MediumAccountability◐Demonstrated
Unclear accountability / ownership
Governance, Accountability & ComplianceDescription
No clear owner or RACI for AI outcomes leaves harms unaddressed and responsibility diffuse.
Example scenario
After an AI mis-statement, no team is clearly accountable for remediation.
Real-world evidence◐Demonstrated
Audits of financial institutions and red-team exercises regularly surface missing or untested AI-specific incident response plans, and guidance from NIST and FSB calls them out explicitly, but the absence of AI incident response has not yet been the confirmed primary cause of a large-scale financial sector production incident.
Primary mitigations
- Named accountable owner per system
- RACI
- AI risk committee
- decision audit trail.
Detection signals
Ownership-coverage audit; unassigned-system detection.
Mitigating controls
4 Non-agentic controls