Responsible AI
Accountability, Decision Rights, and Independent Challenge
Design governance roles that distinguish delivery ownership, risk challenge, approval, assurance, and remedy.
By the end you can
- Explain why accountability requires named authority for decisions, independent challenge, operational ownership, and remedy
- Distinguish RACI label, Decision-rights design, and Committee consensus
- Identify evidence that connects business owner to remedy owner
- Design a review that moves from list governed decisions to test under pressure
What accountability and decision rights changes in practice
Accountability means a named person or body has authority and responsibility for a decision, can obtain evidence, and faces consequences for failing to act. Responsibility can be distributed. Final approval, challenge, operation and remedy should not. Ambiguity collects at one point in particular: the moment a release is finally approved. Several functions contributed, and afterwards nobody can say who cleared it.
A practical model separates three things. The first line owns and operates the risk. The second line sets frameworks and challenges decisions. The third line provides independent assurance. The structure should fit the company it sits in rather than copy a diagram mechanically.
This is no longer only good practice. It is law. The EU AI Act puts the same demand on deployers of high-risk systems, and it applies from 2 August 2026. Oversight has to be assigned to named natural persons (Article 26(2)). Use has to be suspended when the system may present a risk (Article 26(5)). An explanation is owed to the person the decision fell on (Article 86(1)). The rest of this lesson is largely those three paragraphs, and what other regulators and standards bodies found when they tested them.
Ask who could have halted the release and would face consequences for not halting it. Article 26(5) of the EU AI Act obliges the deployer to suspend use, and no committee consensus can discharge that.
Visual
Five roles, and a statute that already insists on natural persons
Business owner, technical owner, independent challenge, approval authority, remedy owner. Five roles, and a review has to be able to name a person in each. That requirement is not this lesson's invention. Article 26(2) of the EU AI Act states it: “Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.”
Read the four attributes slowly, because a governance chart usually carries none of them. Competence: the reviewer must understand what they are reviewing. Training: someone has to have supplied that understanding. Authority: the reviewer must be able to act on what they find. Support: the organisation has to carry the reviewer when they do. A box on a diagram asserts a role. The statute asks what stands behind the box.
The fifth box has a claimant behind it. A person the decision fell on can demand clear and meaningful explanations, and can demand them from the deployer. The system has to be a listed high-risk one, and the decision has to be taken on its output. That is Article 86(1). The remedy owner is answering a legal claim, not running a courtesy service.
- 1
Business owner
Owns intended purpose, benefit, operating process, and residual risk.
- 2
Technical owner
Owns model, data, testing, change records, and technical response.
- 3
Independent risk function
Challenges assumptions, controls, and compliance without delivery incentives.
- 4
Approval authority
Accepts, restricts, or rejects deployment within delegated risk appetite.
- 5
Remedy owner
Ensures complaints, correction, compensation, and learning reach the system.
Key idea
Signs of undue pressure, and a champion with a rule number
A reviewer is not independent if career incentives, reporting lines, or deadlines make it costly to disagree. No governance chart can replace judgment, competence, or ethical courage. The clearest statement of that comes from a standards body, about its own framework. NIST published the Artificial Intelligence Risk Management Framework (AI RMF 1.0) on 26 January 2023. Section 1.2.4 says: “Organizations need to establish and maintain the appropriate accountability mechanisms, roles and responsibilities, culture, and incentive structures for risk management to be effective. Use of the AI RMF alone will not lead to these changes or provide the appropriate incentives.” The framework is explicitly voluntary. It names incentive structures as the piece it cannot supply.
Formal separation can fail even when a regulator designed it. The engineers who made compliance findings on the FAA's behalf for the Boeing 737 MAX flight control system worked for Boeing. They were engineering unit members of Boeing's Organization Designation Authorization: deputised by the regulator, employed by the applicant. The Joint Authorities Technical Review, chaired by former NTSB Chairman Christopher Hart, delivered its report to the FAA on 11 October 2019. Finding F5.3-A reads: “There are signs of undue pressure on E-UMs performing delegated functions, which may be attributed to conflicting priorities and an environment that does not support FAA requirements.” Recommendation R5.3 asked the FAA to review that work environment. The separation was formal, documented and delegated by law. It bent under conflicting priorities anyway.
