What does Dr. Jonah Tebaa on Why Governance Committees Keep Losing to the Clock mean in practice?
Dr. Jonah Tebaa explains that governance committees lose to the clock because automated systems execute in seconds while monthly committee reviews serve as audit trails rather than real-time controls. Even diligent committees arrive after damage is already done, such as credit limit cuts reported to bureaus within 48 hours. To solve this, Dr. Jonah Tebaa advocates using pre-execution gates for high-risk actions, confidence thresholds that route low-confidence decisions before execution, and tracking time-to-reverse as a key governance KPI.
A regional retail bank's Model Risk Committee meets on schedule, reviews its sample of decisions, and does its job well. That is the detail that makes the case Dr. Jonah Tebaa uses with boards worth sitting with, because the usual story about AI governance failure involves someone missing something. This one does not. Everyone involved does exactly what the process asks of them, and the customer still loses.
A Credit Line, a Wedding, and a Committee That Got It Right
The setup, as Tebaa lays it out, is deliberately unremarkable. A mid-sized bank runs a model that adjusts consumer credit limits every month based on spending patterns and risk signals, touching on the order of 40,000 accounts per cycle. There is a governance structure on paper: a Model Risk Committee, a monthly cadence, a sample of 50 decisions reviewed each cycle, an escalation path if something looks wrong.
One month, the model reads a single large purchase — a wedding expense — as the leading edge of a debt spiral and cuts a customer's limit from $10,000 to $4,000. The decision executes immediately. Because the bank's credit-bureau reporting obligations run on their own clock, the cut is reported to the bureau within 48 hours, well before anyone with judgment has looked at the case.
Three weeks later, the committee reviews it and gets the call right: one large purchase is not a trend, and the model's confidence score on the decision was 58 percent — below the bank's own 70 percent threshold for auto-execution. The case should have been routed to a human. A configuration gap meant it was not. The committee votes to reverse.
Reversing a bureau-reported change is not an internal correction, however. It requires a formal dispute filing and carries a 45-day resolution window. In the interim, the customer — never notified that anything had happened — is declined a mortgage rate lock because a credit utilization ratio spiked overnight for reasons that have nothing to do with their actual creditworthiness.
The Distinction the Case Exposes
Tebaa's read on this is not that the bank's committee was negligent. It is that the committee was structurally incapable of intervening in time, and that this is a design property, not a performance failure. The model's execution clock ran in seconds. The bureau's reporting clock ran in 48 hours. The bank's governance clock ran in weeks. Only the customer's actual damage clock — the one that determined whether the mortgage rate lock was still available — moved at the speed that mattered, and it was faster than all three.
This is where Tebaa draws a line that a lot of governance documentation blurs: the difference between an audit trail and a control. An audit trail tells an organization what happened and, with enough forensic effort, why. A control changes what happens before the outcome becomes permanent. The Model Risk Committee in this case produced an excellent audit trail. It produced no control at all, because by the time it convened, the only thing left to govern was the paperwork of undoing something already done.
The reason this is easy to miss, in Tebaa's telling, is precisely that the committee performed well. A monthly meeting that catches an error and votes correctly looks, on every internal scorecard, like governance functioning as intended. Nothing about the committee's conduct would trigger a red flag in a board presentation. The failure is invisible from inside the process that produced it — visible only from the customer's side of the 45-day window.
Where the Same Gap Shows Up Elsewhere
Tebaa is careful to note that credit modeling is simply the clearest illustration, not the only site of the problem. An automated pricing engine can reprice thousands of SKUs overnight on a bad demand signal while the pricing committee meets weekly. A content moderation system can suspend a business account in seconds while an appeals queue runs days deep. An automated hiring screen can filter out a quarter's worth of candidates before any outcome audit is scheduled to run. In each case, the review cadence may be entirely reasonable by conventional standards and still be irrelevant to the actual damage window, because the damage window is set by the system's execution speed, not by the calendar.
What Tebaa Tells Executives to Ask
His argument to the executives and board members who bring him cases like this is not that governance needs to happen more often. A monthly review that becomes a weekly review is still a review — it has simply moved the same category of clock a little faster, without changing its relationship to an execution clock measured in seconds. What he pushes for instead is a set of structural changes to where and how a decision can be stopped:
- Pre-execution gates for any decision class with high blast radius and low reversibility — the credit-cut, the mass repricing, the account suspension — so the check happens before the action, not after.
- Confidence thresholds that route, not log. A threshold that records a low-confidence decision without stopping it is a footnote for the audit trail, not a control on the outcome. If 70 percent was meant to be a gate, it has to function as one.
- Time-to-reverse tracked as a governance KPI, with the same institutional weight given to time-to-review — because a committee that can identify an error in three weeks but needs 45 days to undo it has, in practical terms, no reversal capability at all.
The uncomfortable part of Tebaa's argument, for boards used to measuring governance maturity by meeting frequency and sample size, is that none of those metrics say anything about whether the control can act before the harm is locked in. A committee can be diligent, well-resourced, and entirely correct in its findings, and still arrive too late every single time — not because it failed to do its job, but because its job was never wired to the clock that actually decided the outcome. The international standard-setting language already carries that expectation: UNESCO's Recommendation on the Ethics of Artificial Intelligence approaches AI ethics as a "systematic normative reflection, based on a holistic, comprehensive, multicultural and evolving framework" of interdependent values, principles and actions — actions being the word a review calendar quietly drops.