In This Article
- Executive Summary
- Why Mid-Cap Biotech Needs a Charter, Not a Working Group
- The 12-Section AI Steering Committee Charter Template
- Committee Composition, Quorum, and Term Design
- The Decision Authority Matrix: RACI for AI Decisions
- Sub-Committees for GxP, Commercial, and Research
- Interaction with Board Audit Committee and Data Governance Council
- The Standing Agenda and Quarterly Rhythm
- Escalation Paths and Stop-Work Authority
- The 90-Day Committee Stand-Up Plan
- Failure Modes to Anticipate
- Conclusion
- References & Sources
Executive Summary
Mid-cap biotechs, meaning organizations between roughly 200 and 2,000 employees, are in an awkward middle. They have enough AI activity that a governance gap is now material. They do not have the layered committee structure of a top-20 pharma to absorb the load. The typical response is to name a working group, hold a few meetings, and hope the pilots do not cross a line no one has drawn. That approach is running out of runway.
The pace and stakes have shifted. FDA’s Center for Drug Evaluation and Research consolidated its AI oversight into a single CDER AI Council in 2024, folding in the earlier steering committee, policy working group, and community of practice.1 The EU AI Act becomes broadly applicable in August 2026, with most obligations for high-risk pharma AI systems requiring documented governance, risk classification, and oversight before deployment.2 EMA’s finalized reflection paper commits to a risk-based, human-centered approach across the medicinal product lifecycle.3 Regulators expect a committee to point to. Investors and boards are starting to expect one too.
This article delivers a complete, adaptable AI Steering Committee charter for mid-cap biotech. It includes a 12-section charter template you can lift directly into your governance package, a decision authority matrix that assigns RACI roles across common AI decisions, sub-committee design for the GxP, commercial, and research domains, the interaction pattern with the Board Audit Committee and Data Governance Council, and a 90-day stand-up plan for organizations that need to move from an informal working group to a governed body without slowing science down.
Why Mid-Cap Biotech Needs a Charter, Not a Working Group
The pattern is familiar. A CIO or Head of Digital gathers four or five interested leaders. They call themselves an AI working group. They meet monthly for six months, mostly to look at pilots. Someone eventually asks whether the group can actually stop a project, and the room goes quiet. That is the moment a mid-cap biotech has outgrown its working group.
The pressure to formalize is coming from three directions at once. Regulators are consolidating and clarifying expectations. The FDA’s establishment of the CDER AI Council in 2024 signaled that the agency itself has moved from exploration into structured oversight, and industry is expected to mirror that maturity.1 Commercial pressure is intensifying, with more than 80% of pharma leaders reporting AI is an immediate priority and budgets rising in tandem.4 And the governance gap remains stark: Deloitte’s global boardroom survey of 695 board members and C-suite executives found that while AI is now on the agenda for the majority, roughly one in three organizations still reports they are not ready to deploy AI, and boards still report material knowledge gaps.5
A working group can shape a strategy deck. It cannot approve a high-risk use case, halt a deployment that has crossed a validation line, or represent the organization to a Board Audit Committee that has been asked what its AI oversight structure looks like. A charter changes the object from a discussion forum into a governed body with defined authority, accountable membership, quorum rules, and a written mandate the CEO and the Board have both endorsed.
For mid-cap biotech specifically, the charter must do something top-20 pharma templates rarely do well: it must be light enough to actually function inside a company where a handful of senior leaders wear multiple hats, and it must be layered enough to cover the GxP, commercial, and research risks that a smaller biotech still carries in full. Templates written for large enterprises tend to assume separate Chief AI Officers, dedicated AI ethics offices, and a full-time secretariat. A 400-person biotech has none of that. The charter that works here is deliberately sized for a company where the same VP of Quality may sit on the steering committee, chair a sub-committee, and personally review three of the twelve active use cases.
The Sakara Digital perspective. The point of the charter is not to look like a large pharma. It is to concentrate authority in a small, credible group of people who can make risk decisions at the speed the science demands, backed by a mandate specific enough that no one has to ask what the committee is allowed to do.
The 12-Section AI Steering Committee Charter Template
The charter below is deliberately structured so that a mid-cap biotech can adopt it with modest tailoring. Every section is present because it either answers a question the Board Audit Committee will eventually ask, resolves an ambiguity that would otherwise stall a decision, or aligns the organization with an external framework such as the NIST AI Risk Management Framework or the EMA reflection paper.7
Section 1. Purpose and Scope
The AI Steering Committee, hereinafter the Committee, is the enterprise governance body responsible for approving, prioritizing, and overseeing the responsible development, procurement, and deployment of AI and machine learning systems across the Company. The Committee’s scope includes generative AI, predictive machine learning, traditional analytical models used in regulatory or business-critical decisions, and any third-party AI capability embedded in a Company workflow. The Committee does not manage the day-to-day operation of individual AI systems; that responsibility remains with the business function that owns the workflow.
