Defined AI Responsibilities
Are responsibilities for AI risk, security, data access, model approval, autonomous actions, monitoring, incident response, and lifecycle management formally assigned?
Assessment
Rate each activity on the 0–5 maturity model, then record where ownership and decision rights are assigned. Answers are saved automatically in this browser.
Governance
Operational accountability for AI decisions, risks, controls and operations — not committee structure.
Are responsibilities for AI risk, security, data access, model approval, autonomous actions, monitoring, incident response, and lifecycle management formally assigned?
Does every critical production AI system have an accountable business owner?
Principle: no critical AI system should exist without an accountable business owner.
Does every production AI agent capable of executing business actions have an accountable human sponsor or owner?
Distinguish technical identity, business owner, human sponsor and security owner — they may overlap.
Is accountability explicitly assigned for approving changes in an AI system's level of autonomy or authority?
Can the organization identify who formally accepted the residual risk for high-risk AI deployments?
Is accountability clearly defined for AI-specific security incidents and autonomous-action incidents?
Assess whether the organization knows who holds authority to act during an AI incident.
Lifecycle
Approval, change control and decommissioning of AI systems and models.
Is there an explicit owner and path for approving new AI use cases and AI architecture?
Is accountability assigned for approving models, model changes, and critical prompt/system-instruction changes?
Is accountability assigned for retiring AI systems, agents, credentials and associated data access?
Data & Access
Who approves what AI systems and agents can read, write and reach.
Is accountability assigned for approving AI and agent access to sensitive data?
Is accountability assigned for authorizing the tools, APIs and integrations an AI agent may invoke?
Is accountability assigned for increasing agent privileges and enabling agent-to-agent delegation?
Operations
Operational ownership of AI behaviour, security telemetry, containment and recovery.
Is ownership assigned for monitoring AI behaviour, agent actions and AI security telemetry?
Is authority defined to contain an AI agent and to authorize restoration of AI services after containment?
Third-Party
Accountability for external AI providers, procurement and regulatory exposure.
Is accountability assigned for approving third-party AI services, models and AI procurement?
Is accountability assigned for AI regulatory obligations and for classifying AI risk levels?
Supporting indicator
Mark whether accountability is clearly assigned for each area. This produces a 0–100 supporting governance indicator; it does not replace the main maturity score.
Business ownership
Named accountable business owner for production AI systems.
Technical ownership
Engineering owner for AI architecture, deployment and operation.
Security ownership
Team accountable for AI security requirements and monitoring.
Agent sponsorship
Human sponsor accountable for each production agent's purpose and scope.
Risk acceptance ownership
Authority that formally accepts residual AI risk.
Incident ownership
Authority to disable, contain, isolate and recover AI services.
Model lifecycle ownership
Ownership of model approval, change and retirement.
Data access ownership
Authority approving AI and agent access to sensitive data.
Third-party AI accountability
Ownership of external AI provider approval and oversight.
Decommissioning ownership
Accountability for retiring AI systems, agents and credentials.
Decision rights
Ownership is necessary but not sufficient. Record whether decision rights are explicitly defined for each change that alters AI capability, access or authority.
Introducing a new AI system
Increasing data access
Connecting a new tool
Enabling autonomous actions
Changing models
Modifying prompts / system instructions for critical AI
Adding new agents
Increasing agent privileges
Enabling agent-to-agent delegation
Accepting AI risk
Disabling AI during an incident
Restoring AI after containment