This week’s questions
Three questions to take into the room
Each week starts with a small set of live, copy-ready challenges. Use one, ask for the evidence, then assign the follow-up.
Question 01 / Decision evidence
For one AI-assisted decision, can management reconstruct what information the system accessed, what it relied on and who challenged the outcome?
- Why it matters now
- Agentic retrieval improves the ability to work through complex records, but it also makes the evidence path part of the control. A confident answer is not enough when a customer, regulator or committee needs to understand how it was reached.
- Ask for
- The approved source corpus, access permissions, retrieval and tool log, output, named reviewer, exception record and a sample challenge of the answer against the underlying record.
Question 02 / Shared infrastructure
If a cloud region or network path degrades, which important services fail together and can the firm show the recovery route actually works?
- Why it matters now
- This week’s provider incident evidence shows that a disruption can originate below the application layer. A service map that stops at the named provider misses capacity, routing, identity and operational dependencies that shape customer impact.
- Ask for
- The service-and-dependency map, regional and network assumptions, impact tolerance, recovery design, last exercised test, customer communication plan and accountable owner.
Question 03 / Market disclosure
When a material assumption changes, who re-tests the statement, decides whether escalation is needed and records why the disclosure remains accurate?
- Why it matters now
- The Rex decision is a useful reminder that forward-looking statements depend on current, supportable information. Data quality, management challenge and the escalation route need to work before a market announcement becomes difficult to defend.
- Ask for
- The forecast or disclosure, underlying management information, challenge record, escalation threshold, legal and finance sign-off, subsequent changes and retained decision log.
Use in the next meeting
Ask less. Follow through.
The aim is not a larger committee pack. It is one clear challenge that produces a named action and evidence for the next meeting.
- 01Choose one live question
Take the question that most directly affects an important service, decision or customer outcome.
- 02Ask for the evidence
Request the actual map, record, test result or decision trail—not an assurance summary.
- 03Record the follow-through
Name the owner, due date and evidence expected back. Bring the closure record to the next meeting.
Evergreen library
Choose the decision domain, then ask for evidence
These questions are built to last beyond the weekly news cycle. Pick the one or two that are live for your firm, assign an owner and use the evidence request as the follow-up.
Strategy and investment
Where AI, infrastructure, and market exposure change the business case
Use these where the decision is about scaling, funding, dependency, or strategic exposure.
Copy-ready question
Which AI-enabled workflows are moving from productivity case to business-critical dependency, and what investment is needed to control them?
- Why it matters
- Frontier-AI ICT risk is now part of the supervisory conversation, including governance, cyber prevention, response and critical-provider oversight.
- Strong answer contains
- A prioritised AI workflow inventory, business-criticality rating, owner, funding need, and control maturity view.
- Evidence to request
- AI inventory, dependency map, investment backlog, control gaps, and exit or fallback options.
Copy-ready question
Where could AI infrastructure, model-provider concentration, or vendor lock-in create downside exposure that is not yet in our financial scenarios?
- Why it matters
- AI capability is becoming an important service and critical-provider dependency, so concentration and substitution need to appear in business and resilience scenarios.
- Strong answer contains
- Exposure sizing, stressed assumptions, substitution options, vendor concentration limits, and monitoring triggers.
- Evidence to request
- Supplier spend, contract terms, concentration dashboard, scenario assumptions, and exit practicality assessment.
Governance and accountability
Who owns the decision when automation acts
Use these where the live issue is authority, sign-off, accountability, and escalation.
Copy-ready question
Can we stop an agent quickly, prove why it acted, and show who owned the decision when the evidence is challenged?
- Why it matters
- New model capability and evaluation incidents make permission boundaries, incident disclosure and human intervention operating controls rather than policy language.
- Strong answer contains
- Named accountable owner, permission boundary, monitoring trail, override path, rollback process, and tested escalation route.
- Evidence to request
- Permission map, audit logs, kill-switch owner, rehearsal evidence, decision log, and incident communications plan.
Copy-ready question
Which AI agents or copilots can touch production data, code, email, or tickets today, and are their permissions technically enforced?
- Why it matters
- Prompt rules are not control evidence when AI tools have access to real systems and privileged workflows.
- Strong answer contains
- Access list, technical enforcement, least-privilege review, logging, exception process, and emergency-stop proof.
- Evidence to request
- Access-control export, privileged-action logs, exception approvals, and live stop-path demonstration.
Operational readiness
Whether the firm can operate when the signal becomes real
Use these where the question is whether a process, journey, or service can actually perform under stress.
Copy-ready question
Which critical payment journeys would fail if a processor, tokenisation provider, or telecom route degraded for two hours tonight?
- Why it matters
- IT resilience evidence increasingly has to account for cyber, geopolitical and third-party dependence across important services and customer journeys.
- Strong answer contains
- Journey map, dependency map, impact tolerance, fallback route, customer communications, and last test result.
- Evidence to request
- Processor, tokenisation, telecom, power, and manual-fallback test evidence by customer journey.
Copy-ready question
Do we know which network providers and CDN paths sit behind each top digital service, by user region?
- Why it matters
- Status pages can stay green while customers experience failure at the edge, especially when internet-routing dependencies degrade.
- Strong answer contains
- Customer-edge telemetry, route map, region view, alert thresholds, and service-owner response plan.
- Evidence to request
- External monitoring, CDN/provider map, incident playbook, and customer-impact dashboard.
Control and assurance
Whether the answer is evidenced, not merely asserted
Use these where the firm is relying on policy, attestations, management information, or inherited assurance.
Copy-ready question
Where are we relying on policy, attestation, or status pages instead of telemetry, technical controls, and evidence of recovery under stress?
- Why it matters
- Regulators are testing whether firms can prove control operation under stress, not just describe the control framework.
- Strong answer contains
- Operational telemetry, technical enforcement, independent test results, exception tracking, and owner sign-off.
- Evidence to request
- Control test pack, real-time telemetry, incident evidence, and open-risk remediation plan.
Copy-ready question
Which critical decisions this week relied on data whose source, transformation, quality controls, and accountable sign-off can be reconstructed?
- Why it matters
- AI adoption, supervisory analytics, cyber evidence, privacy duties, and regulatory reporting all depend on reconstructable data lineage.
- Strong answer contains
- Source, transformation, quality checks, exception owner, retention, approval, and use-case linkage.
- Evidence to request
- Lineage map, quality-control report, exception log, sign-off trail, and sample reconstruction.
Copy-ready question
Where could rising scam typologies, known control gaps, or complaint ageing be characterised as systemic inaction?
- Why it matters
- Fraud, conduct, complaints, restrictions, and restoration speed are converging into one supervisory narrative.
- Strong answer contains
- Typology movement, control performance, complaint ageing, remediation times, vulnerable-customer impact, and owner actions.
- Evidence to request
- Fraud dashboard, complaint ageing, control-gap register, reimbursement trend, and remediation evidence.
Resilience and response
Whether the firm can recover, communicate, and learn
Use these where the live issue is fallback, incident response, or the boundary between firm and supplier.
Copy-ready question
Which top customer journeys depend on third parties whose failure would look to customers like our failure, and when did we last test the fallback?
- Why it matters
- Provider and infrastructure failures can become the firm’s customer and supervisory problem, even where the source of failure sits outside the firm.
- Strong answer contains
- Important business service mapping, supplier dependency, fallback option, last test, communications route, and tolerance result.
- Evidence to request
- Fallback test evidence, supplier SLA performance, incident communications pack, and customer-impact assessment.
Copy-ready question
Which weak signals already have owners, dates, and executive visibility?
- Why it matters
- Weak signals matter only when they have an owner, action date, escalation threshold and a route into executive visibility.
- Strong answer contains
- Signal owner, action date, escalation threshold, management-information view, and closure evidence.
- Evidence to request
- Open-signals register, accountable owner list, due dates, risk acceptance, and committee reporting extract.
Have a question a committee actually asked that belongs here? Send it across — ben@stgeorgesstrategy.com — and it may be added to the next edition of this page.