Introduction: The Rise of the Algorithmic Corporation
Artificial Intelligence (AI) and Machine Learning (ML) are transitioning from operational utilities to core strategic decision-makers within corporate entities.
A decade ago, an algorithm in a Ghanaian bank might have flagged suspicious transactions for a human officer to review. Today, algorithms score loan applications end-to-end, set dynamic prices, screen job candidates, forecast cash flows, allocate marketing budgets, and increasingly draft the very reports that boards rely upon to discharge their duties.
The corporation is becoming, in a meaningful operational sense, algorithmic, and the pace of this transition has accelerated sharply with the commercial availability of generative AI.
This transition has exposed a critical vulnerability in corporate governance: the structural inability of boards of directors to effectively oversee technologies they did not design, cannot fully inspect, and frequently do not understand. Scholars describe this as an “accountability gap,” the space between an algorithm’s real-world consequences and the governance structures nominally responsible for them (Raji et al., 2020).
The gap widens as models grow more complex, as decision authority migrates from humans to systems, and as the vendors who build those systems sit outside the governance perimeter of the firms that deploy them.
The stakes for Ghana are not abstract. Our banks, insurers, pension trustees, telecommunications firms, and FinTechs are deploying ML at scale in a market where regulatory capacity is stretched and where the memory of the 2017–2019 financial sector clean-up remains fresh.
That crisis taught us that governance failures, not merely technical failures destroy institutions and household savings. The question this paper poses is simple: when the next governance failure arrives wearing the clothes of an algorithm, will our corporate governance architecture even recognise it?
Understanding the Accountability Gap
The accountability gap is best understood through its casualties. In one of the most cited studies of algorithmic harm, researchers examining a widely used American healthcare algorithm found that it systematically assigned lower risk scores to Black patients than to equally sick white patients, because the model used healthcare cost as a proxy for healthcare need, a design choice that no board had interrogated and few executives understood (Obermeyer, Powers, Vogeli, & Mullainathan, 2019).
The bias affected decisions for millions of patients before independent researchers, not internal governance, exposed it.
Public institutions are not immune. The Dutch childcare benefits scandal, in which an algorithm used by tax authorities wrongly flagged thousands of families, disproportionately those with immigrant backgrounds, for fraud, ultimately brought down a national government. Experimental research conducted in its aftermath demonstrated the underlying human mechanism: decision-makers exhibit “automation bias,” deferring to algorithmic advice even when confronted with contradictory warning signals from other sources (Alon-Barkat & Busuioc, 2023).
Markets have supplied their own cautionary tales: in late 2021, the American property firm Zillow shut down its algorithm-driven home-buying business and wrote down hundreds of millions of dollars after its pricing models systematically overpaid for houses, a strategic failure produced not by fraud, but by unchallenged confidence in a model.
Three features unite these episodes. First, the harm was generated by design choices; proxies, training data, objective functions, made far below board level. Second, existing oversight structures (audit committees, risk committees, external auditors) neither detected nor prevented the failure, because none of them was looking at the model. Third, accountability, when it finally arrived, was assigned to humans: executives resigned, governments fell, shareholders sued.
The algorithm did the damage; the governance structure bore the consequences. That asymmetry is precisely why algorithmic accountability is a corporate governance problem, not merely a technology problem.
Ghana’s Governance Architecture: Strengths and Silences
Ghana has made commendable progress in formalising corporate governance. The Companies Act, 2019 (Act 992) modernised directors’ duties, codifying the duty to act in good faith and in the best interests of the company and to exercise the degree of care and skill of a reasonably diligent person (Republic of Ghana, 2019).
The Securities and Exchange Commission’s Corporate Governance Code for Listed Companies, published in October 2020, imposes rigorous requirements on board composition, boards of five to thirteen members, limits on multiple directorships, a majority-independent audit committee including a chartered accountant with recent and relevant financial experience, as well as on risk management, remuneration, and disclosure (Securities and Exchange Commission Ghana [SEC Ghana], 2020).
The Bank of Ghana’s Corporate Governance Directive for banks, issued in the wake of the financial sector clean-up, added fit-and-proper standards and board accountability requirements for the financial sector. The Institute of Directors, Ghana has complemented this legal architecture with director training and certification.
These frameworks, however, were designed for an era of human-centric decision-making. Read the SEC Code from cover to cover and you will find careful provisions on board charters, committee composition, and related-party transactions but not a single provision addressing algorithmic decision-making. There is no requirement that boards understand, audit, or even inventory the AI systems making consequential decisions inside their companies.
