think hard about risk on The Risk Appetite Podcast.

RiskMetrica

I am a co-founder of RiskMetrica, home of the Risk Intelligence Operating System (RIOS), for organisations that want continuing insight into their risks rather than a single review.

A London Underground train at a crowded platform, blurred with movement
London Underground

Talk to Richard

If you are wondering whether your board shares a common view of its AI risks, I would be glad to talk it through, with no commitment on either side.