AI Accountability & Responsibility Model

Operational accountability for AI decisions, risks and agents.

This assessment does not enforce one universal RACI model. It determines whether AI responsibilities are explicitly assigned, understood, documented, consistently applied, auditable, and maintained as AI systems evolve.

Principle — No critical AI system should exist without an accountable business owner. No AI agent capable of executing business actions should operate without an accountable human sponsor or owner.

Network of AI systems converging on a single accountable owner node

The stronger questions

Governance is not a committee exercise. These questions drive scoring, recommendations and the roadmap.

Who owns this AI system?

Who can approve what it can access?

Who can increase its autonomy?

Who accepted its residual risk?

Who has authority to stop it?

Who is accountable if it acts incorrectly?

Accountability areas assessed

approving new AI use casesAI business ownershipAI risk classificationAI security requirementsdata access approvalmodel approvalmodel lifecycle managementmodel changesAI architecture approvalAI agent ownershipagent privilege approvalagent autonomy approvaltool and API authorizationthird-party AI approvalAI procurementproduction deploymentAI monitoringsecurity monitoringAI incident responseagent containmentAI service recoveryresidual risk acceptanceregulatory accountabilityAI decommissioning

Agent accountability roles

These roles may overlap depending on organizational structure — they are not required to be separate individuals.

Technical Identity

The identity the agent uses to authenticate and access systems.

Business Owner

The person accountable for the business outcome produced by the agent.

Human Sponsor

The person accountable for the agent's approved purpose, scope and operation.

Security Owner

The team accountable for defining and monitoring security requirements.

Assessment domains

Governance

Governance & Accountability

Operational accountability for AI decisions, risks, controls and operations — not committee structure.

6 questions

Lifecycle

Model & System Lifecycle

Approval, change control and decommissioning of AI systems and models.

3 questions

Data & Access

Data & Access Accountability

Who approves what AI systems and agents can read, write and reach.

3 questions

Operations

Monitoring, Incident & Recovery

Operational ownership of AI behaviour, security telemetry, containment and recovery.

2 questions

Third-Party

Third-Party & Regulatory

Accountability for external AI providers, procurement and regulatory exposure.

2 questions