In short: King V Principle 10 makes the governing body, not management and not the AI vendor, accountable for governing the organisation’s use of artificial intelligence. It sets out nine values a board must hold in view (ethics, human centricity, accountability, transparency, explainability, security, privacy, fairness and trustworthiness), and Recommended Practice 109(c)(ii) is explicit that accountability for a system’s decisions cannot be delegated to a vendor by contract. Approving an AI policy and receiving a quarterly activity report does not, on its own, discharge the duty - the board has to be able to name who owns each consequential AI decision, not just that the system exists.
A director sits in a governance committee meeting, pen in hand. In front of her is the organisation’s brand-new AI policy: fourteen pages, drafted by the vendor, recommended by management. She signs. She feels, reasonably, that she has done her job. Six months later the same AI tool has quietly declined a tranche of loan applications on grounds no one inside the organisation can explain. She calls the vendor. The vendor points to a clause in the contract. In that moment she learns the thing no one told her at the signing: accountability does not travel with the signature. It stays in the room. It stays with the board.
Oversight is not management
Start with the distinction everything else rests on. A governing body oversees. Management manages. These are not two words for the same activity. Management selects the AI tool, negotiates the contract, configures the model, monitors its day-to-day output, and runs the controls. The board does none of that. What the board does is set the direction, approve the risk appetite, and then satisfy itself, on evidence, that the thing it directed is actually happening.
Oversight is not doing the work, and it is not trusting that the work is being done either. It is the disciplined act of asking for proof and being willing to act when the proof is thin. The common failure mode is a board sliding into one of two extremes - either trying to run the model itself, which it cannot, or waving it through because management seemed confident. Neither is oversight. And the duty to oversee cannot be delegated away: management can be tasked with execution, but accountability for the outcome remains with the governing body.
What King V Principle 10 actually says
That duty lives at Principle 10 of King V, South Africa’s current Code on Corporate Governance. The Principle reads: “The governing body governs data, information and technology in a way that enables the organisation to sustain and optimise its strategy and objectives.” It does not say the board should be aware of technology, or informed about it. It says the board governs it, toward the organisation’s strategy - and artificial intelligence sits squarely inside “technology” here.
Two points of discipline are worth flagging. First, this is Principle 10 under King V. If you have seen it referred to as Principle 12, that was King IV, which King V has superseded - use the current number. Second, King V is a governance code, not legislation; it is not law unless incorporated into a statute or a listing requirement. But it applies across organisation types and sectors, and it is the benchmark against which a South African board’s conduct on this is judged.
The nine values a board must hold in view
Under Principle 10, King V sets out nine values a governing body is expected to hold in view whenever the organisation uses artificial intelligence: ethics, human centricity (keeping people at the centre of how the technology is used), accountability, transparency, explainability (the ability to say why a system produced the output it did), security, privacy, fairness, and, deliberately last, trustworthiness.
This is not a technical checklist for a data science team to work through. These are governance values - the lens through which the board interrogates what management brings to it. When an AI deployment lands in a board pack, this is the frame: can the organisation demonstrate each of the nine, or only some of them?
The line you cannot disclaim
Here is the single most important sentence for a director to internalise. King V’s Recommended Practice 109(c)(ii) calls for “clear accountability for decisions, actions, outputs and outcomes.” Sit with one word in that line: decisions, not designs.
This closes exactly the escape route the director in the opening scenario tried to use. When an AI system produces a decision - an approval, a decline, a score, a recommendation acted upon - the accountability for that decision has a named owner inside the organisation. It is not the model’s. And, the hard part, it is not transferable to the vendor that built the model. A contract can allocate liability. It cannot allocate governance accountability. The board that deployed the system owns the decisions the system makes on the organisation’s behalf. That is why signing the vendor’s policy solved nothing in the opening scenario - the signature acknowledged the tool, it did not move the accountability anywhere.
Apply and explain, not apply or explain
King V operates on a mechanism called “apply and explain,” and it is worth getting exactly right because it is frequently misstated. Under apply and explain, application of the Principles is assumed - the organisation is taken to be applying them - and what gets disclosed is an explanation of the recommended practices implemented, and how. Contrast this with the older King III approach of “apply or explain,” where an organisation could elect not to apply a principle provided it explained why. King V does not offer that election on its Principles: Principle 10 is not optional, and a board cannot quietly decide the AI values do not apply to it and simply note that choice.
