Skip to content

Leadership and readiness

Questions private company boards should ask about AI and company data

By SourceX Editorial · Updated

Short answer

A private company board should ask about AI and company data in four areas: how staff use AI tools, whether software vendors train on company records, whether and how records may be licensed externally, and what is retained or deleted. The test for every answer is whether management can point to a named owner and a written record.

Key takeaways

  • Group board questions into internal AI use, vendor training, external licensing and retention.
  • A good answer names an owner and points to a register, policy or decision log, not a reassurance.
  • Any external license of company records should follow an approval path the board has agreed in advance.
  • Retention rules decide which records exist to protect, use or license, so they belong on the same agenda.

What boards are overseeing when they ask about AI and data#

Boards asking about AI and company data are overseeing three things: risk to customers and the company's reputation, the value of the records the company holds, and whether management has controls in place. Directors are not choosing tools or reading tickets.

In a private company the board may be the founder, family members, independent directors and investor representatives. The questions below work for any of them, and each can be answered from documents management should already have or should create.

The board's job is to ask until the answers are specific. Vague comfort such as we are careful with data is not an answer; a register, a policy with an owner, or a decision log is. If management cannot produce one, the follow-up action is to create it, with a date for the board to review it.

Questions about internal AI use#

Questions about internal AI use test whether the company knows which AI tools staff use and which company records go into them. Use of personal AI accounts for work is the most common blind spot.

A red flag is not proof of a problem. It is a sign that nobody has looked, which is the gap the board is there to close.

Questions about internal AI use
QuestionA good answer includesRed flag
Which AI tools are approved, and who approved them?A current list with an ownerNo list, or a list held in one person's memory
Which company or customer records may go into those tools?A written rule by record typeRules that exist only in an email thread
Do staff use personal AI accounts for work?Managed accounts and a stated ruleNobody has checked
Who reviews AI output used in customer work?Named review steps for customer-facing outputOutput sent to customers unreviewed
Has sensitive material been entered into a public AI tool?A reporting route and an incident logNo way to know

Questions about vendors training on company data#

Questions about vendor training ask whether software the company pays for is using company records to build products for others. Help desks, CRMs, meeting recorders and document tools are the usual places to look.

The board does not need to read the clauses. It needs to know that someone has, and that the answers are written down.

  • Which of our systems have AI features switched on, and who made that decision?
  • Which vendor contracts allow use of our content for service improvement, aggregated data or model training?
  • Where we opted out, do we have written confirmation, and does it cover past data?
  • Who keeps the register of vendor AI terms, and when is it rechecked?
  • Have any AI features been enabled by default since the last review?

Questions about licensing company records externally#

Questions about external licensing decide whether records such as support histories, project files or job records may ever be shared with an AI developer, and under what controls. An inbound request is the worst moment to invent the answer.

Licensing means granting defined use under contract while the company keeps ownership, so the board's interest continues after signature: what was permitted, for how long, and how deletion is confirmed. Directors should expect a decision log that records each request, the answer and the reason, whether the answer was yes or no.

Questions about licensing company records externally
QuestionWhy it mattersWho usually answers
Do we have a policy on licensing records, including what is never licensed?Prevents ad hoc decisions on inbound requestsCEO with counsel
Who can sign a data license for the company?Authority must be clear before terms are discussedCounsel
Which board, investor or lender consents could apply?Shareholder and credit documents can restrict IP licensesCFO and counsel
How are customer and employee personal details removed?Privacy obligations follow the recordsPrivacy lead
Which permitted uses would we accept, and which never?Sets limits before a buyer proposes termsCEO and board
How would we explain a license to customers and staff?Reputation risk is a board-level concernCEO

Questions about retention and deletion#

Questions about retention and deletion matter because retention rules decide which records exist to protect, use or license. A company that deletes too early loses its history; one that keeps everything carries the risk of everything.

Retention questions often surface surprises, such as an old help desk still under subscription because nobody knows whether its history matters, or a former ERP whose records were never exported before the contract ended. Each one is a decision someone should have made on purpose, and the board's questions make sure someone does.

  • Do we have a retention schedule by record type, and is it followed in practice?
  • What happens to records when a system is retired or replaced?
  • Are legal holds tracked and respected in every system?
  • Who approves deleting an archive, and is that decision recorded?

What management should bring to the board#

Management should bring a short pack of standing documents rather than a narrative update. The same documents let new directors, auditors and future buyers of the company see how decisions were made.

A useful pack contains the approved AI tools list, the vendor AI terms register, the data licensing policy and decision log, the retention schedule with exceptions and a note of any incidents. Review it on a regular cadence and whenever a material event occurs, such as an inbound data request, an acquisition or a system retirement.

Illustrative: a mechanical contractor's annual board review#

Illustrative: a fictional HVAC and plumbing contractor has a three-person board: the founder, an independent director and a representative of a minority investor. At its annual review, the board works through the four question groups with the COO and the controller.

Internal use turns up service managers pasting customer notes into personal AI chat accounts to draft estimates. Vendor training turns up an AI estimating assistant in the field service platform, enabled by an administrator during a trial with no record of its terms. Licensing turns up no policy, and the investor's shareholder agreement requires consent for licenses outside the ordinary course. Retention turns up a former dispatch system still billed monthly because nobody knows whether its history matters. The board asks for an approved tools list, a vendor AI register, a draft licensing policy with the consent route, and a full export of the old system before cancellation, each with an owner and a date.

How SourceX supports board oversight#

SourceX supports board oversight by giving directors a defined decision point rather than an open-ended process. Approval is its own step in the SourceX five-step transaction, and the release authorization names who approved the final package for the company.

Before any request arrives, the SourceX Enterprise Data Value Framework helps a board see which record families may be worth assessing at all. For any license that proceeds, the SourceX Evidence Packet gives directors one file to review, showing where the records came from, which rights and permitted use apply, how privacy was handled and who authorized release.

Frequently asked questions

Does the board need to approve a data license?

That depends on the company's governing documents, delegated authority and any investor or lender agreements. Many boards choose to reserve approval of external data licenses, or adopt a policy that defines when management may approve alone. Counsel can confirm what your documents require.

Should the board ban staff from using public AI tools?

Outright bans are hard to enforce and tend to push use onto personal accounts the company cannot see. Boards usually get better control by asking for an approved tools list, managed accounts and a clear rule on which records may never be entered into any AI tool.

Do we need an AI policy before considering data licensing?

An internal AI use policy and a data licensing policy are different documents, but both should exist before the company answers an inbound request. The licensing policy should state who approves, which records are excluded and which permitted uses the company will consider.

What should the minutes record about these discussions?

Minutes typically record that the board reviewed the topic, which documents it considered, any decisions or delegations, and follow-up actions with owners. Counsel can advise on the right level of detail for your company and your investors.

How do investors and lenders fit in?

Shareholder agreements and credit agreements sometimes restrict licensing intellectual property or transferring assets. The CFO and counsel should check those documents early, so any consent is planned rather than discovered during a negotiation.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify