← All posts
AI at Work21 Jul 20264 min read

Five pillars of responsible AI oversight, and the one a certificate can't cover

Board conversations about AI oversight increasingly organise around five pillars: people, process, technology, data and governance. Four of them run on documents and architecture. The people pillar runs on behaviour, and behaviour is the one thing you can't evidence with a policy or a completion certificate. Here's how self-reflection closes that gap.

The Skilly Team


As AI systems become more autonomous, the board conversation is changing shape. It's no longer "should we adopt AI?" but "how do we oversee it responsibly?", and that conversation increasingly organises around five pillars: people, process, technology, data and governance.

  • People. As AI takes on more of the doing, humans shift from being in the loop to being responsible guardians of it. That means AI literacy at board level, and business, operations and risk teams who can critically challenge AI outputs rather than wave them through.
  • Process. Moving pilots into production on clear go/no-go criteria, and redesigning operating models around what AI can now do rather than layering it onto old workflows.
  • Technology. Choosing between proprietary, tailored and open-source models; managing compute, cost and vendor dependency.
  • Data. Treating input quality as a control, tracing prompts and model versions, and protecting the sensitive information AI systems now touch daily.
  • Governance. Embedding AI oversight in existing risk disciplines, keeping a live inventory of models in use, and staying aligned with frameworks like the EU AI Act.

It's a sound structure. But look at what each pillar actually runs on, and one of them stands apart.

Four pillars run on documents. One runs on behaviour.

Process, technology, data and governance can all be evidenced the traditional way. You can show the board a model inventory, a procurement strategy, a data lineage diagram, a governance framework with named owners. They're artefacts. They can be written, reviewed and filed.

The people pillar can't. "Our teams critically challenge AI outputs" is a claim about behaviour: what a busy analyst actually does with a confident, wrong AI answer at 4pm on a deadline. No policy document evidences that. Neither does a completion certificate, which proves only that a person clicked through a course, not that the course changed what they do.

This is the quiet gap in most AI oversight programmes. Boards can point to artefacts for four pillars and, for the fifth, an attendance record.

Self-reflection is how behaviour becomes evidence

The way through is to capture behaviour where it actually lives: in the everyday moments people use AI, told in their own words, against a defined standard.

That's what Skilly Work does. Each cycle, staff write a short reflection on a real AI-use moment from their own work. An AI rubric scores the judgement shown across five observable habits that spell SHARP (Scrutinise, Hold the decision, Acknowledge, Ring-fence, Practise), the expression of one underlying standard: Consider, the mark of people who use AI well. We've written about how those habits build a culture and who should own them; the point here is what the loop produces.

  • A per-person record. Each reflection is timestamped and scored, so "our people apply judgement" traces to named individuals, refreshed every cycle rather than certified once.
  • A gap view for managers. Where the habits are strong and where they're thin, by role and by risk, so the upskilling mandate becomes a coaching plan instead of a hope.
  • Board oversight, evidenced. Directors and senior managers run the same reflection cycle as staff. Board AI literacy stops being an assertion in a skills matrix and shows up in the record itself.
  • An audit-ready evidence pack. The scored reflections, standing per habit and the risk log with actions taken, exportable per person and per cohort, which is what regulatory alignment looks at in practice: not whether training was assigned, but what you can show your people actually did.

And because reflections are self-authored, the loop builds the behaviour while it evidences it. Honesty about a near-miss is scored as awareness, not marked down, so people keep telling you the truth about how AI is really being used.

Where it fits, honestly

Skilly Work doesn't build your model inventory, your data controls or your governance framework. Those pillars remain your own disciplines. What it does is evidence the pillar those disciplines depend on: the people expected to challenge, oversee and stay accountable for AI. It also hands your governance pillar something it otherwise lacks, a behavioural record to sit alongside the artefacts.

If your board is working through the five pillars, start with a simple test: for each one, ask "what would we put on the table if someone asked us to prove it?" When you reach people, and the answer is a completion report, that's the gap. One team and one reflection cycle is enough to see what closing it looks like: the rollout playbook covers the setup, and the interactive preview lets you try the reflection loop in your browser, no sign-up.

Explore Skilly Work →

See how your people actually use AI.

Try the interactive Skilly Work demo, or request early access to run a pilot with your team.