The data question your board should be asking
3 August 2026
Every board now asks an AI question. Far fewer ask the question that comes before it. "Are we doing something with AI" is comfortable, and management always has an answer. The harder, prior question is about data: which of our critical decisions run on data we trust — and which only look like they do?
The distinction that question surfaces is between the data-driven enterprise and the data-decorated one, and from a board seat they are easy to confuse. The data-decorated organisation has dashboards everywhere. Reports arrive on schedule, beautifully rendered. And underneath, decisions are still made the old way — by anecdote, by seniority, by the weekly meeting whose real function is to reconcile which of three conflicting versions of a number the organisation will agree to believe. The decoration is expensive, and it photographs well, and it changes nothing about how the enterprise actually decides.
There is a simple test, and it works at board level: would you act on this number without someone checking it first? Ask it of the numbers behind pricing, risk, capital allocation, customer decisions. Where the honest answer is no — where every important figure travels with a caveat and a person whose job is to verify it — the organisation does not have an analytics capability. It has a reporting habit with manual assurance, and the cost of that assurance is paid on every decision, in money and in days.
What makes a number trustworthy is not sophisticated and never has been. Lineage: it is known where the data originated and what transformed it on the way. Ownership: a named person — not a committee — holds each significant data domain, with the authority and budget to fix it. Access: who and what may touch the data is designed and enforced, not accumulated by exception. Boards already understand these disciplines perfectly, because they are the same ones financial control is built on: provenance, accountability, authorisation. No director would accept a set of management accounts assembled the way most operational dashboards are — by extract, from systems that disagree, with no audit trail. The data question simply asks that the numbers running the business meet the standard already demanded of the numbers reporting it.
For a regulated enterprise, the stakes are sharper, because attestations rest on data. Operational resilience tolerances, incident reporting, financial and non-financial disclosure — each is a claim built on numbers, and a claim whose lineage cannot be shown is a hope with a signature on it. Regulators have noticed; the supervisory question is decreasingly "what is the number" and increasingly "show me how you know".
And this is also, properly asked, the AI question. Every AI ambition inherits the data estate beneath it. A report built on doubtful data at least passes a sceptical human on its way to a decision; a model operates at scale, inside automated processes, with no one reading each output. The tolerance for quietly wrong data falls precisely as the volume of decisions rises. An organisation that cannot answer the trust question is not one prudent step away from AI value — it is standing on the part of the bridge that is not built.
None of this argues for the multi-year data foundation crusade; those programs fail by asking for years of cost before showing a decision improved. What works is narrower: pick the decisions that matter most, and make the data under each of them trustworthy — traced, owned, access-designed — one governed slice at a time, each slice paying for itself in a decision the business can feel. The estate improves incrementally, and deliberately, and visibly.
A practical place to start: name the three numbers this board relies on most, and ask management to trace each one end to end — where it originates, what transforms it, who owns it, and what happens when two systems disagree. The gaps that exercise finds are not a reason for alarm. They are the data strategy, in priority order, written by the board's own reliance.