Section 2. Authority
The Committee derives its authority from the Chief Executive Officer and reports on a routine basis to the Board Audit Committee. Within the scope defined in Section 1, the Committee has authority to approve, defer, condition, or halt any AI initiative, including initiatives already in production. The Committee has stop-work authority for any AI system that presents an unmitigated GxP, patient safety, privacy, or regulatory risk. This authority is delegated to the Committee Chair between meetings for urgent matters, subject to notification of members within one business day.
Section 3. Membership
The Committee shall have between seven and nine voting members. Standing voting members include the Chief Information Officer or equivalent digital leader (Chair), the Chief Medical Officer, the Chief Scientific Officer, the Head of Quality Assurance, the Head of Regulatory Affairs, the General Counsel or Head of Legal, and the Chief Privacy Officer or Head of Information Security. Additional voting members may include the Chief Commercial Officer and the Head of Human Resources depending on the current portfolio. Non-voting standing invitees include the Chair of the Data Governance Council, the Head of Internal Audit, and the AI Governance Program Manager who serves as Committee Secretary. Term for voting members is two years, renewable once, with staggered rotation to preserve continuity.
Section 4. Quorum and Voting
Quorum requires a majority of voting members present, including at least one representative from each of the Quality/Regulatory, Medical/Scientific, and Legal/Privacy functions. Decisions are made by majority vote of members present; ties are broken by the Chair. Decisions to halt an in-production system or to approve a high-risk use case require a supermajority (two-thirds) of voting members. Members may not delegate their vote; a designated alternate may attend and speak but may not vote.
Section 5. Meeting Cadence
The Committee meets monthly for two hours, with an additional half-day quarterly business review. Extraordinary sessions may be convened by the Chair, the CEO, or any three voting members. All decisions are recorded in signed minutes retained for the greater of ten years or the retention period required for GxP records associated with the systems under review.
Section 6. Responsibilities
The Committee is responsible for maintaining the enterprise AI policy, approving the AI use case inventory and its risk classifications, reviewing and approving new high-risk and moderate-risk use cases, monitoring in-production systems against defined performance and drift metrics, approving the AI training and awareness curriculum, and coordinating with the Board Audit Committee, the Data Governance Council, and the Compliance and Ethics function on cross-cutting matters. The Committee owns the annual AI risk assessment and is accountable for its accuracy and completeness.
Section 7. Sub-Committees
The Committee shall maintain three standing sub-committees: the GxP AI Sub-Committee, chaired by the Head of Quality Assurance; the Commercial AI Sub-Committee, chaired by the Chief Commercial Officer or delegate; and the Research AI Sub-Committee, chaired by the Chief Scientific Officer. Each sub-committee has its own charter derived from this one, meets on its own cadence, and holds delegated approval authority for low-risk and moderate-risk use cases within its domain. High-risk use cases are always escalated to the full Committee. Sub-committee composition is defined in Appendix A of this charter.
Section 8. Escalation Paths
Any member of the Committee, any sub-committee chair, or the Chief Compliance Officer may escalate an AI matter to the full Committee. Any member of the Committee, the Chief Compliance Officer, or the General Counsel may escalate a matter to the CEO. The Chair of the Committee reports to the Board Audit Committee at each of its regular meetings and may escalate a matter to the Audit Committee Chair between meetings when material risk warrants it. Whistleblower reports concerning AI misuse are received by the Chief Compliance Officer and, where appropriate, transmitted to the Committee with source-identifying details redacted.
Section 9. Decision Authority Matrix
The Committee maintains a formal Decision Authority Matrix, refreshed annually, that maps AI decision types to Responsible, Accountable, Consulted, and Informed roles across the executive team. The current matrix is included as Appendix B and is binding on the organization. In regulated industries, a Verifier/Signatory extension (RACI-VS) is applied to high-risk decisions so that verification and approval remain separated.8 No AI system may enter a controlled environment without the signatures required by the matrix, regardless of any commercial timeline.