Staff who raise a credible concern need a safe channel, and cover for having used it. Two UK regulators have turned that into one named person's prescribed job. Since 7 March 2016, FCA rules have required an insurer to appoint a director or senior manager as its whistleblowers' champion (SYSC 18.4.2R). An SMCR banking firm allocates the same role to an SMF manager, as an FCA-prescribed senior management responsibility. The rules set out what the role owns: “A firm must allocate to the whistleblowers’ champion the responsibility for ensuring and overseeing the integrity, independence and effectiveness of the firm’s policies and procedures on whistleblowing (see SYSC 18.3 (Internal Arrangements)) including those policies and procedures intended to protect whistleblowers from being victimised because they have disclosed reportable concerns.” The champion is expected to have a level of authority and independence within the firm, and access to resources including independent legal advice and training. The Prudential Regulation Authority sets a parallel expectation in supervisory statement SS39/15. The channel is not a poster on a wall. It has an owner, and the owner has a rule number.
Product, legal, risk and data science all reviewed the lending model. The chart showing all four is exactly what let each of them assume another one owned the final call.
Test what it costs a reviewer to disagree: the JATR found signs of undue pressure on reviewers a regulator had deputised, and NIST says its own framework will not supply the incentives.
Case
The Three Lines Model, July 2020, and the line it will not blend
Two of the three lines can be merged. The third cannot. The Institute of Internal Auditors published the Three Lines Model in July 2020, replacing the Three Lines of Defence adopted in 2013. First-line and second-line roles, it says, may be blended or separated. Principle 4 keeps internal audit in a third-line role, providing independent and objective assurance on governance and risk management.
Independence is the whole of what that line supplies. Blend it and there is nothing left to blend.
Comparison
A label, a filed statement of responsibilities, or a room where nobody decided
A RACI label says who is consulted. A decision-rights design says who may block. Committee consensus says nobody in particular.
The strongest form of a decision-rights design is filed with a regulator and enforceable against a person. In the UK, an application to perform a designated senior management function must be accompanied by a statement of responsibilities. That is section 60(2A)–(2B) of the Financial Services and Markets Act 2000. Section 66A of the same Act, in force from 7 March 2016, then attaches consequences to that map. Under condition C in section 66A(5), a senior manager is personally guilty of misconduct where the firm contravened a relevant requirement in an area they were responsible for managing and “the senior manager did not take such steps as a person in the senior manager's position could reasonably be expected to take to avoid the contravention occurring (or continuing).” That duty-of-responsibility limb, section 66A(5)(d), arrived on 10 May 2016 with the Bank of England and Financial Services Act 2016. The same Act repealed the original reverse burden of proof. FCA guidance then sets the standard: the steps a competent SMF manager would have taken, at that time, in that specific individual's position, with that individual's role and responsibilities, and in all the circumstances. That is what separates a label from a design. The label records who was consulted. The design records whose name is on the contravention.
The diffusion of responsibility that committee consensus invites is not a metaphor either. It has a measured size. Fischer and colleagues pooled the bystander literature in Psychological Bulletin in 2011, and the abstract reports: “In a fixed effects model, data from over 7,700 participants and 105 independent effect sizes revealed an overall effect size of g = -0.35.” People help less when other people are present. That is how much less.
The same meta-analysis reports when the effect weakens: when the situation is perceived as dangerous, when a perpetrator is present, and when the costs of intervening are physical. That qualifier is the design brief for a governance forum. Make the danger explicit with a risk tier. Give the cost of not acting to a named approver.
RACI label
Clarifies who is responsible, accountable, consulted, or informed.
- Useful for routine coordination
- Can become static and ceremonial
- Does not guarantee authority or competence
- Needs linkage to real decisions
Decision-rights design
Defines who may approve, block, override, and escalate.
- Tied to risk tier and evidence
- Names time limits and quorum
- Protects independent challenge
- Supports incident action
Committee consensus
Combines perspectives without clear ownership.
- Can improve deliberation
- May encourage diffusion of responsibility
- Often vulnerable to deadline pressure
- Needs a named accountable chair or approver
Analogy
A ship with named watch officers and emergency authority
On a ship, navigation, engineering, safety and command hold distinct duties, and one officer can order an emergency stop. Coordination matters, but accountability cannot disappear into a meeting.
The analogy stops at the hull. A ship has one chain of command and a boundary. An AI decision runs through vendors, regulators and affected people who never signed the crew list. The EU AI Act writes one of those outsiders into the statute: the affected person of Article 86(1) has a claim against the deployer directly. That is why the roles below are written as decision rights rather than as reporting lines.
Shared work requires explicit authority, independent challenge, and a route from harm to correction.
Example
How accountability and decision rights becomes an operating problem
A lending model passes every review meeting because product, legal, risk and data science each assume another function owns the final decision. Then the complaints arrive. Every team can describe its input, and none accepts accountability.
