NIST AI RMF APPLICATION DATA GOVERNANCE INFRASTRUCTURE

Accountability structures

Part of: GV: GOVERN — Policies, Accountability & Culture

Description

Roles, responsibilities, and lines of communication related to AI risk management are established with clear accountability. Every AI system must have a named human accountable for its behavior in production.

Suggested Actions

1
Define AI governance roles with explicit authority: AI Ethics Officer (policy interpretation), Model Risk Manager (validation oversight), Data Steward (data quality and privacy), AI System Owner (business accountability for outcomes)
2
Establish an AI Governance Committee or Board with executive representation, meeting at least quarterly, with authority to halt AI deployments that exceed risk appetite
3
Document accountability chains from individual contributors to executive leadership — when an AI system causes harm, there must be zero ambiguity about who is responsible
4
Create RACI matrices for every AI lifecycle activity: who is Responsible for execution, Accountable for outcomes, Consulted for input, and Informed of decisions
5
Ensure accountability structures cover third-party AI systems — outsourcing the technology does not outsource the responsibility
6
Integrate AI accountability into existing corporate governance structures (board risk committees, audit committees) rather than creating parallel governance silos

Related Controls

AI Acceptable Use Policy