What concerns me most about organizational AI use is not that companies are moving quickly. It is that many cannot identify who has the authority to stop an AI system from being deployed when the risks are unclear.
Every organization knows how to manage financial risk, cyber risk, and legal risk. Far fewer know how to manage algorithmic risk — the risk that shows up when an AI system helps decide something important about a person’s life: who gets hired, who gets a loan, whose resume gets screened out, whose insurance claim gets flagged.
That risk doesn’t belong to any one department. IT didn’t build the business case. HR didn’t write the code. Legal didn’t pick the vendor. It cuts across all of them — which is exactly why it falls through the cracks, until a biased hiring tool or a broken chatbot becomes a headline, a regulatory inquiry, or a lawsuit.
The fix isn’t another policy nobody reads. It’s a governance structure with real authority: an Algorithmic Risk Committee (ARC).
Algorithmic risk is the potential for harm — to people, to the organization, to its reputation — created by how an AI system is built, deployed, and used. In practice, that means:
Bias, when a system treats people differently based on race, age, disability, or other protected traits, even unintentionally
Privacy problems, from how personal data is collected, used, or retained
Lack of explainability, when a decision affecting someone can’t actually be explained to them
Loss of trust, from employees, customers, or regulators
Security exposure, unique to how AI systems and their data are built
Legal and reputational exposure, when known risks aren’t caught and addressed before a system goes live
The nonprofit ForHumanity, which focuses on AI governance and oversight, groups these into five categories: ethics, bias, privacy, trust, and security. The point isn’t the label — it’s that algorithmic risk isn’t a technical problem with a compliance footnote. It’s a management problem that happens to involve technology.
A policy tells people what should happen. It doesn’t tell you who’s accountable when it doesn’t. Most organizations using AI today have:
No single group reviewing AI risk before, during, and after deployment
No process for asking “what risk is left over after we’ve tried to fix this, and have we told anyone?”
No way to get feedback from the people a system might actually affect before it launches
No clear separation between the team that builds a system, the team that oversees it, and the team that checks the oversight
That gap is exactly what an Algorithmic Risk Committee is built to close.
An ARC is a group — internal staff, outside experts, or both — responsible for making sure every AI system in use has been checked for risk, and that any risk found gets fixed, explained, or disclosed.
It doesn’t need to be a new committee of the board. In most companies, it works better as a management-level committee: a defined group of people with clear authority, a documented decision-making process, and a direct line to leadership and the board.
In practice, a working ARC:
Reviews systems before they launch — not after a complaint or a regulator gets involved
Sets a risk threshold for each system — a hiring tool and an internal chatbot don’t carry the same stakes, and shouldn’t be judged by the same bar
Brings in outside perspective before launch, not just the team that built the system
Writes down what risk remains after mitigation, and makes sure someone above the team knows about it
Works with legal, HR, IT, and business leaders on the ground, while keeping clean records so internal audit can independently check the work later
Reports to senior leadership and the board, so accountability doesn’t stop at the committee room door
This isn’t a new invention. It’s how most companies already manage other kinds of risk — it just hasn’t been applied to AI yet. The same logic behind risk committees for finance or cybersecurity applies here.
The idea also aligns with major external frameworks. NIST’s AI Risk Management Framework calls for clearly documented roles and responsibilities, mechanisms to inventory AI systems, and executive leadership accountability for decisions about AI risk. ISO/IEC 42001 provides a complementary management-system structure for establishing, implementing, maintaining, and continually improving AI governance. An Algorithmic Risk Committee—or another clearly designated cross-functional body—can provide a practical way to put those expectations into operation.
A committee that can only offer an opinion isn’t a governance structure — it’s a discussion group. What makes an ARC real is decision-making authority. A credible ARC should be able to:
Require a risk review before any system launches
Put conditions on approval, or stop a launch, when serious risk hasn’t been resolved
Require the business owner to justify, in writing, why the benefit is worth the remaining risk
Escalate anything above an agreed risk threshold to leadership or the board
Require ongoing monitoring and a re-review after any major change to a system
Keep a record of who approved what, based on what evidence, and under what conditions
Without that authority, an ARC just produces meeting notes. With it, it produces a paper trail that holds up under a regulator’s questions, an audit, or a lawsuit.
Three things are pushing this from “nice to have” to necessary.
Regulation is catching up. New York City’s Local Law 144 already requires certain employers to get an independent bias audit before using AI hiring tools, and to notify candidates. The EU AI Act goes further, though many of its toughest deadlines have recently been pushed back. The direction, either way, is the same: regulators want proof — documented, checkable proof — that a company understands and manages the risk in its AI systems. An ARC, or something like it with real authority, is what produces that proof as a byproduct of doing the work right.
Lawsuits are already happening. In Mobley v. Workday, plaintiffs claim an AI hiring tool discriminated against candidates. The case is still active and nothing has been proven, but it shows exactly the kind of question companies and vendors are now being asked in court: who was responsible, what testing was done, and who was watching. A company that can show it identified and addressed known risk is in a very different position than one that had a policy no one followed.
Trust is the thing actually on the line. Employees, customers, and the public are watching how companies use AI. An ARC isn’t just risk control — it’s proof that a company takes seriously the people affected by its algorithms.
You don’t need a fully built-out committee on day one. Start with:
Naming someone accountable for AI risk — even a small cross-functional group
Making a list of every AI system in use, so you know what you’re actually managing
Building a simple risk review step before any new AI system goes live
Making sure leadership actually sees this reporting, instead of it staying buried at the working level
ForHumanity’s free resources at ForHumanity.center are a solid place to start building from, rather than starting with a blank page.
Algorithmic risk is not a future problem. It is a current operating condition. The organizations that build the governance muscle now—before a regulator, litigant, employee, or customer forces the issue—will be better positioned not only to control AI risk, but to use AI with confidence, credibility, and trust.
Thanks for reading Ethical Edge by Evie’s Substack! This post is public so feel free to share it.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.