There is no obligation to disclose to shareholders that credit decisions, pricing, or financial forecasts are model-generated, no standard for validating those models, and no allocation of committee responsibility for algorithmic risk. Ghana’s Data Protection Act governs personal data processing, but data protection is not model governance: a model can be fully compliant with data protection law and still be biased, unstable, or strategically dangerous. The architecture is strong; the silence at its centre is the problem.
The Fiduciary Duty Problem
This silence matters because the law will not remain silent when things go wrong. When an ML model generates a flawed financial projection, misprices credit risk, or introduces systemic bias into lending decisions, the fiduciary duty still rests squarely with the board of directors. Ghanaian company law does not recognise “the algorithm did it” as a defence. Under Act 992, a director must exercise independent judgment and reasonable care, skill, and diligence; a director who rubber-stamps model outputs he cannot interrogate has arguably delegated his judgment to a machine, something the law never contemplated and does not permit (Republic of Ghana, 2019).
Consider the practical scenarios. A bank’s credit-scoring model drifts as economic conditions change, quietly tightening lending to an entire region; the board learns of it from a Bank of Ghana query. An insurer’s pricing algorithm, trained on historical data, discriminates against informal-sector workers; the board learns of it from the press. A listed firm’s revenue forecast, produced by an ML pipeline with a data error, misleads the market; the board learns of it from a restatement. In each case, directors will be asked the same questions: Did you know the model existed? Did you ask how it was validated? Who was responsible for it? If the honest answers are no, no, and nobody, then oversight was ceremonial rather than substantive, and governance, in any meaningful sense, failed before the algorithm did.
Regulatory Lessons from the United States
We can draw direct regulatory lessons from the U.S. Securities and Exchange Commission. Following high-profile data breaches and the rapid integration of generative AI, the U.S. SEC finalised rules in July 2023 requiring public companies to disclose material cybersecurity incidents within four business days and to describe, in their annual reports, the board’s oversight of cybersecurity risk and management’s role and expertise in assessing and managing it (U.S. Securities and Exchange Commission [U.S. SEC], 2023).
The underlying regulatory philosophy is what matters for Ghana: technology risk is now treated as a board-level fiduciary matter, subject to mandatory disclosure, rather than an IT-department concern. Disclosure obligations are governance-forcing devices, a board cannot describe its oversight of a risk it has never discussed. The market response is equally instructive. A growing number of S&P 500 companies have established dedicated Technology or AI Committees, recruited directors with data science backgrounds, and commissioned regular audits of machine learning models for security, bias, and strategic alignment. None of this was directly mandated; it emerged because disclosure rules, litigation risk, and investor expectations converged to make algorithmic oversight a condition of credibility. Ghana can reach the same destination faster, and at lower cost, by learning from this sequence rather than repeating its crises. A Global Convergence Ghana Cannot Ignore
The direction of international travel is unmistakable. The European Union’s Artificial Intelligence Act, which entered into force in 2024, classifies credit scoring and employment-related algorithms as “high-risk” systems subject to mandatory risk management, data governance, documentation, human oversight, and conformity assessment obligations (European Union, 2024).
Ghanaian firms that process EU-linked business, or that seek European capital, will feel its extraterritorial pull. The United States’ National Institute of Standards and Technology has published an AI Risk Management Framework, built around the functions of governing, mapping, measuring, and managing AI risk, that is rapidly becoming the de facto benchmark for enterprise AI governance (NIST, 2023).
The International Organization for Standardization has issued ISO/IEC 42001, the first certifiable AI management system standard, giving boards and auditors an assurance-ready reference point (International Organization for Standardization, 2023).
Nor is this solely a Global North agenda. In July 2024, the African Union Executive Council adopted the Continental Artificial Intelligence Strategy, fittingly, at its session held in Accra, calling on member states to build Africa-centric, ethical, and responsible AI governance frameworks (African Union, 2024). Ghana hosted the continent’s commitment to AI governance; it should not be among the last to give that commitment corporate-governance teeth. Institutional investors conducting due diligence on Ghanaian firms will increasingly measure our governance architecture against these converging standards, and capital will price the gap.
Proposal 1: Mandating Algorithmic Literacy for Directors
Technical fluency is no longer optional for board members. The Institute of Directors, Ghana should integrate a mandatory, continuous certification module focused on AI risk, data governance, and algorithmic auditing, mirroring the continuing professional development already required in financial reporting and anchored to recognised international frameworks (NIST, 2023; International Organization for Standardization, 2023).
