For Heads-of · Practitioner
AI ownership and accountability framework
A named individual or committee accountable for each AI system's risk posture, with defined reporting lines.
- directive
- governance
- accountability
What it does
Assigns a specific, named owner to each AI system's risk decisions, with a defined reporting line into the organisation's wider risk governance.
Where it fits
Turns diffuse, assumed accountability into an actual answerable role, which is what regulators and internal audit both expect to find.
Risks this mitigates
The risks this control addresses, ranked by effectiveness.
Inadequate AI resourcing and competence
AI systems are adopted without provisioning the compute, tooling, data quality controls, or trained personnel needed to operate them safely.
Unclear AI ownership and accountability
No individual or committee owns AI risk decisions end-to-end, so accountability for a given system's behaviour is diffuse or absent.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| NIST AI Risk Management Framework (AI RMF 1.0) | Govern | Govern |
| SS1/23: Model Risk Management Principles for Banks | Principle 2 | Model risk governance |
| ISO/IEC 42001:2023 | Annex A.3 | Internal organisation |