For Heads-of · Practitioner
Unclear AI ownership and accountability
No individual or committee owns AI risk decisions end-to-end, so accountability for a given system's behaviour is diffuse or absent.
- medium
- governance
- accountability
- ownership
How it happens
An AI system spans data science, engineering, and a business function, and each assumes governance is someone else's responsibility, so no one actually owns the risk decision for the system as a whole.
Why it matters
When something goes wrong, diffuse ownership means the incident response is improvised and slow, and regulators increasingly expect a named accountable individual, not a shared assumption.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| NIST AI Risk Management Framework (AI RMF 1.0) | Govern | Govern |
| SS1/23: Model Risk Management Principles for Banks | Principle 2 | Model risk governance |
| ISO/IEC 42001:2023 | Annex A.3 | Internal organisation |
Related resources
The external sources behind this risk, from the Resources library.