Why Clear Business Ownership Unlocks Effective AI Risk Management

AI risk management keeps failing for the same boring reason: nobody actually owns it.

Not IT, not legal, not the business unit running the use case — everyone assumes someone else has it covered. In 2026, that assumption has a name attached to it, and regulators are starting to ask for it directly.


The 30-second take

AI risk management is not a control function’s job — it starts and ends with business ownership.

ASIC and APRA are now both explicit that boards need a named accountable person attached to every material AI use case, not a shared committee or a vague line in a policy document.

Directors who can’t answer who owns this AI use case, and what happens if it goes wrong, are exposed personally, not just organisationally.

Getting ownership right before a regulator or an incident forces the question is the fastest way to speed up AI adoption, not slow it down.


ASIC: “I did not know the algorithm did that” won’t cut it

ASIC’s first deep look at AI governance, Report 798 Beware the Gap, reviewed 624 AI use cases across 23 AFS and credit licensees and found governance lagging well behind adoption — nearly half the licensees reviewed had no policy addressing consumer fairness or bias in their AI use cases.

The tone has hardened since. Speaking at the AICD’s Australian Governance Summit in Sydney in March 2026, ASIC Chair Joe Longo told directors bluntly that “I did not know the algorithm did that” is not a legal defence.

ASIC has framed 2026 as a year of accountability, signalling it will pursue directors who fail to exercise independent judgement over material risks — AI included.

APRA wants a name next to every AI use case

On 30 April 2026, APRA wrote to every bank, insurer and superannuation trustee in the country. The message was blunt: AI deployment is outpacing the governance, risk management and assurance practices meant to oversee it.

The practical requirement is specific — APRA expects entities to hold an inventory of every model, agent, copilot and embedded AI feature, each classified by risk tier and assigned to a named accountable person under the FAR/BEAR regime. A shared governance committee is not an accountable person, and APRA has said so explicitly.

Directors already feel the gap

AICD’s Director Sentiment Index for the first half of 2026, surveying 828 directors through Roy Morgan, found concern over AI risk has surged even as cybercrime and data security hold the top spot for what keeps directors awake at night. Boards know this is live. What the sentiment data doesn’t show is whether anyone in the organisation could actually name the accountable owner if asked tomorrow.

What diffused ownership actually looks like in practice

A documented 2025 case involving a global firm’s AI-powered hiring platform shows how this plays out on the ground.

The platform remained accessible using default vendor credentials for months, exposing candidate data. Nobody caught it because ownership was split three ways: the business assumed IT had secured the platform, IT assumed the vendor’s defaults were adequate, and legal assumed its oversight obligations were covered by the vendor contract.

Each party owned a slice of the decision. Nobody owned the outcome.

Clear business ownership transforms AI risk management from a blocking exercise into a strategic enabler.

Questions to ask your organisation this week

  • For every material AI use case in production, can we name the single accountable person — not a committee — responsible for it?
  • Would that person’s name and role hold up if ASIC or APRA asked for it in writing tomorrow?
  • Have we updated our risk management policies specifically for AI, or are we relying on pre-AI frameworks and hoping they stretch?
  • Where AI touches consumers, have we assessed fairness and bias risk from the customer’s perspective, not just the business’s?
  • Do our vendor contracts for AI tools actually assign security and oversight responsibility, or do we just assume they do?
  • If an AI use case failed publicly tomorrow, do we know right now who would be the one explaining why?

Where to start

So, there are a lot of articles and opinions telling you what the problem is, so what can you do today?

Quite simply, this requires an AI inventory, an owners name against each line of it, and someone senior enough to own the answers when the question gets asked.

The AI Signal BoxTM provides a simple tool to use, and our readiness snapshot at the Innovation of Risk is a great place to see where your organisation stands before the regulator, or an incident, asks first.

More from the Reading Room

Why AI Operational Resilience Must Be a Boardroom Priority Now

AI failures can disrupt critical operations and damage customer trust. Boards and executives must treat AI operational resilience as a core governance responsibility—not just a technical issue—to safeguard business continuity and reputation.

How to Master AI Risk Control Testing for Real-World Assurance

NIST’s August 2026 TEVV-Athlon draft makes real-world AI evaluation a current governance issue. Businesses should connect every test to pre-agreed acceptance thresholds, a named decision owner and clear retest triggers.

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.

Turning AI Risk Assessments into Business Accelerators: A Practical Path Beyond Bottlenecks

AI risk assessments often stall innovation when unclear ownership and inconsistent evidence requirements create bottlenecks. Business leaders must own AI risk decisions, supported by clear triage and third-party evidence standards to speed value delivery without compromising controls.