Section 10. Interaction with Other Governance Bodies
The Committee coordinates deliberately with the Board Audit Committee, the Data Governance Council, and the Enterprise Risk Committee. The Committee Chair provides a written report to the Board Audit Committee ahead of each of its meetings covering the AI risk register, in-production system performance, material incidents, and upcoming high-risk decisions. The Committee and the Data Governance Council maintain a shared use case intake pipeline; data governance approves the data foundation and the Committee approves the AI application. Where jurisdiction is unclear, the two chairs resolve it, with unresolved matters escalated to the CEO.
Section 11. Documentation and Transparency
The Committee publishes an internal annual report summarizing decisions, incidents, portfolio composition, and performance metrics. Minutes are stored in the enterprise document management system with role-based access. A summary of Committee activity, appropriately redacted, is made available to auditors and regulators on request. The Committee reviews and re-approves this charter every twenty-four months at minimum, or sooner if regulatory or business conditions change materially.9
Section 12. Appendices
Appendix A defines sub-committee composition, cadence, and delegated authority. Appendix B is the current Decision Authority Matrix. Appendix C is the AI Use Case Intake Form and Risk Classification Rubric. Appendix D is the reporting template used for the Board Audit Committee. Appendix E is the standing agenda and quarterly rhythm. Appendices are maintained by the Committee Secretary and updated between charter reviews as needed, with material changes approved by the Committee.
Tailoring guidance for mid-cap biotech. Do not add sections. Compress. If the same VP of Quality holds two seats, consolidate. If the Chief Privacy Officer role does not yet exist, name the senior-most privacy accountability holder and revisit at the next charter review. Keep the twelve sections; adjust the specifics inside them.
Committee Composition, Quorum, and Term Design
Composition is where mid-cap biotech charters most often fail. The temptation is either to keep the committee small enough that it functions like the existing exec team plus one, or to make it so large that no one owns anything. Neither works.
The recommendation of seven to nine voting members is calibrated for a mid-cap where roles are held by identifiable people rather than office layers. Cross-functional representation is not optional; effective governance is operational and cross-functional because AI simultaneously affects scientific workflows, submission quality, validation, and lifecycle management.10 Under-representing any of Quality, Medical/Scientific, Legal, or Privacy risks a decision that later needs to be reopened.
CIO or Head of Digital
Holds the enterprise view of AI systems and vendors. Runs the meeting, owns escalations to the CEO, and reports to the Board Audit Committee.
Head of Quality Assurance
Guardian of GxP integrity. Chairs the GxP AI Sub-Committee. Holds veto power on any use case that touches validated systems.
Head of Regulatory Affairs
Interprets FDA, EMA, MHRA, and PMDA expectations. Owns the mapping of use cases to regulatory submissions and inspection risk.
Chief Medical / Chief Scientific Officer
Represents the clinical and scientific risk view. In biotech, one person may hold both roles; that is acceptable in a mid-cap structure.
General Counsel
Owns contractual, IP, and regulatory liability exposure. Anchor for EU AI Act obligations and cross-border data considerations.
Chief Privacy / InfoSec Officer
Owns the confidentiality, integrity, and availability of models and their data. Anchor for GDPR, HIPAA, and secondary use questions.
Non-voting invitees matter as much as voting members. The Data Governance Council Chair should attend every meeting to keep the two councils aligned. The Head of Internal Audit should attend to observe, not to police, so that when audit later reviews AI processes it does so with context rather than surprise. The Committee Secretary, typically an AI Governance Program Manager, holds the minutes, tracks actions, and maintains the appendices. In a mid-cap biotech, this may be a fractional role at first; that is fine, but the role should not be vacant.
A composition trap. Do not staff the committee entirely with the people building AI. Data science and engineering leadership belong at the table as consulted parties, not as voting members. When the builders vote, the committee cannot credibly govern.
Term design matters more than most templates admit. Two-year terms with staggered rotation prevent institutional memory from evaporating when the CIO leaves. A rule that voting members cannot serve more than two consecutive terms preserves fresh perspective and prevents the Committee from becoming a fixed clique. In practice, mid-cap biotechs often need to grant term extensions during regulatory inspection windows or major submissions; the charter should permit that with Board Audit Committee notification.