That is also why disclosure has real teeth even for a code that is not law. The King V Disclosure Framework expects the governing body to report, in a way its full range of stakeholders can read - shareholders, employees, regulators, customers whose data feeds the systems, and the communities affected by automated decisions - on how it has discharged Principle 10. A disclosure that says “the board approved an AI policy and receives quarterly updates” reads very differently to one that shows the board can identify every AI system in use, knows which ones make consequential decisions, and can point to who is accountable for each. The first describes activity. The second describes governance.
What a weak AI board pack looks like
Make this concrete with the artefact a director actually sees. Imagine the AI section of a quarterly pack reporting that the tool processed 40,000 transactions, that uptime was 99%, and that no complaints were escalated. Every number is true, and the pack tells the board almost nothing it needs. It reports activity, volume, availability and absence of noise - not exposure. It does not say which decisions the tool made that materially affected a person. It does not say whether anyone reviewed the declines, or who owns the risk classification and when it was last revisited.
A governing body exercising real oversight reads that pack and asks the questions it does not answer. Noticing what a confident report leaves out is the difference between a board that governs and a board that is managed by its own reporting.
Why a policy and a quarterly report are not enough
Many boards believe that approving an AI policy and receiving a periodic report discharges the Principle 10 duty. It does not. A policy is a statement of intent - it governs nothing until it is implemented, tested and revisited. A quarterly report discharges nothing if it reports activity rather than exposure.
Discharging the duty is an ongoing posture, not two completed tasks. It means the board can name who is accountable for AI decisions, can see a current inventory of the systems in use, can point to a risk classification the organisation owns rather than the vendor, and can show that human oversight is specified for the systems that need it. Approval is a moment. Governance is a practice sustained between the meetings, and evidenced at them.
The same duty, converging internationally
A director might reasonably ask whether King V is an isolated South African expectation. It is not. ISO/IEC 38507, the international governance standard, directs the governing body toward exactly this kind of technology oversight, sitting alongside the separate management-system standard for artificial intelligence, ISO/IEC 42001, within the same ISO governance family. International principles from bodies such as the OECD land on the same core ideas of accountability and human-centred use. And when South Africa’s Financial Sector Conduct Authority and Prudential Authority surveyed the market for their November 2025 joint report on artificial intelligence, they pressed exactly these points: robust governance frameworks, board-level oversight, explainability, and disclosure where AI affects consumers.
King V is the worked example here, but the duty it describes is one governing bodies across jurisdictions are being held to. The real work is the standing willingness to ask what a confident report leaves out, to insist that accountability for every consequential AI decision has a named owner inside the organisation, and to treat “the vendor handles that” as the start of a conversation rather than the end of one. Artificial intelligence is already making decisions in your organisation’s name. The question Principle 10 asks is whether the next disclosure can show the board is governing those decisions, or only that it was told about them.
Check your board against these same nine values
The interactive AI Governance Oversight Checklist scores your board against the King V Principle 10 values covered in this article - no email required to start. Enrolment in Celagenix® Academy unlocks the full learning unit this article is drawn from.
Take the free AI Governance Oversight Checklist →Frequently asked questions
Principle 10 requires that “the governing body governs data, information and technology in a way that enables the organisation to sustain and optimise its strategy and objectives.” Artificial intelligence falls within “technology” for this purpose, so the board is required to actively govern AI use toward the organisation’s strategy, not merely stay informed about it. It was Principle 12 under the earlier King IV Code; King V, the current Code, renumbers it as Principle 10.
Management selects the AI tool, negotiates the vendor contract, configures the model, monitors day-to-day output and runs the operational controls. The board does none of that directly. Its role is to set direction, approve risk appetite, and satisfy itself on evidence that what it directed is actually happening - and that oversight duty cannot be delegated away, even though execution can be.
King V sets out nine values a governing body must hold in view when the organisation uses AI: ethics, human centricity, accountability, transparency, explainability, security, privacy, fairness, and trustworthiness. They function as a governance lens for interrogating AI deployments brought to the board, not as a technical checklist for a data science team.
No. King V’s Recommended Practice 109(c)(ii) calls for “clear accountability for decisions, actions, outputs and outcomes.” A vendor contract can allocate liability between the parties, but it cannot allocate governance accountability - the board that deployed the system remains accountable for the decisions that system makes on the organisation’s behalf.
Not on their own. A policy is a statement of intent that governs nothing until implemented, tested and revisited, and a report that describes activity - volume, uptime, complaint counts - rather than exposure tells the board little about which decisions materially affected people or who owns the associated risk. Discharging Principle 10 is an ongoing posture: the board must be able to name who is accountable for each consequential AI decision, not simply that a policy and report exist.