The Evolving Role of AI in Corporate Governance: Insights from Monique Shivanandan
As the landscape of artificial intelligence (AI) continues to shift and evolve, the implications for corporate governance have never been more significant. Monique Shivanandan, a prominent board member at Token and the former group chief information security officer (CISO) and chief data and analytics officer at HSBC, has emphasized the critical need for technology executives to provide their boards with clarity regarding the business value, risks, and accountability concerns surrounding AI technologies.
With AI agents increasingly capable of accessing sensitive information, writing code, and executing operational tasks, it is essential for Chief Information Officers (CIOs) to navigate the conversation around these technologies effectively. Shivanandan suggests that CIOs should concentrate their discussions on the overarching business outcomes these technologies can generate rather than getting bogged down by the intricate technical details. The directive is clear: focus on value creation and risk assessment, which are vital in the eyes of board members.
Boards are recognizing AI’s dual nature as both an opportunity and a potential threat. Directors are particularly interested in whether their organizations are staying competitive by investing in AI capabilities that promise to enhance revenue streams or lower operational costs. At the same time, they remain acutely aware of the risks associated with AI systems, including the potential for "hallucination"—when AI generates incorrect or misleading outputs—and the risk of such systems acting unpredictably, possibly endangering customers.
“It’s about business enablement and customer enablement. It’s not about cool tech,” Shivanandan stated, pinpointing a common misconception that innovation for innovation’s sake is the goal. This insight serves as a reminder that technology should serve to enhance business functions and customer experiences.
To facilitate more constructive discussions around AI, Shivanandan recommends organizing the strategy into three foundational pillars: governance, risk mitigation, and innovation. Governance involves establishing clear frameworks for how AI initiatives are reviewed and managed within the organization. Shivanandan stresses that having a well-defined governance model not only empowers businesses but also assures stakeholders that due diligence is being exercised.
Risk mitigation is equally vital. Organizations must articulate how they are working to minimize the likelihood of failures associated with AI, as well as the impact of any such events should they occur. This proactive approach can help build trust among board members and stakeholders, reassuring them that the organization is prepared to face any unforeseen consequences that may arise from AI deployment.
Innovation, the final pillar, differentiates between merely automating existing operations and developing entirely new services and products. In a competitive market, companies must demonstrate that they are leveraging AI not just for efficiency but for groundbreaking advancements in their offerings.
During a recent video interview with Information Security Media Group (ISMG), Shivanandan delved into several critical topics, including how CIOs can translate technical AI concerns into comprehensible business and operational risks. She discussed the types of metrics and governance frameworks that can provide boards with meaningful oversight of AI initiatives, and underscored the importance of requiring verified and informed human approval for consequential decisions made by AI systems.
Shivanandan’s extensive experience, spanning four decades in technology across sectors such as financial services and telecommunications, gives her a unique perspective on the intersection of AI and corporate governance. Her previous role as the group CISO at HSBC involved leading security initiatives and shaping governance strategies for AI. Additionally, she has held senior leadership positions at several notable organizations, including Chubb Insurance, Aviva PLC, Capital One, and BT. As a member of various public and private boards, Shivanandan also contributes her expertise to Iridium Communications, further enriching her understanding of the nuances involved in overseeing innovative technologies.
In summary, as AI becomes increasingly integrated into business operations, the conversation surrounding its governance and risk management must evolve. Monique Shivanandan’s insights underline the necessity for technology leaders to shift their focus from mere technicality to encompass the wider business implications and risk assessments of AI technologies. By framing discussions around governance, risk mitigation, and innovation, CIOs can engage their boards more effectively and pave the way for responsible and beneficial AI integration.