The Decision Authority Matrix: RACI for AI Decisions
A charter without a Decision Authority Matrix is a policy document; a charter with one is a working operating model. The matrix below is written for a mid-cap biotech and assigns Responsible, Accountable, Consulted, and Informed roles across the AI decisions that most reliably create ambiguity. For high-risk decisions, we add a Signatory role, drawn from the RACI-VS variant used in regulated industries such as pharmaceuticals, which separates verification from approval to preserve audit-ready accountability.8
| AI Decision | Responsible | Accountable | Consulted | Signatory |
|---|---|---|---|---|
| Approve enterprise AI policy | Chair, AI Steering Committee | Chief Executive Officer | Board Audit Committee, General Counsel | CEO |
| Approve new high-risk use case | Use case sponsor | AI Steering Committee | Quality, Regulatory, Privacy, Legal, Data Governance | Chair, AISC + QA Head |
| Approve new moderate-risk use case | Use case sponsor | Sub-Committee Chair (GxP, Commercial, or Research) | Data Governance, Privacy | Sub-Committee Chair |
| Approve low-risk use case | Use case sponsor | Sub-Committee Chair | Data Governance | Sub-Committee Chair |
| Halt in-production AI system | Chair, AI Steering Committee | AI Steering Committee (supermajority) | System owner, Quality, Regulatory | Chair, AISC |
| Approve model retraining or major update | System owner | Sub-Committee Chair | Quality, Data Governance | Sub-Committee Chair |
| Approve third-party AI vendor | Head of Procurement | Chair, AI Steering Committee | Privacy, InfoSec, Legal, Data Governance | General Counsel + Chair, AISC |
| Approve AI use in a regulatory submission | Head of Regulatory Affairs | Chief Medical Officer | Quality, AISC Chair | CMO + Head of Reg Affairs |
| Approve external AI communication or claim | Head of Communications | General Counsel | Regulatory, Medical, Compliance | General Counsel |
| Investigate AI incident | Head of Internal Audit | Chair, AI Steering Committee | Legal, Privacy, InfoSec, system owner | Chair, AISC |
| Approve annual AI risk assessment | AI Governance PM | Chair, AI Steering Committee | All sub-committee chairs, Internal Audit | Chair, AISC |
| Report AI oversight to Board | Chair, AI Steering Committee | CEO | General Counsel, CFO | Chair, AISC + CEO |
The matrix does two useful things. It ends the recurring argument about who has final say on a specific type of decision, and it produces an audit trail that a regulator can follow. When FDA or EMA inspectors ask how a particular AI-supported decision was authorized, the Signatory column shows precisely who put their name on it and where the corresponding record lives. That is closer to how validated GxP systems are already governed, and it lowers the friction of extending existing quality practices to AI.
How to use the matrix without paralyzing the organization. The matrix is a decision tool, not a workflow tool. Do not build a fourteen-step approval process on top of it. For a low-risk use case, the sub-committee chair signs; that is one meeting, one signature. For a high-risk use case, the full committee signs; that is one meeting, one supermajority vote, one signature package. The volume of approvals should be proportional to the risk, not to the number of columns in the matrix.
Sub-Committees for GxP, Commercial, and Research
A mid-cap biotech does not have the bandwidth for the full Committee to see every use case. It also cannot afford a governance model where one committee treats a pharmacovigilance intake assistant, a sales territory optimizer, and a target discovery model as the same class of decision. Three sub-committees, each with its own risk lens, resolve both problems.
The GxP AI Sub-Committee
Chaired by the Head of Quality Assurance and composed of representatives from Regulatory Affairs, Manufacturing IT, Clinical Operations, Pharmacovigilance, and Validation, this sub-committee owns AI use cases that touch validated systems or regulatory decisions. Its lens is GAMP 5, ALCOA+, and the EMA reflection paper’s insistence on a risk-based, human-centered approach across the medicinal product lifecycle.3 This sub-committee reviews pharmacovigilance case-intake assistants, computerized system validation activities that use AI, AI-assisted regulatory submissions, and any AI system whose failure would create a deviation, CAPA, or regulatory reportable event.
What good looks like for GxP AI. The sub-committee reviews use cases at three checkpoints: intake (does this need to be validated?), pre-deployment (is validation complete and are controls in place?), and periodic review (is the model still performing within specification?). Each checkpoint produces a signed record that can be retrieved during inspection. The volume is manageable in a mid-cap biotech because most low-risk automation does not reach this sub-committee at all.
The Commercial AI Sub-Committee
Chaired by the Chief Commercial Officer or delegate and composed of representatives from Marketing, Sales Operations, Medical Affairs, Market Access, Compliance, and Privacy, this sub-committee covers use cases in customer engagement, market analytics, HCP targeting, content generation, and any AI that touches promotional review. Its lens is PhRMA Code compliance, OIG guidance, GDPR and HIPAA privacy considerations, and the reputational risk associated with AI-generated claims. The sub-committee also owns the interaction between Medical, Legal, and Regulatory (MLR) review workflows and any AI capability that generates content that will enter MLR.
The Research AI Sub-Committee
Chaired by the Chief Scientific Officer and composed of representatives from Discovery, Preclinical, Bioinformatics, Data Science, IP Counsel, and External Innovation, this sub-committee covers target discovery, molecular design, in silico modeling, translational research, and any collaboration with academic or platform partners where AI is central. Its lens is scientific reproducibility, IP protection, publication policy, and the emerging model risk considerations flagged in the EMA reflection paper for early-stage research uses that later inform regulatory submissions.3
Meets monthly
Validated systems, pharmacovigilance, regulatory. Signatory: QA Head. Escalates high-risk to full Committee.
Meets monthly
Marketing, sales, MLR, patient engagement. Signatory: CCO delegate. Escalates promotional claims to Legal.
Meets every six weeks
Discovery, translational, external collaborations. Signatory: CSO. Escalates novel platform partnerships to full Committee.
Sub-committee chairs sync
Every six weeks. Resolves jurisdictional overlaps, standardizes intake, aligns metrics.
The three sub-committees make three risks visible in ways the full Committee cannot. First, they reveal jurisdictional overlaps early. A generative AI tool that writes both regulatory narratives and marketing content belongs in more than one sub-committee, and the chairs need to decide who owns approval. Second, they create realistic escalation triggers. A sub-committee that operates only advisorily will not escalate anything; a sub-committee with delegated authority and a clear escalation criteria list will. Third, they normalize a portfolio view of AI risk that the full Committee can steer, rather than a series of one-off deep dives.
Interaction with Board Audit Committee and Data Governance Council
The AI Steering Committee is not the only governance body in the organization, and boards increasingly expect a clear picture of how the various bodies interact. In Deloitte’s boardroom survey, among directors who said a committee has been tasked with AI-related matters, the Audit Committee received the assignment in about a quarter of cases, second only to the risk and regulatory committee.11 That means, for many mid-cap biotechs, the Board Audit Committee is the destination for AI governance reporting, and the AI Steering Committee is the working body that feeds it.
The Board Audit Committee interface
The interface should be predictable, brief, and standardized. Prior to each regular Board Audit Committee meeting, the AI Steering Committee Chair delivers a one-page dashboard and a supplementary memo of no more than five pages. The dashboard covers portfolio composition (count of use cases by risk tier), performance and drift metrics for in-production systems, material incidents since the last report, upcoming high-risk approvals, and a red/amber/green rating of the overall governance posture. The memo elaborates on any red or amber items and any decisions that require Board awareness.
Between meetings, the Chair may escalate a matter directly to the Board Audit Committee Chair when material risk warrants it. This is not a routine channel; it is the exception. When it is used, it should be used decisively, because directors who feel they are being surprised by AI matters they should have seen earlier lose confidence in the entire governance structure.
The Data Governance Council interface
Whether AI governance and data governance are one council or two is a debated question. Some organizations, notably AstraZeneca, have chosen to integrate AI governance within enterprise data governance, arguing that AI risk is primarily data risk.12 Others separate the two, arguing that AI governance requires distinct expertise, moves at a different cadence, and carries obligations (such as EU AI Act obligations) that data governance does not.13
For a mid-cap biotech, we generally recommend two separate councils with a deliberately designed interface. Data governance approves the data foundation on which AI is built: sources, quality, lineage, master data definitions, retention, and access. AI governance approves the AI application on top of that foundation: use case selection, model validation, human oversight, monitoring, and lifecycle management. The two councils share a joint intake pipeline; a use case cannot enter the AI Steering Committee agenda unless its data foundation has been approved by the Data Governance Council. The two chairs meet monthly to reconcile the pipeline and resolve jurisdictional questions.
Where the interface most often breaks. A Data Governance Council that approves a data product without knowing it will be used to train an AI model creates a downstream mismatch. An AI Steering Committee that approves a use case without confirming the data foundation is fit for purpose signs its name to a risk it cannot see. The joint intake pipeline is not administrative overhead; it is where these two failure modes are prevented.
Interaction with the Enterprise Risk Committee and Compliance
The AI Steering Committee also touches the enterprise risk register and the compliance function. Every high-risk AI use case should appear on the enterprise risk register with its own owner, treatment plan, and residual risk rating. The Compliance and Ethics function receives whistleblower reports concerning AI, retains independence from the Committee, and reports separately to the Board Audit Committee on its findings. This is a healthy tension, not a duplication. Governance is stronger when the body that authorizes AI is not the same body that investigates its misuse.