AI used to evaluate creditworthiness or set a credit score is high-risk under the EU AI Act (Annex III, point 5(b)). So the appeal that dies at the support desk is not a goodwill matter. Article 86(1), “Right to explanation of individual decision-making”, provides: “Any affected person subject to a decision which is taken by the deployer on the basis of the output from a high-risk AI system listed in Annex III, with the exception of systems listed under point 2 thereof, and which produces legal effects or similarly significantly affects that person in a way that they consider to have an adverse impact on their health, safety or fundamental rights shall have the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken.” The right runs against the deployer. Routing it to a desk with no authority over the source policy does not answer it. It parks a legal obligation with the one function in the chain that cannot discharge it.
- Delivery: The product team controls scope, schedule, and integration.
- Technical assurance: Data scientists evaluate model behavior and limitations.
- Risk challenge: Compliance questions fairness and legal obligations but cannot delay launch — finding F5.3-A is what that pressure looks like when someone writes it down.
- Approval ambiguity: A steering committee records consensus without naming a decision owner. Article 26(2) requires oversight assigned to natural persons with competence, training and authority.
- After harm: Customer support receives appeals without authority to correct the source policy. Article 86(1) owes those borrowers clear and meaningful explanations from the deployer.
Steps
Run the review again under a deadline
Step five is the one that matters. Run the whole review again under a deadline, with an executive sponsor in the room and the evidence still uncertain.
Steps 1 and 2 already have a published description of what finishing them looks like. The AI RMF offers both as outcomes rather than requirements. GOVERN 2.1: roles, responsibilities and lines of communication for mapping, measuring and managing AI risks are documented and clear throughout the organization. GOVERN 2.3: executive leadership takes responsibility for decisions about risks associated with AI system development and deployment. Both sit in a voluntary framework. That is precisely why the same document warns that using it alone will not produce the accountability mechanisms or the incentive structures.
Step 5 supplies the missing test. It asks whether the documented clarity of step 1 and the executive responsibility of step 2 survive a room with a launch date in it.
1. List governed decisions
Include scope, data, model, release, exception, incident, and retirement.
2. Assign authority
Name who can approve, block, override, and require new evidence.
3. Separate challenge
Give reviewers access, time, expertise, and escalation independent of delivery.
4. Connect remedy
Route complaints and incidents to owners who can change the system.
5. Test under pressure
Run a simulation involving deadline, executive sponsorship, and uncertain evidence.
Stop the release, keep the job
Accountability is real only where a named person can stop a release and still have a job the following week.
One legislature has made the stopping mandatory. Article 26(5) of the EU AI Act provides: “Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system.” Three hinges are worth reading twice. The trigger is reason to consider, not proof. The deadline is without undue delay, not the next scheduled committee. The duty falls on the deployer, which through Article 26(2) means the natural persons it has assigned.
UK financial regulation makes the mirror-image point. Failing to take the steps a person in that position could reasonably be expected to take is the individual's misconduct, not the committee's. That is section 66A(5) of the Financial Services and Markets Act 2000.
Define when accountability and decision rights requires the board to redesign, restrict, remedy, or retire the system.
Key takeaways
- Responsibility can be distributed; final decision authority cannot. Article 26(2) of the EU AI Act assigns human oversight of a high-risk system to natural persons who have the necessary competence, training and authority, as well as the necessary support.
- A separate job title is not independent challenge. Boeing engineering unit members were making compliance findings on the FAA's own behalf. Finding F5.3-A of the Joint Authorities Technical Review, reported on 11 October 2019, found signs of undue pressure on them.
- Committees need named accountability, evidence standards and conflict procedures. The diffusion effect they invite is measured at g = −0.35 across 105 independent effect sizes and more than 7,700 participants (Fischer and colleagues, 2011). It weakens when the danger is unambiguous.
- Delivery, risk challenge, audit and remedy are different jobs. The IIA's July 2020 Three Lines Model lets first-line and second-line roles be blended or separated, but principle 4 keeps internal audit's independent assurance in the third line.
- Ownership should survive staff turnover and vendor changes. A senior management function application must be accompanied by a statement of responsibilities, under section 60(2A)–(2B) of the Financial Services and Markets Act 2000. Section 66A(5) makes that map enforceable against whoever holds it.
- Governance is credible when it still works under deadline and executive pressure. NIST warns in AI RMF 1.0 that use of the framework alone will not produce the accountability mechanisms, roles, culture and incentive structures it needs. Article 26(5) turns suspension from a judgment call into a duty owed without undue delay.