Seven questions a social service agency board should ask before approving an AI use

A board does not need to become an AI lab. It does need a clear account of the service problem, people affected, evidence, controls, human responsibility and conditions for stopping.

In brief

Approve a bounded problem, named responsibilities, usable evidence and explicit stop conditions. Require management to return with results before any wider or more consequential use.

On this page

Introduction

A board paper says an AI tool will save staff time, improve consistency or help the agency respond faster. The demo is polished. The proposal may still be too vague to approve.

Singapore charity boards are responsible for the organisation's overall direction, supervision and accountability. The Charity Portal says governing board members should act in the charity's best interests, be actively involved in management and decision-making, and make policy decisions jointly.[1][2] An AI proposal belongs inside those ordinary duties when it can affect services, people, data, finances or reputation.

This guide helps board members turn a broad technology proposal into a decision they can explain later. For the wider operating model, read responsible AI governance for social service agencies. If the agency is still choosing a modest learning project, start with why your first AI project should probably be boring.

Ask for a decision-ready proposal

Board members do not need to diagnose model architecture. They need enough detail to judge whether the proposed use serves the agency's purposes, whether the important risks have owners, and whether management can detect trouble early.

NCSS's Social Services Digitalisation Playbook places technology work inside mission-driven strategy, user journeys, workforce capability, data governance, cybersecurity and data protection.[3] The Charity Council's risk-management material also treats risk management as a way to protect assets, maintain compliance, reduce disruption and safeguard reputation.[4] Those are useful lenses for a board paper.

Ask management to answer the seven questions below in plain language. A supplier's slide deck can support the paper, but it cannot stand in for management's assessment.

Seven questions before approval

  1. 1. What mission or service problem are we solving, and which non-AI options were considered?

    Name the current workflow, the people doing it, the present cost or failure, and the result the agency wants. Ask why AI is suitable compared with process repair, staff training or ordinary software. Require a baseline so the board can later tell whether anything improved.

  2. 2. Who could benefit, be burdened, excluded or harmed?

    Identify clients, caregivers, staff, volunteers, donors, partners and people who may be wrongly excluded. Describe how an error could affect safety, dignity, access to help, workload, privacy or trust. Include the people who will experience the changed service, especially where refusal or appeal may feel difficult.

  3. 3. What data and systems will the use touch?

    Map prompts, files, recordings, model inputs, outputs, logs, backups, connected systems and any manual exports. State the purpose, minimum data needed, access, storage location, retention, deletion, overseas transfer and vendor use for every copy. Where personal data is involved, record the DPO's assessment and the relevant PDPA basis and controls. PDPC's generative AI guidance applies across the lifecycle, including personal data in prompts and inputs.[5]

  4. 4. Which decisions remain with people, and can those people genuinely challenge the output?

    Name the person accountable for the service outcome and the staff member who checks each output. Explain what evidence the reviewer sees, what training and time they receive, and how they can reject or override the tool. Define a route for a person affected to ask for explanation, correction or human reconsideration where appropriate.

  5. 5. What evidence would justify starting, continuing or stopping?

    Separate evidence about the exact workflow from general claims about AI. Set measures before the pilot, covering service quality, material errors, review effort, overrides, complaints, incidents and uneven performance across relevant groups or language use. AI Verify's voluntary framework covers governance principles including transparency, safety, security, fairness, data governance, accountability and human oversight.[6] Choose the parts that fit the use, preserve the evidence and agree hard stops before results arrive.

  6. 6. What is the full operating commitment?

    Show staff review time, integration and security work, training, support, monitoring, incident handling, contract costs, supplier dependency and exit effort. Include who will do this work after the pilot team moves on. A low licence price can still support an expensive workflow if people must repair outputs or maintain parallel systems.

  7. 7. Who is accountable, how will incidents reach us, and when will the board review the use again?

    Name one management owner, the operational owners and the person authorised to pause or stop the use. Define the fallback process, incident route and reporting timetable. State when approval expires and which changes require fresh review, such as a new model, new data class, new integration, larger user group or use in a more consequential decision.

Scale the evidence to consequence. These examples are editorial guidance; the approval route still follows the agency's governance.