The Standing Agenda and Quarterly Rhythm
A charter can be beautifully written and still fail because the meetings drift. A standing agenda solves for that. The recommended agenda below fits a two-hour monthly meeting and preserves time for the discussions that actually move the portfolio, rather than status theater.
Consent agenda (10 minutes)
Minutes approval, action item status, low-risk use case ratifications from sub-committees, standard KPI review.
Portfolio and risk dashboard review (20 minutes)
Portfolio composition, in-production performance and drift, incidents since last meeting, red/amber items requiring discussion.
High-risk use case reviews (45 minutes)
One to three deep dives on new high-risk use cases or in-production systems requiring re-approval. Sponsor presents, committee decides.
Cross-committee coordination (15 minutes)
Data Governance Council update, Compliance update, sub-committee chair reports, jurisdictional resolutions.
Emerging topics and regulatory horizon (20 minutes)
New regulatory guidance, external incidents, emerging vendor risks, policy updates for approval or discussion.
Executive session (10 minutes)
Voting members only. Chair confirms decisions and identifies any items to escalate to CEO or Board Audit Committee.
The quarterly rhythm layers on additional discipline. In Q1, the Committee re-approves the annual AI policy, reviews the risk assessment, and confirms sub-committee charters and appendices. In Q2, the Committee conducts a portfolio strategic review, evaluating whether the mix of use cases still aligns with corporate priorities. In Q3, the Committee focuses on vendor and third-party risk, reviewing all material AI vendor relationships and the state of contractual protections. In Q4, the Committee prepares the Board-level annual report, forecasts the year-ahead governance agenda, and refreshes the Decision Authority Matrix.
Escalation Paths and Stop-Work Authority
Stop-work authority is the single most contested provision in an AI governance charter. Everyone agrees, in principle, that the Committee should be able to halt an AI system that presents unmitigated risk. In practice, halting an in-production system is expensive, disruptive, and politically difficult, particularly when the system supports a commercial or clinical priority. The charter must be explicit enough that the authority is real when it is needed.
Three distinct escalation channels
The first channel is the routine one. Any Committee member, any sub-committee chair, or the Chief Compliance Officer may raise a concern about an AI system to the Committee agenda. The system owner is notified, given a chance to respond, and the Committee decides at its next meeting. Most concerns resolve here.
The second channel is the urgent one. Where a Committee member, the Chief Compliance Officer, or the General Counsel identifies a risk that cannot wait for the next meeting, the matter is escalated to the Chair, who may exercise delegated authority to require immediate mitigation, restrict system usage, or halt the system pending Committee review. The Chair must notify Committee members within one business day and convene an extraordinary session within five business days.
The third channel is the board-level one. Where the Committee itself is conflicted, the CEO is unavailable, or the Chair believes the matter requires board attention, the Chair escalates directly to the Board Audit Committee Chair. This is a deliberately narrow channel; overuse would undermine confidence in the working committee.
The stop-work moment is what tests the charter. If the Committee has never halted a system, it is either extremely disciplined at the intake stage or lacks the credibility to invoke the authority. Boards should ask both possibilities directly. Regulators, in FDA’s finalized guidance direction, expect that governance structures can and do intervene when models fail their intended-use conditions.14
Whistleblower and independent-channel matters
The Committee does not investigate whistleblower reports concerning AI misuse. Those reports flow through Compliance and Ethics, are investigated independently, and are reported to the Board Audit Committee on Compliance’s own cadence. The Committee is informed of trends and systemic issues but does not review individual reports. This separation preserves the credibility of both bodies.
The 90-Day Committee Stand-Up Plan
The gap between “we should charter this properly” and “we have chartered this properly” is where most mid-cap biotechs stall. The plan below is structured so that a company with an existing working group can complete the stand-up in ninety days without pausing AI activity. A company with no existing working group can still complete it in ninety days but should expect the first thirty days to be more difficult.
Days 1 to 30: Foundation
Secure CEO sponsorship and Board Audit Committee notification
The CEO signs a memo endorsing the charter effort and notifies the Board Audit Committee Chair. Without this step, the Committee has no authority to invoke; with it, the Committee has authority from day one.
Identify voting members and secure their acceptance
Seven to nine names. Each candidate accepts in writing, acknowledging the time commitment and the fiduciary posture of the role. Alternates are also named.
