Tier 1: Foundation controls
AI accountability and role assignment
Clear assignment of responsibility and decision rights for AI systems across design, deployment, monitoring, and incident response, so liability does not default to ambiguity.
Board-defensible evidence
- Role and responsibility model (RASCI or equivalent) naming accountable owners for business outcomes, technical operation, risk oversight, compliance review, and security controls, with documented decision rights.
- System-level ownership records showing named individuals and back-ups, last reviewed dates, and evidence of acceptance of responsibility for required control obligations.
- Approval workflow documentation showing who can authorize production deployment, who can approve exceptions, and who can stop or roll back a model when risk thresholds are breached.
- Meeting minutes or governance committee charters showing escalation pathways, quorum requirements, and how disputed decisions are resolved and recorded.
- Incident accountability evidence showing who is on the response roster, who must be notified, what timelines apply, and how post-incident corrective actions are assigned and tracked.
Why this matters
When a regulator asks who was accountable, undefined roles convert a technical failure into a governance and liability failure.
How ready is your board on foundation controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.