
The chair asked the question at the end of the board meeting almost as an afterthought.
"Do we actually own the AI in our own product?"
The room paused. The CTO started to answer. The general counsel started to answer differently. The head of product looked at the CTO. Nobody was wrong, exactly. Nobody was sure. The board had approved every quarter for two years. The board had never once asked to see the evidence.
Every board tracks revenue. Far fewer track whether the company can prove it owns its IP, has the rights to its data, or can evidence the AI claims in its own marketing. Those are the quiet domains. They surface late and cost most. A board that has never asked to see the evidence is trusting that it exists.
The Ortent Diligence Radar reads those quiet domains. It scores a SaaS or AI company on nine of them against two axes, exposure and readiness, and shows the gaps where a buyer will concentrate. The launch anchor of this series set out the frame. The middle post set out why consistency and response time decide conviction. This one is about the board's use.
There are three.
The first is to watch the quiet domains. Chain of title. Data provenance. AI governance and claims. Sector and regulatory perimeter. Insurability. Each of those can carry high exposure for a company selling into a regulated market, holding sensitive data or making categorical AI claims, and each is easily invisible from a revenue-and-pipeline board pack. The chair does not need to become a technical expert. They need to ask, every quarter, one plain question: which of these can we evidence today, and which cannot. Then follow the ones that cannot to a named artefact and a named owner.
The second is to treat readiness as a value lever, not a cost. The work that closes these gaps is the same work that makes the company better run. A signed IP assignment from every contributor. A data bill of materials for every material dataset. A substantiation file for every categorical claim in marketing. A reconciled monthly cohort file. A tested incident-response plan. A board that funds this work is not adding overhead. It is protecting the exit multiple two years out, and buying operational quality it will benefit from every quarter between now and then.
The third is the one that changes the meeting. Ask for proof, not policy. The failure mode this whole exercise guards against is the polished document that nothing stands behind. A written AI policy is not AI governance. A privacy policy is not a data map. A security policy is not a control that runs. If the answer to a board question is a document title, the follow-up is: show me the artefact.
A board adds the most value here by asking the same question a buyer will ask. Show me the evidence, not the policy.
The practical reason a board can no longer wave these questions through is the insurance market. Insurers are ending what they call silent AI. AI-specific exclusions are being written into cyber, technology errors and omissions, directors and officers, and warranty and indemnity cover through 2025 and 2026. That matters at exit. In most deals of any size the buyer transfers risk off its balance sheet by wrapping the seller's warranties in W&I insurance. If your AI governance, your data rights, and your security cannot be evidenced, the insurer carves out those representations, and the risk they would have carried falls back onto the seller in a larger escrow, a specific indemnity or a lower headline price. The board that pushes for evidence now is the board that keeps those representations inside the insurance package later.
Two facts sharpen this. Anthropic settled a training-data class action this July for around 1.5 billion dollars, roughly 3,000 dollars a book. Data provenance is now a priced question. And the SEC and FTC brought AI-washing enforcement through 2025 and 2026, including business-to-business cases. A categorical AI claim your marketing team cannot substantiate is a regulatory exposure your buyer will inherit and price. Neither of those is a marketing conversation. They are board conversations.
Three readers should carry this away.
The board or NED gets a governance instrument that reads the domains a board pack does not. The three uses above set the agenda. The radar names the domains and the ladder makes the questions concrete. Same questions every quarter. Different answers each time.
The founder or CEO gets a board that finally engages with the evidence base rather than the summary. That is uncomfortable in the short term and worth a lot at the table.
The PE operating partner gets a portfolio standard. A portfolio company that is diligence-ready from the start carries less risk, sells faster, and defends a higher price. That is a return on portfolio hygiene, not a cost of governance.
Score your company at ortent.co/tools/diligence-radar. The whitepaper carries the argument. The self-scoring prompt runs the exercise from your own evidence. And if you want a second read before a raise or a sale, ortent.co/contact.
The board that reads the evidence rather than the summary is the board that finds the quiet defect while the fix is a signature, not a price cut.