
Why artificial intelligence has already entered your organization — and what your board can do about it
There is a particular kind of risk that never appears on a risk register, because nobody ever made a decision that would have put it there.
No paper went to the board. No business case was approved. No vendor was onboarded, no policy was amended, no control was designed. And yet the exposure is real, it is growing weekly, and if a regulator, an insurer or a correspondent bank asked about it tomorrow, most organizations in this region would not be able to answer.
Artificial intelligence is in your organization right now. The question is not whether to adopt it. That decision has already been made — quietly, in dozens of small acts, by people who were simply trying to do their jobs faster.
The only open question is whether it is governed.
1. The adoption nobody voted on

Every previous technology wave arrived through the front door. Core banking systems, ERP platforms, cloud migration — each came with a project, a budget, a steering committee and an implementation partner. Governance was imperfect, but it was at least present, because the technology could not arrive without someone signing for it.
AI is different. It arrives without a signature.
An accounts officer pastes a draft into a free chatbot to tidy the language. A marketing assistant uploads a customer list to generate segments. A branch manager uses a transcription tool for meeting notes. A software vendor pushes an update that adds an “AI assistant” to a system your organization has used for six years. None of these events triggers a governance process. Collectively, they constitute an adoption programme that no one designed and no one owns.
The distinguishing feature of AI risk is not its severity. It is its invisibility.
This is why the standard management response — “we’ll look into AI next year” — misreads the situation entirely. There is nothing to look into next year. There is something to map this quarter.
2. The four doors

When we begin an AI exposure review, we find capability entering the organization through four distinct routes. Most executives are aware of one of them.
The first door is employee use. Staff using public generative AI tools on work material — sometimes on personal devices, sometimes on corporate ones, almost always without a policy that says what may and may not be entered. This is the door most organizations think about, and it is the one they most often try to close with a blanket prohibition. We will come to why that rarely works.
The second door is vendor platforms. Software you already licence, which has quietly acquired AI features. Your HR system now drafts job descriptions. Your helpdesk suggests responses. Your accounting package summarizes transactions. Nobody procured these features. They arrived in a release note. The contract you signed three years ago says nothing about how your data may be used to serve them.
The third door is embedded intelligence. AI operating inside products where it is not marketed as AI at all — fraud scoring, credit decisioning, network monitoring, spam filtering, customer analytics. Some of these have made consequential decisions about your customers for years.
The fourth door — and the one that will define the next twenty-four months — is agency. Tools that no longer just answer, but act: scheduling, sending, filing, transacting, calling other systems on your behalf. The governance question shifts at this point from what did it say to what did it do, and under whose authority.
An organization that has policed only the first door has not addressed its AI exposure. It has addressed the fraction of it that was visible.
3. This is a governance problem wearing a technology costume

There is a strong institutional reflex to treat AI as an IT matter, delegate it to the IT manager, and await a report. That reflex will fail, for a straightforward reason: almost none of the consequential decisions are technical.
Whether confidential client information may be entered into a third-party model is not an IT decision. It is a confidentiality and data protection decision.
Whether an AI-generated output may be relied upon in a customer communication, a regulatory filing or a credit assessment is not an IT decision. It is a decision about the standard of care your organization owes.
Whether a vendor may use your operational data to improve its models is not an IT decision. It is a contracting decision with competitive and privacy consequences.
Whether an automated agent may execute a transaction without human review is not an IT decision. It is a delegation of authority — and delegations of authority belong to boards.
IT can tell you what the technology does. Only governance can tell you what your organization has permitted.
4. The six questions

In our experience, an organization’s AI position can be diagnosed with six questions. They are not technical. Any director can ask them, and any competent management team should be able to answer them with evidence rather than reassurance.
- Where is AI being used across the organization? Not where it is approved — where it is used.
- What data is being entered into AI systems? Client data? Employee data? Financial records? Anything regulated?
- Are AI tools approved, monitored and governed? By whom, under what policy, with what record?
- Are AI vendors using organizational data? What do the contracts actually say — not what does the salesperson say?
- Are cybersecurity controls adequate for AI-enabled systems? Including exposures that did not exist three years ago, such as prompt injection and unauthorized tool use.
- Can management provide assurance to the board? Not an opinion. Assurance — supported by evidence a third party could examine.
Where these questions cannot be answered with evidence, the organization is not making a decision about AI risk. It is inheriting one.
5. Why “we have a policy” is not an answer

Many organizations, prompted by a headline or a peer, have issued an AI policy. Often it is a single page. Sometimes it consists of one sentence: staff must not use AI tools for company work.
Three problems follow.
A prohibition without visibility is not a control. If you have banned AI use but cannot say whether it is occurring, you have not reduced your exposure. You have relocated it — from a governed activity to a concealed one. Staff who believe a tool makes them better at their job will generally keep using it, and will now do so without telling anyone. Prohibition converts a manageable risk into an unmeasurable one.
A policy without classification treats all use as identical. Using a language model to improve the tone of an internal memo and using one to draft advice to a client are not the same act, and should not attract the same rule. Policies that fail to distinguish between them are either so restrictive that they are ignored, or so permissive that they protect nothing.
A policy without ownership decays. If no named executive owns AI risk, no one updates the policy when a vendor adds a feature, no one reviews the tool register, and no one reports to the board. Within two quarters the document describes an organization that no longer exists.
The test of an AI policy is not whether it exists. It is whether anyone could produce evidence that it is being followed.
6. The question nobody asks the vendor