Directors need not become data scientists, any more than audit committee members must be able to prepare consolidated financial statements. What they must be able to do is ask, and evaluate the answers to, a disciplined set of questions.
A serious curriculum would equip directors to interrogate at least five things. First, data provenance: what data trained this model, who owns it, and does it represent the population the firm actually serves, including Ghana’s informal sector? Second, model drift: how is performance monitored after deployment, and what triggers retraining or withdrawal? Third, explainability: can the firm explain an individual adverse decision, a declined loan, a rejected claim to the customer and to a regulator? Fourth, vendor risk: where models are procured rather than built, what audit rights, performance warranties, and liability allocations does the contract secure? Fifth, generative AI: what policies govern the use of large language models in preparing analyses and disclosures that boards will rely upon? A director who can press management on these five fronts transforms AI oversight from theatre into governance. The lesson of automation bias research is that unprompted scepticism cannot be assumed; it must be trained (Alon-Barkat & Busuioc, 2023).
Proposal 2: Integrating ML Audits into Statutory Oversight Audit committees are the foundation of financial oversight in Ghanaian firms; under the SEC Code they must be majority-independent and include chartered accountancy expertise (SEC Ghana, 2020).
I propose that the Institute of Chartered Accountants, Ghana (ICAG) and the Internal Audit Agency expand their guidelines to require the periodic auditing of AI and ML models used in financial reporting, credit decisioning, and risk management. Just as financial statements are stress-tested, the algorithms generating those statements must be validated for accuracy, robustness, and bias.
The methodological groundwork already exists and need not be invented locally. The internal algorithmic audit framework developed in the accountability literature sets out a structured, end-to-end procedure, scoping the system and its use case, mapping stakeholders and failure modes, collecting design and testing artifacts, conducting adversarial and bias testing, and closing the loop with documented remediation, explicitly designed so that organisations can audit AI systems against their own principles before harm occurs, not after (Raji et al., 2020).
Complementing this, standardised documentation practices such as “model cards” short, structured reports disclosing a model’s intended use, performance across demographic groups, and known limitations, give audit committees a reviewable artifact in the same way that financial statements give them accounts to examine (Mitchell et al., 2019).
Institutionally, the reform maps cleanly onto the three-lines-of-defence model Ghanaian financial institutions already use. Management owns model development and validation (first line); risk and compliance functions set model-risk policy and challenge (second line); internal audit provides independent assurance over the whole (third line), reporting to the audit committee. ICAG’s role is to issue the assurance guidance and build the competency pipeline; the Internal Audit Agency’s role is to embed model audit in the public-sector entities and state-owned enterprises where algorithmic procurement is accelerating. External auditors, for their part, will increasingly confront ML-generated estimates within the financial statements themselves, expected credit losses under IFRS 9 being the obvious example, and will need Ghanaian guidance on auditing through, rather than around, the model.
Proposal 3: Leveraging Cognitive Diversity as a Risk-Mitigation Tool My published research on board gender diversity and financial performance in Ghana demonstrates that diverse boards are associated with stronger firm outcomes and are more effective at mitigating groupthink (Atisu, Akuamoah, & Mensah, 2024). This finding is consistent with earlier Ghanaian evidence linking gender-diverse boards to improved bank efficiency (Adeabah, Gyeke-Dako, & Andoh, 2019). In the context of AI, the stakes of homogeneity rise sharply. Automation bias is, at root, a failure of challenge: a room in which everyone shares the same training, the same heuristics, and the same deference to quantitative output is a room in which the model’s errors compound unopposed (Alon-Barkat & Busuioc, 2023).
The policy lever is already half-built. The SEC Code requires boards to adopt a gender-balance policy with defined timelines (SEC Ghana, 2020). I propose extending this logic: nomination committees should be required to assess and disclose the board’s cognitive diversity, of gender, professional discipline, sector experience, and technical background, explicitly as an algorithmic-risk control, and to explain how the board’s composition equips it to challenge model-driven recommendations. A board that contains a data-literate director, a consumer-facing perspective, and members whose lived experience mirrors the customers the firm’s algorithms score is statistically and structurally better equipped to catch the failure modes that homogeneous boards wave through. Diversity, in this framing, is not a social aspiration appended to governance; it is a control environment for the algorithmic age.
