AI Risk Management Must Anchor on Clear Business Accountability from Day One

AI risk management is not the role of the Risk function, it is the role of the business leader who has the authority to approve, pause or retire the system.

A committee can challenge the decision, but it cannot substitute for a person who is answerable for the outcome.

The 30-second take

Every AI use case needs a named business owner from intake through retirement. That owner should define the purpose, approve the risk trade-offs, ensure the evidence exists, monitor outcomes and act when the system stops behaving as intended.

Risk, legal, privacy, cyber and technology teams provide expertise and challenge. They should not inherit the business decision merely because the technology is complex or because it is a risk.

Air Canada could not outsource responsibility to its chatbot

In Moffatt v Air Canada, a website chatbot told a customer that a bereavement fare could be claimed after travel, while another Air Canada webpage said otherwise. The customer relied on the chatbot, bought the tickets and was refused the reduction.

The British Columbia Civil Resolution Tribunal found negligent misrepresentation and ordered Air Canada to pay $812.02, including damages, interest and fees. The published CanLII case extract records the Tribunal’s conclusion that the chatbot remained part of Air Canada’s website and that the airline was responsible for the information it provided.

The operating lesson is wider than customer chatbots. Accountability does not transfer to a model, vendor, data team or governance forum. If an AI-enabled process affects a customer, employee or material business decision, a person with authority must own the result.

AICD puts roles and decision rights first

The AICD and the Human Technology Institute updated their Director’s Guide to AI Governance in June 2026. The guide is designed to help boards balance opportunity and risk as AI becomes embedded across organisations, including the human impact on employees, customers and other stakeholders.

The accompanying board checklist asks directors to test whether existing privacy, data-governance and cyber controls work for AI and whether technology and data foundations support deployment. Those questions are useful only when management can identify who must act on the answer.

A practical ownership record should name the accountable executive, operational owner, technical custodian, data owner, challenge functions and any material vendor. More importantly, it should allocate decisions: who approves the use case, who accepts residual risk, who authorises a material change, who handles affected customers and who can stop the system.

Make ownership visible at every handoff

Accountability should appear consistently in the business AI register, impact assessment, approval record, monitoring plan, incident pathway and retirement decision. If those records point to different owners, the organisation has created delay precisely when rapid action matters.

For lower-impact internal tools, a functional executive may own a fast, proportionate review. Customer-facing, safety-related or sensitive-data uses need stronger evidence and senior challenge. The control effort changes with risk; the need for one accountable owner does not.

Questions to test your accountability model

  • Can you name one business owner for every AI use case from proposal through retirement?
  • Does that owner have explicit authority to approve, pause, escalate or stop the AI-enabled process?
  • Are specialist functions positioned as advisers and challengers rather than default owners?
  • Does the approval record show who accepted residual risk and which evidence supported the decision?
  • Would a complaint, incident or vendor change reach the accountable owner quickly enough to act?

Turn ownership into evidence

If your AI register records a system but cannot identify who is answerable for its outcomes, the governance gap is already visible. Visit the AI Signal Box to test practical AI governance questions and take a readiness snapshot.

More from the Reading Room

Why AI Operational Resilience Must Be a Boardroom Priority Now

AI failures can disrupt critical operations and damage customer trust. Boards and executives must treat AI operational resilience as a core governance responsibility—not just a technical issue—to safeguard business continuity and reputation.

How to Master AI Risk Control Testing for Real-World Assurance

NIST’s August 2026 TEVV-Athlon draft makes real-world AI evaluation a current governance issue. Businesses should connect every test to pre-agreed acceptance thresholds, a named decision owner and clear retest triggers.

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.

Turning AI Risk Assessments into Business Accelerators: A Practical Path Beyond Bottlenecks

AI risk assessments often stall innovation when unclear ownership and inconsistent evidence requirements create bottlenecks. Business leaders must own AI risk decisions, supported by clear triage and third-party evidence standards to speed value delivery without compromising controls.