Purpose
Define ownership, accountability, and decision rights for AI governance activities so responsibilities remain clear across business, technical, legal, and risk teams.
Scope
Covers the AI governance council, model owners, product sponsors, Responsible AI function, and supporting teams (security, privacy, compliance, IT).
- Strategic sponsors and funding approvers
- Model owners and technical leads
- Risk, compliance, and Responsible AI roles
- Operational support (SRE, Data, Privacy, Security)
Definitions
- RACI Chart: Matrix mapping Responsible, Accountable, Consulted, and Informed parties for key AI activities.
- Model Owner: Business and technical stakeholder accountable for lifecycle reporting.
- Governance Council: Cross-functional steering committee guiding AI strategy and escalation.
Policy
Every AI initiative must have an assigned Model Owner and Sponsor. Governance council membership, quorum, and decision rights must be documented. Succession plans must exist for critical roles to prevent control gaps.
Roles and Responsibilities
COO (or equivalent) sponsors the council and approves RACI updates. Governance council adjudicates escalations and policy changes. Model Owners ensure ongoing compliance. Supporting teams maintain their respective controls.
Procedures
Accountability management includes:
- Maintain a RACI chart for all governance activities (risk assessment, validation, monitoring, incident response).
- Review and update roles quarterly or when re-orgs occur.
- Publish role descriptions and required training per role.
- Document escalation paths and communication plans for each control domain.
- Store succession plans and delegate information in the governance portal.
Exceptions
Temporary role gaps (e.g., during leave) must have named delegates with documented handover notes. Gaps longer than 30 days require executive approval.
Review Cadence
Governance council reviews role assignments and RACI accuracy quarterly. Findings feed into leadership action items.
References
- ISO/IEC 42001:2023 Clause 5.3 (Organizational roles, responsibilities, authorities)
- Internal documents: Governance Council Charter, RACI Template, Succession Plan SOP