Draft the charter and Decision Authority Matrix
Start from the template above. Adapt sections to the organization’s structure and existing policy landscape. Circulate a two-page executive summary for CEO and Board Audit Committee review before the full charter goes for approval.
Take an inventory of existing AI activity
Every AI use case, every third-party AI vendor, every model in development, in pilot, or in production. Do not filter; visibility is the point. Classify each into low, moderate, or high risk using a draft rubric.
Days 31 to 60: Formalization
Approve and publish the charter
CEO signs. Charter is published internally with the Decision Authority Matrix. Legal reviews for consistency with existing policies and contractual obligations.
Stand up the three sub-committees
Chairs named, members recruited, sub-committee charters adopted. Each sub-committee holds an inaugural meeting focused on inventory review and prioritization within its domain.
Hold the first three full Committee meetings
Meeting 1: ratify inventory, approve risk rubric, adopt standing agenda. Meeting 2: review first tranche of moderate-risk use cases, resolve any escalations from sub-committees. Meeting 3: begin high-risk deep dives.
Establish the Data Governance Council interface
Joint intake pipeline is stood up. Both chairs sign a one-page memorandum documenting the interface. First joint review of shared items is completed.
Days 61 to 90: Operating rhythm
Deliver the first Board Audit Committee report
One-page dashboard and five-page memo. Cover portfolio composition, red/amber items, upcoming high-risk approvals, and any decisions that require board awareness. Ask the Audit Committee for feedback on the format.
Publish the annual AI training and awareness curriculum
Role-based modules for the full workforce, additional modules for AI builders and system owners, and executive-level briefings for the Board. Curriculum is approved by the Committee.
Complete the first end-to-end high-risk use case approval
A single high-risk use case is taken from intake through data governance approval, sub-committee review, full committee approval, and signed record. This is the test that the mechanism actually works.
Retrospective and calibration
Ninety-day review with the Committee. What worked, what stalled, what to adjust. Update the appendices as needed. Confirm the next twelve-month calendar.
What a successful stand-up looks like at day 90. The Committee has met three times. Each sub-committee has met at least twice. The inventory is complete and risk-classified. The Data Governance Council interface is documented and functioning. The Board Audit Committee has received one report and endorsed the format. At least one high-risk use case has gone through the full mechanism. And the CEO has publicly reinforced the Committee’s authority at least once, in an all-hands or leadership forum, so that the organization understands the Committee is not a suggestion.
Failure Modes to Anticipate
A charter that survives its first ninety days can still fail in its second or third year if the Committee does not actively defend the discipline it installed. The failure modes below are the ones we most often see in mid-cap biotech, and each has a countermeasure.
The charter becomes a document, not an operating model
Symptom: the charter is signed, filed, and referenced only when Legal asks. Meetings continue but no one uses the Decision Authority Matrix. Countermeasure: the Secretary reads out the Signatory column for every decision at every meeting until it becomes reflex. Minutes explicitly cite the Matrix. The Board Audit Committee report references it. The Matrix is not a chart; it is the script.
The Committee becomes a bottleneck
Symptom: builders start avoiding the Committee. Use cases enter production without approval. The Committee looks busy but is losing ground. Countermeasure: audit the intake pipeline monthly. If sub-committees are not receiving enough intake, either the workforce does not know the intake exists (a communication problem) or the intake is too onerous (a design problem). Both are fixable; ignoring them is fatal.
Sub-committees drift into advisory roles
Symptom: sub-committees discuss but do not decide. Everything escalates to the full Committee, overwhelming its agenda. Countermeasure: the Decision Authority Matrix is enforced. If a sub-committee is delegated authority for moderate-risk use cases, moderate-risk decisions do not appear on the full Committee agenda except by exception.
Governance widens faster than the mid-cap can sustain
Symptom: the Committee adds a new sub-committee, a new appendix, a new working group each quarter. The organization stops being able to keep up. Countermeasure: the charter review every twenty-four months is not ceremonial. Sections and appendices that are not producing value are removed. Adding to the charter should require the same rigor as removing from it.
The Board loses the plot
Symptom: the Board Audit Committee starts asking for more detail, more often, with less structure. The Chair spends more time preparing than deciding. Countermeasure: agree on the one-page dashboard format at the outset. Preserve it. When the Board asks for more, offer to schedule a dedicated deep dive rather than lengthen the standing report. Predictable reporting is what sustains director confidence.