Anticipating the Objections
Three objections deserve honest answers. The first is cost: smaller listed firms will protest that model audits and director certification are expensive. The answer is proportionality. Obligations should scale with the materiality of algorithmic decision-making—a firm whose only ML is a marketing tool should face lighter requirements than a bank whose lending book is model-priced. A comply-or-explain tier, familiar from governance codes worldwide, can bridge the transition. The second objection is talent scarcity: Ghana has few algorithm auditors today. True, but the same was said of IFRS specialists two decades ago, and demand created supply. Embedding competencies in ICAG and IoD curricula is precisely how a national talent pipeline is built, and it is a far cheaper strategy than importing crisis consultants after a failure.
The third objection is that regulation will chill innovation. The international evidence suggests the opposite: clear governance expectations reduce uncertainty, and firms that can demonstrate audited, well-governed AI will find it easier, not harder to attract international capital measured against EU, NIST, and ISO benchmarks (European Union, 2024; NIST, 2023). The genuinely chilling scenario is an algorithmic scandal in a governance vacuum, followed by panicked over-regulation.
An Implementation Roadmap
Reform should proceed in three phases. In the first twelve months, the SEC Ghana should issue a guidance note, without amending the Code, asking listed companies to disclose, on a comply-or-explain basis, an inventory of material AI systems, the committee responsible for their oversight, and the validation practices applied to them. Disclosure alone will force the internal conversations that currently do not happen. In parallel, IoD–Ghana should pilot its algorithmic literacy module with audit committee chairs, and ICAG should convene a working group on model assurance guidance drawing on the frameworks discussed above (Raji et al., 2020; Mitchell et al., 2019; International Organization for Standardization, 2023).
In the second phase, spanning roughly years two and three, the SEC should amend the Corporate Governance Code to make algorithmic oversight an explicit board responsibility, require the disclosure of board-level AI expertise and training, and extend the gender-balance policy into a broader cognitive-diversity assessment. ICAG and the Internal Audit Agency should issue their model-audit guidelines, and the Bank of Ghana should align its supervisory expectations for banks’ model risk management.
In the third phase, supervision begins in earnest: thematic reviews of algorithmic governance disclosures, model-audit inspection as part of routine examination, and enforcement where disclosure proves to have been decorative. The sequence matters—disclose, build capacity, mandate, enforce—because it gives firms time to comply and regulators time to learn.
Implications for Policy and Practice
For policymakers and regulators, the immediate implication is that the next revision of the SEC Ghana Corporate Governance Code should explicitly name AI and algorithmic systems as a board-level risk category, in the same way the U.S. SEC has done for cybersecurity (U.S. SEC, 2023). Requiring listed companies to disclose whether and how the board oversees algorithmic decision-making would cost little, yet would immediately elevate the issue from the IT department to the boardroom. The Bank of Ghana should mirror this in its supervision of banks and specialised deposit-taking institutions, where credit-scoring algorithms already carry systemic consequences, and Ghana’s implementation of the African Union’s Continental AI Strategy should treat corporate governance as a named workstream rather than an afterthought (African Union, 2024).
For professional bodies, the IoD–Ghana and ICAG hold the practical levers. Embedding algorithmic literacy in director certification, and model-audit competencies in the continuing professional development of accountants and internal auditors, would build national capacity ahead of regulation rather than behind it. Anchoring these curricula to recognised international standards such as the NIST AI Risk Management Framework and ISO/IEC 42001 (NIST, 2023; International Organization for Standardization, 2023) would also make Ghanaian certifications portable and credible to international investors, and could position Ghana as the West African hub for algorithmic assurance services.
For boards and executives, the message is that fiduciary duty already covers the algorithm. Directors should not wait for a mandate to commission an inventory of the AI systems making consequential decisions in their firms, assign clear committee ownership of AI risk, demand periodic independent model audits, and insist on reviewable documentation such as model cards for material systems (Mitchell et al., 2019). Nomination committees should treat cognitive diversity, of gender, discipline, and professional background as a documented risk-mitigation tool against automation bias, not a box-ticking exercise (Alon-Barkat & Busuioc, 2023; Atisu, Akuamoah, & Mensah, 2024).
