Search the Atlas

Search risks, controls, and glossary terms

MediumAccountabilityDemonstrated

Unclear accountability / ownership

Governance, Accountability & Compliance

Description

No clear owner or RACI for AI outcomes leaves harms unaddressed and responsibility diffuse.

Example scenario

After an AI mis-statement, no team is clearly accountable for remediation.

Real-world evidenceDemonstrated

Audits of financial institutions and red-team exercises regularly surface missing or untested AI-specific incident response plans, and guidance from NIST and FSB calls them out explicitly, but the absence of AI incident response has not yet been the confirmed primary cause of a large-scale financial sector production incident.

Primary mitigations

  • Named accountable owner per system
  • RACI
  • AI risk committee
  • decision audit trail.

Detection signals

Ownership-coverage audit; unassigned-system detection.

Mitigating controls

4
Non-agentic controls

Related risks in Governance, Accountability & Compliance