Conclusion
The move from an AI working group to a governed AI Steering Committee is one of the more important transitions a mid-cap biotech will make in the next eighteen months. Regulators have already made the move on their side; FDA has consolidated its own AI oversight, the EU AI Act’s applicability is imminent, and EMA has committed to a risk-based lifecycle approach. Investors are asking about it. Boards are being briefed on it. The organizations that treat the move as procedural, rather than strategic, will find themselves reworking their governance later under external pressure. The organizations that treat it as strategic will find that the charter, the Decision Authority Matrix, and the sub-committee structure become the operating chassis on which their AI portfolio actually accelerates.
Sakara Digital works with pharma and biotech organizations building this kind of AI governance chassis. If you are standing up an AI Steering Committee, revising a charter that no longer fits, or trying to design the interface between AI governance and data governance in a way that actually holds under audit, we are happy to have that conversation. The template in this article is meant to be adapted, not adopted verbatim; we help mid-cap biotechs do the adaptation with the specificity their regulators, boards, and scientists all need.
References & Sources
- U.S. Food and Drug Administration. “Artificial Intelligence for Drug Development” (CDER AI Council overview). FDA, 2024. https://www.fda.gov/about-fda/center-drug-evaluation-and-research-cder/artificial-intelligence-drug-development
- USDM Life Sciences. “EU AI Act Compliance for Pharma and Life Sciences: What to Prepare Before August 2026.” USDM, 2025. https://www.usdm.com/resources/blogs/the-eu-ai-act
- European Medicines Agency. “Reflection paper on the use of artificial intelligence in the lifecycle of medicines.” EMA, adopted September 2024. https://www.ema.europa.eu/en/news/reflection-paper-use-artificial-intelligence-lifecycle-medicines
- IQVIA. “How Emerging AI Capabilities Are Reshaping Life Sciences.” IQVIA Blogs, October 2025. https://www.iqvia.com/blogs/2025/10/how-emerging-ai-capabilities-are-reshaping-life-sciences
- Deloitte Global. “Governance of AI: A critical imperative for today’s boards, 2nd edition.” Deloitte Global Boardroom Program, 2025. https://www.deloitte.com/global/en/issues/trust/progress-on-ai-in-the-boardroom-but-room-to-accelerate.html
- Gartner. “Global AI Regulations Fuel Billion-Dollar Market for AI Governance Platforms.” Gartner Press Release, February 17, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-02-17-gartner-global-ai-regulations-fuel-billion-dollar-market-for-ai-governance-platforms
- National Institute of Standards and Technology. “AI Risk Management Framework.” NIST, 2023-. https://www.nist.gov/itl/ai-risk-management-framework
- Agility at Scale. “RACI Matrix for AI Accountability: Template, Guide, and Implementation.” Agility at Scale, 2025. https://agility-at-scale.com/ai/governance/raci-matrix-for-ai-accountability/
- Info-Tech Research Group. “Enterprise AI Governance Committee Charter Example.” Info-Tech, 2025. https://www.infotech.com/research/enterprise-ai-governance-committee-charter-example
- BioProcess Online. “AI Has Arrived In Biotech CMC Amid Patchwork Governance.” BioProcess Online, 2026. https://www.bioprocessonline.com/doc/ai-has-arrived-in-biotech-cmc-amid-patchwork-governance-0001
- Deloitte. “Artificial Intelligence: An Emerging Oversight Responsibility for Audit Committees?” Deloitte Center for Board Effectiveness. https://www.deloitte.com/us/en/programs/center-for-board-effectiveness/articles/artificial-intelligence-an-emerging-oversight-responsibility-for-audit-committees.html
- CDO Magazine. “Should AI Governance Stand on Its Own? AstraZeneca CDO Weighs In.” CDO Magazine, 2025. https://www.cdomagazine.tech/aiml/should-ai-governance-stand-on-its-own-astrazeneca-cdo-weighs-in
- Koenders, Willem. “Should data and AI governance councils be separate?” ZS Associates on Medium, 2024. https://medium.com/zs-associates/should-data-and-ai-governance-councils-be-separate-3f4bec727e00
- Applied Clinical Trials. “FDA and EMA Align on Ten Principles to Guide Artificial Intelligence Use in Drug Development.” Applied Clinical Trials, 2025. https://www.appliedclinicaltrialsonline.com/view/fda-ema-align-ten-principles-artificial-intelligence-use-drug-development
- Trustible. “How to Establish an Effective AI Governance Committee in 2026.” Trustible Blog, 2026. https://trustible.ai/post/how-to-establish-an-effective-ai-governance-committee-in-2026/








Your perspective matters—join the conversation.