For investors and the public, the implication is a new due-diligence question. Pension trustees, institutional investors, and analysts covering Ghanaian equities should begin asking boards how algorithmic decisions are governed—and treating the absence of an answer as the risk signal it is. Market discipline of this kind has historically moved boards faster than regulation alone. Conclusion
Ghana’s corporate governance architecture was built for human decision-makers, but strategic decisions in our companies are increasingly shaped by machines. This paper has traced the accountability gap through its international casualties, shown that Ghana’s otherwise robust framework, Act 992, the SEC Code, the Bank of Ghana’s directives is silent precisely where algorithms speak loudest, and argued that closing the gap requires three coordinated moves: mandatory algorithmic literacy for directors, the integration of ML model audits into statutory oversight, and the deliberate use of cognitive diversity as a defence against automation bias. A phased roadmap, disclose, build capacity, mandate, enforce makes the reform practicable rather than punitive.
None of this demands new technology; it demands governance will. Algorithmic accountability is not a compliance burden but a competitive asset, the foundation on which resilient firms, credible disclosure, and investor confidence are built, and the corporate-governance expression of the AI ambitions the African Union adopted on Ghanaian soil (African Union, 2024). The SEC Ghana, IoD–Ghana, and ICAG have a window to act before the first algorithmic governance failure forces their hand. The boardrooms that will thrive in the AI era are those that learn to govern the machine before the machine’s errors govern them.
References
Adeabah, D., Gyeke-Dako, A., & Andoh, C. (2019). Board gender diversity, corporate governance and bank efficiency in Ghana: A two stage data envelope analysis (DEA) approach. Corporate Governance: The International Journal of Business in Society, 19(2), 299–320. https://doi.org/10.1108/CG-08-2017-0171
African Union. (2024). Continental Artificial Intelligence Strategy: Harnessing AI for Africa’s development and prosperity. African Union Commission.
https://au.int/en/documents/20240809/continental-artificial-intelligence-strategy
Alon-Barkat, S., & Busuioc, M. (2023). Human–AI interactions in public sector decision making: “Automation bias” and “selective adherence” to algorithmic advice. Journal of Public Administration Research and Theory, 33(1), 153–169. https://doi.org/10.1093/jopart/muac007
Atisu, J. C., Akuamoah, O. A., & Mensah, N. (2024). Board gender diversity and financial performance of listed and unlisted firms in Ghana. International Journal of Research Publication and Reviews, 5(1).
European Union. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
International Organization for Standardization. (2023). ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system. ISO. https://www.iso.org/standard/42001
Mitchell, M., Wu, S., Zaldivar, A., Barnes, P., Vasserman, L., Hutchinson, B., Spitzer, E., Raji, I. D., & Gebru, T. (2019). Model cards for model reporting. In Proceedings of the Conference on Fairness, Accountability, and Transparency (FAT* ’19) (pp. 220–229). ACM. https://doi.org/10.1145/3287560.3287596
National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce. https://doi.org/10.6028/NIST.AI.100-1
Obermeyer, Z., Powers, B., Vogeli, C., & Mullainathan, S. (2019). Dissecting racial bias in an algorithm used to manage the health of populations. Science, 366(6464), 447–453. https://doi.org/10.1126/science.aax2342
Raji, I. D., Smart, A., White, R. N., Mitchell, M., Gebru, T., Hutchinson, B., Smith-Loud, J., Theron, D., & Barnes, P. (2020). Closing the AI accountability gap: Defining an end-to-end framework for internal algorithmic auditing. In Proceedings of the 2020 ACM Conference on Fairness, Accountability, and Transparency (FAT* ’20) (pp. 33–44). ACM. https://doi.org/10.1145/3351095.3372873
Republic of Ghana. (2019). Companies Act, 2019 (Act 992). Government Printer, Assembly Press.
Securities and Exchange Commission Ghana. (2020). Corporate Governance Code for Listed Companies, 2020. SEC Ghana. https://sec.gov.gh
U.S. Securities and Exchange Commission. (2023). Cybersecurity risk management, strategy, governance, and incident disclosure (Release Nos. 33-11216; 34-97989). https://www.sec.gov/rules/final/2023/33-11216.pdf
About the Author: Jerome Christopher Atisu is a Corporate Finance and Governance Expert, and a Legal Accountant with the Judicial Service of Ghana.
He holds an MSc in Industrial Finance and Investment from KNUST (Top 1%), where his research focused on board diversity and financial performance.
He is a CFA Program Scholarship Recipient, an ALX Data Analytics Fellow, and serves as the member of the Audit Committee for the Jasikan Municipal Assembly (ICAG Nominee).
He is a member of ICAG and the Institute of Internal Auditors, Ghana.










