AI risk management is not the role of the Risk function, it is the role of the business leader who has the authority to approve, pause or retire the system.
A committee can challenge the decision, but it cannot substitute for a person who is answerable for the outcome.
The 30-second take
Every AI use case needs a named business owner from intake through retirement. That owner should define the purpose, approve the risk trade-offs, ensure the evidence exists, monitor outcomes and act when the system stops behaving as intended.
Risk, legal, privacy, cyber and technology teams provide expertise and challenge. They should not inherit the business decision merely because the technology is complex or because it is a risk.
Air Canada could not outsource responsibility to its chatbot
In Moffatt v Air Canada, a website chatbot told a customer that a bereavement fare could be claimed after travel, while another Air Canada webpage said otherwise. The customer relied on the chatbot, bought the tickets and was refused the reduction.
The British Columbia Civil Resolution Tribunal found negligent misrepresentation and ordered Air Canada to pay $812.02, including damages, interest and fees. The published CanLII case extract records the Tribunal’s conclusion that the chatbot remained part of Air Canada’s website and that the airline was responsible for the information it provided.
The operating lesson is wider than customer chatbots. Accountability does not transfer to a model, vendor, data team or governance forum. If an AI-enabled process affects a customer, employee or material business decision, a person with authority must own the result.
AICD puts roles and decision rights first
The AICD and the Human Technology Institute updated their Director’s Guide to AI Governance in June 2026. The guide is designed to help boards balance opportunity and risk as AI becomes embedded across organisations, including the human impact on employees, customers and other stakeholders.
The accompanying board checklist asks directors to test whether existing privacy, data-governance and cyber controls work for AI and whether technology and data foundations support deployment. Those questions are useful only when management can identify who must act on the answer.
A practical ownership record should name the accountable executive, operational owner, technical custodian, data owner, challenge functions and any material vendor. More importantly, it should allocate decisions: who approves the use case, who accepts residual risk, who authorises a material change, who handles affected customers and who can stop the system.
Make ownership visible at every handoff
Accountability should appear consistently in the business AI register, impact assessment, approval record, monitoring plan, incident pathway and retirement decision. If those records point to different owners, the organisation has created delay precisely when rapid action matters.
For lower-impact internal tools, a functional executive may own a fast, proportionate review. Customer-facing, safety-related or sensitive-data uses need stronger evidence and senior challenge. The control effort changes with risk; the need for one accountable owner does not.
Questions to test your accountability model
- Can you name one business owner for every AI use case from proposal through retirement?
- Does that owner have explicit authority to approve, pause, escalate or stop the AI-enabled process?
- Are specialist functions positioned as advisers and challengers rather than default owners?
- Does the approval record show who accepted residual risk and which evidence supported the decision?
- Would a complaint, incident or vendor change reach the accountable owner quickly enough to act?
Turn ownership into evidence
If your AI register records a system but cannot identify who is answerable for its outcomes, the governance gap is already visible. Visit the AI Signal Box to test practical AI governance questions and take a readiness snapshot.

