AI Risk Management Must Anchor on Clear Business Accountability from Day One

AI risk management is not the role of the Risk function, it is the role of the business leader who has the authority to approve, pause or retire the system.

A committee can challenge the decision, but it cannot substitute for a person who is answerable for the outcome.

The 30-second take

Every AI use case needs a named business owner from intake through retirement. That owner should define the purpose, approve the risk trade-offs, ensure the evidence exists, monitor outcomes and act when the system stops behaving as intended.

Risk, legal, privacy, cyber and technology teams provide expertise and challenge. They should not inherit the business decision merely because the technology is complex or because it is a risk.

Air Canada could not outsource responsibility to its chatbot

In Moffatt v Air Canada, a website chatbot told a customer that a bereavement fare could be claimed after travel, while another Air Canada webpage said otherwise. The customer relied on the chatbot, bought the tickets and was refused the reduction.

The British Columbia Civil Resolution Tribunal found negligent misrepresentation and ordered Air Canada to pay $812.02, including damages, interest and fees. The published CanLII case extract records the Tribunal’s conclusion that the chatbot remained part of Air Canada’s website and that the airline was responsible for the information it provided.

The operating lesson is wider than customer chatbots. Accountability does not transfer to a model, vendor, data team or governance forum. If an AI-enabled process affects a customer, employee or material business decision, a person with authority must own the result.

AICD puts roles and decision rights first

The AICD and the Human Technology Institute updated their Director’s Guide to AI Governance in June 2026. The guide is designed to help boards balance opportunity and risk as AI becomes embedded across organisations, including the human impact on employees, customers and other stakeholders.

The accompanying board checklist asks directors to test whether existing privacy, data-governance and cyber controls work for AI and whether technology and data foundations support deployment. Those questions are useful only when management can identify who must act on the answer.

A practical ownership record should name the accountable executive, operational owner, technical custodian, data owner, challenge functions and any material vendor. More importantly, it should allocate decisions: who approves the use case, who accepts residual risk, who authorises a material change, who handles affected customers and who can stop the system.

Make ownership visible at every handoff

Accountability should appear consistently in the business AI register, impact assessment, approval record, monitoring plan, incident pathway and retirement decision. If those records point to different owners, the organisation has created delay precisely when rapid action matters.

For lower-impact internal tools, a functional executive may own a fast, proportionate review. Customer-facing, safety-related or sensitive-data uses need stronger evidence and senior challenge. The control effort changes with risk; the need for one accountable owner does not.

Questions to test your accountability model

  • Can you name one business owner for every AI use case from proposal through retirement?
  • Does that owner have explicit authority to approve, pause, escalate or stop the AI-enabled process?
  • Are specialist functions positioned as advisers and challengers rather than default owners?
  • Does the approval record show who accepted residual risk and which evidence supported the decision?
  • Would a complaint, incident or vendor change reach the accountable owner quickly enough to act?

Turn ownership into evidence

If your AI register records a system but cannot identify who is answerable for its outcomes, the governance gap is already visible. Visit the AI Signal Box to test practical AI governance questions and take a readiness snapshot.

More from the Reading Room

Why AI Risk Management Must Address Vendor Change Controls to Prevent Operational Disruption

Microsoft Azure AI Foundry and Amazon Bedrock show how model retirement can shorten notice periods, stop requests and require code changes. The EU's DORA framework shows why notification, objection and exit rights must connect to a tested operational response.

AI Risk Management Enables Success

The Digital Transformation Agency’s Microsoft 365 Copilot trial shows how a bounded experiment can produce evidence about benefits and limitations. OECD adoption research and UK Government assurance guidance point to an operating model that helps organisations test, scale or stop AI responsibly.

Why AI Risk Management Must Focus on Third-Party Evidence Verification, Not Vendor Promises

The Australian Cyber Security Centre's procurement and AI supply-chain guidance shows why vendor assurance must be refreshed when services change. OAIC guidance adds a clear requirement for organisations to conduct privacy due diligence on commercially available AI products.

Turning AI Risk Assessments from Roadblocks into Business Accelerators

The FCA's 2026 AI Live Testing cohort and Supercharged Sandbox show how Barclays, Experian, Lloyds Banking Group, UBS and other firms are building evidence through controlled testing. NIST's tailorable AI RMF Playbook provides a practical basis for proportionate triage.