Of all the exposures we encounter, the one most consistently unexamined is contractual.
When a platform adds AI capability, several questions become material that were not material at signing. Is your data used to train the provider’s models, or the models of its subprocessors? Where is it processed, and under whose jurisdiction? Is the AI feature delivered by the vendor, or by a fourth party the vendor has integrated? What are your rights if the output is wrong and you relied on it? Can the feature be disabled — and if you disable it, does the service still function?
Most contracts in force across the region today were signed before these questions existed. That is not a failure of management; it is a consequence of timing. But it does mean the answer to “are we covered?” is almost certainly unknown rather than yes.
For institutions subject to third-party risk expectations — financial institutions above all — this is the gap most likely to be probed first, because it is the one a regulator can examine without any technical expertise at all. They simply ask to see the clause.
7. From exposure to a governed position

The purpose of an AI governance and cyber risk readiness assessment is narrow and practical. It is not to advise you on AI strategy, and it is not to sell you a platform. It is to establish, with evidence, four things:
What is actually in use. A discovery exercise across business units covering formal and informal use, vendor systems, embedded features and emerging agents. This almost always surprises the executive team, and the surprise is the point.
What it touches, and what that is worth. Each use case classified by business impact, data sensitivity, regulatory exposure, cyber risk, autonomy level and potential stakeholder harm — so that attention flows to the five things that matter rather than being spread evenly across fifty that do not.
Where the controls do not reach. The cyber and data protection gaps specific to AI-enabled systems: data leakage, prompt injection, unauthorized tool use, insecure integrations, access control weaknesses, vendor exposure.
What to do first. A prioritized remediation roadmap with named owners and target dates — not a list of recommendations, but a sequence of commitments that a board can track to closure.
The output is a document management can act on and the board can rely on. In a well-run engagement it takes two to four weeks, and it does not compete with the operating calendar.
8. What the board should receive

Directors are entitled to be sceptical of technology reporting, because so much of it is unreadable. The remedy is to specify the format in advance.
At minimum, an AI readiness report should give the board an exposure summary in plain language, a risk heat map plotting use cases by impact and likelihood, a maturity rating across the dimensions that matter — policy and approval, data protection, cyber controls, vendor oversight, board reporting — and a remediation roadmap with owners and dates.
The maturity rating deserves particular attention. Its value is not the score. Its value is that it converts an anxious, unbounded question — are we exposed? — into a bounded one: we are here, the next level requires these four specific things, and they are owned by these three people.
That is the difference between a board that is worried about AI and a board that is governing it.
9. Three objections worth answering

“We are too small for this.” Size determines the scale of the exercise, not the existence of the exposure. A twelve-person firm holding client financial data has the same confidentiality obligation as a twelve-hundred-person one; it simply has fewer places to look. Smaller organizations are frequently more exposed, because informal tool use is easier and procurement discipline is lighter.
“We have banned it.” Then the first finding of the assessment will tell you whether the ban is being observed. That is a useful thing to know, and it is not knowable from inside the assumption.
“Our vendors handle this.” Some of them do. The contract will say which. Third-party assurance is not a reason to avoid the question — it is the answer to one part of it, and it needs to be evidenced like any other control.
10. The starting point

The organizations that will handle this well are not the ones with the most sophisticated technology. They are the ones that moved from assumption to evidence early, while the exercise was still small enough to be done calmly.
That work begins with a single, unglamorous step: finding out what is actually happening. Not what policy says should be happening. Not what the executive team believes is happening. What is happening.
Everything else — the policy, the classifications, the contract amendments, the board reporting cycle — follows from that map, and none of it can be built without it.
AI adoption in your organization was not a decision. Governing it will have to be.
Ten questions for your next board or audit committee meeting

- Do we have a current inventory of AI tools in use across the organization?
- When was it last updated, and by whom?
- What categories of data are permitted to be entered into AI systems, and where is that written?
- Which of our existing vendor contracts address AI data use?
- Who owns AI risk by name, and to which committee do they report?
- Have our cyber controls been assessed against AI-specific exposures?
- What is our position on autonomous agents executing actions without human review?
- If a client asked whether their information had been processed by an AI system, could we answer?
- What is our AI governance maturity level, and what would move us up one?
- When will this appear on the board agenda as a standing item rather than a discussion?
Frequently asked questions
How long does an AI Governance & Cyber Risk Readiness Assessment take?
Typically two to four weeks, depending on the size of the organization and the number of business units in scope. Delivery is hybrid, digital or onsite as required.
Will this disrupt operations?
No. The assessment works primarily from documentation, system inventories, contracts and targeted interviews. It is designed to fit around the operating calendar rather than compete with it.
Do we need to have an AI strategy first?
No — and it is usually better if you do not. An exposure map is a far more useful input to an AI strategy than a strategy is to an exposure map.
Is this a cybersecurity engagement or a governance engagement?
Both, deliberately. The cyber exposures and the governance gaps are the same problem viewed from two positions, and assessing them separately produces two reports that do not reconcile.
We already have an internal audit function. Why would we need this?
Many internal audit functions are now measured against cybersecurity expectations they were not resourced to meet. This assessment can be run as a co-sourced review that strengthens the internal audit position rather than duplicating it.
Who typically commissions this?
Boards, audit committees, chief risk officers and chief executives. The common trigger is a question that was asked and could not be answered.
Download the brochure
Dawgen Global’s AI Governance & Cyber Risk Readiness Assessment examines seven review areas — AI usage discovery, risk classification, cybersecurity exposure, data governance and privacy, governance maturity, vendor AI screening, and board reporting — and delivers a board-ready executive summary with a prioritized remediation roadmap.
Download the service brochure for the full scope, deliverables and engagement format.
About Dawgen Global
Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.
The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.
To explore a partnership, reach out:
- Website: dawgen.global
- Email: [email protected]
- WhatsApp (Global): +1 555-795-9071
- Caribbean offices: +1 876-665-5926 | +1 876-929-3670 | +1 876-926-5210


