This deep dive expands on the Loop Asia conversation with Koo Ping Shung, Practicum Director at Data Science Rex.
Koo Ping Shung named five disciplines a national-level AI governance body needs: technical, technology law and jurisprudence, economics, policy-making, and audit or regulatory background. At company level, he adds a sixth — marketing and PR, for when something goes wrong, not for the launch.
Most "AI governance committees" stood up in the last two years are smaller than that: a data science lead, a compliance reviewer, a VP's sign-off. That's a checklist with two signatures. Each discipline Koo lists that's missing maps to a specific failure mode you'll eventually hit.
Why "technical" alone doesn't cover it
A technical person on the committee is non-negotiable, Koo says — but technical expertise answers a narrower question than most committees assume. A data scientist can tell you whether a model performs within expected error bounds. They can't tell you whether that bound is acceptable given who bears the cost of a wrong decision, whether the training data reflects the population you serve, or whether the decision needs a legal basis that survives audit. Different questions, different people — not deferred to whoever understands "the AI part."
The gap shows up like this: a model performs well on aggregate and gets approved, and the disparate impact on one subgroup only surfaces after a complaint or a regulator finds it. Technical sign-off alone has no mechanism to catch that before it ships, because nobody was tasked with asking.
Economics and policy aren't decoration
It's tempting to treat economics and policy-making as government-only disciplines. Koo's framing says otherwise. Economics is the seat asking what a constraint costs against the risk it prevents — over-constrain and you kill the business case; under-constrain and you're exposed. Somebody needs to own that trade-off explicitly, rather than default to whoever's most risk-averse in the room that week.
The policy seat thinks in second-order effects — not "does this model work" but "what happens across the organisation once this pattern runs at scale." Koo's point that national policy touches manpower, education, healthcare, and environment has a commercial analog: an AI-driven pricing or credit decision touches customer trust, sales incentives, support load, and legal exposure — none of which show up in an accuracy metric.
Audit: the seat that makes it real
The discipline most committees skip — audit and regulatory background — decides whether everything else is theatre. A framework nobody can enforce or externally verify exists on paper only. If your committee can state its principles but can't answer how it would prove to a regulator the framework is actually followed, you have intentions, not governance. That means governance can't live entirely inside the technology function; it needs someone who thinks like an external auditor — what evidence exists, what's the paper trail, what fails under scrutiny.
What this means for the committee you actually build
Few organisations can staff six specialists onto a governance body, and Koo isn't arguing they need to. The useful reframe: treat each discipline as a question that must be explicitly asked and owned in every decision — technical soundness, legal exposure, economic trade-off, downstream effect, enforceability — rather than assume one reviewer covers all five. A committee that names the gaps it isn't staffing is in a stronger position than one that doesn't know the gaps exist.
Not sure which seats your AI governance committee is missing?
Working out which of these disciplines an organisation actually needs — and filling the gap without building a bureaucracy that kills the programme's pace — is exactly where I help.