Scale the evidence to consequence. These examples are editorial guidance; the approval route still follows the agency's governance.
Evidence areaLower-consequence, reversible internal testHigher-consequence or live service use
Purpose and affected peopleOne bounded workflow, named staff users and no direct effect on service access before review.Service pathway, groups affected, possible exclusion or burden, consultation findings and routes for explanation or reconsideration.
Data and systemsSynthetic, public or approved low-risk material; simple data-flow map; no production integration.Detailed data-flow and system map; DPO, security, procurement and relevant professional review; vendor and subprocessor evidence.
Testing and human reviewSmall realistic test set, source checking, named reviewer, error log and clear stop rule.Test coverage tied to likely harm, subgroup or language checks where relevant, qualified reviewers, challenge and override route, independent assurance where proportionate.
Operation, incident and exitShort duration, existing fallback, named owner, weekly review and a simple closure plan.Full operating cost, support capacity, monitoring and incident escalation, business continuity, contract and data exit, expiry and re-approval conditions.

What adequate evidence looks like

Evidence should match the decision being requested. A small, reversible test using synthetic material may need a short proposal, a defined test set, named reviewers and clear stop conditions. A live use involving client information or a service decision needs a deeper assessment and the approvals required by the agency's governance.

A useful board pack usually shows:

  • the existing workflow and baseline;
  • options considered, including improving the process without AI;
  • intended users and people affected;
  • data flow, provider arrangements and relevant reviews;
  • realistic test cases, known limitations and unresolved questions;
  • human checkpoints and accountable owners;
  • costs across the full term, including review, integration, training and exit;
  • measures, monitoring frequency and hard stops; and
  • the narrow decision requested today.

Do not turn this into a paper mountain for every experiment. Scale the work to the likely harm, reversibility, data and reach. Keep enough evidence for the next reviewer to understand what management knew, what the approving body decided and why.

Keep board, management and operational responsibility distinct

Board or authorised committee
Technology may: Support testing summaries and the organisation of evidence.
A person must: Apply the agency's authority limits, test mission fit and management's evidence, declare interests, set conditions and record the decision.
Chief executive and management
Technology may: Help analyse a documented workflow, organise options and support controlled testing.
A person must: Own the recommendation, compare alternatives, resource controls, assign accountable owners and report material incidents and results through the agreed route.
Service, data, technology and professional leads
Technology may: Produce drafts, suggestions or alerts within the approved scope.
A person must: Define safeguards, test realistic cases, train users, monitor practice and escalate failures or changing risks.
Named operational owner and reviewer
Technology may: Provide outputs, usage logs and test results where those records are reliable and approved.
A person must: Check outputs, correct or reject them, keep the fallback available, report concerns and use the stop authority when an agreed limit is crossed.

A short closing test

Before voting, ask each board member to finish one sentence: We are approving this use, for these people and this period, because this evidence is sufficient, provided these controls remain in place.

If the sentence produces several different answers, the paper needs work. Record the gaps and ask management to return with a narrower scope or better evidence. A careful deferral can protect the agency while keeping a useful idea alive.

Sources

  1. [1] Charity Portal, Code of Governance for Charities and IPCs (page describing the April 2023 Code)
  2. [2] Charity Portal, Governing Board's Duties and Responsibilities
  3. [3] National Council of Social Service, Social Services Digitalisation Playbook
  4. [4] Charity Portal, Enterprise Risk Management Toolkit for Charities and IPCs 2024
  5. [5] Personal Data Protection Commission, Advisory Guidelines on Use of Personal Data in Generative AI, published 20 July 2026
  6. [6] AI Verify Foundation, AI Verify Testing Framework

Source note

The governance allocation and example approval wording in this article are editorial guidance. They are not prescribed by the cited agencies. Apply the Charity governance sources where they are relevant to the organisation's legal and regulatory status.

About the author

Darren writes for Social Tech Guild about practical, responsible uses of technology in Singapore's social service sector.

Give the board a decision record, not another AI presentation

Social Tech Guild can help management turn a proposed AI use into a concise assurance paper covering mission fit, affected people, evidence, controls, cost and exit.

Discuss a board-ready AI review

About Darren

Darren explores practical technology with Singapore social-service teams as a volunteer. The work starts with the workflow, the people responsible for it, and the safeguards it needs.

How Social Tech Guild approaches the work

Could a small tool make your team’s work lighter?

Tell me about a task that keeps taking time. We can look at it together and see whether a small volunteer project could help.

Please do not include client-identifying information.

Discuss a project

I volunteer with Singapore social-service teams to explore small, practical ways to reduce repeated work.

This starts a conversation only. It does not confirm fit, a pilot, a project or a partnership.

PrivacyPlease do not include client-identifying information.