AI Governance

    Who Owns AI Risk? Accountability Lessons from Walter Haydock

    ICyberWave Editorial
    Sep 26, 2026
    AI Governance
    Cross-functional team reviewing AI lifecycle risks, human oversight and monitoring

    Accountability must attach to an outcome

    AI governance often begins with a committee, a policy and a list of prohibited tools. Walter Haydock’s public discussions focus attention on the harder question: who is accountable when an AI-enabled process causes harm or fails?

    The answer cannot be “the AI team.” Accountability belongs with the business role that owns the outcome, supported by technical, legal, privacy, security and risk specialists.

    Build a judgement-free AI inventory

    Employees will experiment before governance catches up. An inventory process that threatens punishment encourages hidden use. A better discovery exercise asks teams what tools they use, what decisions those tools influence and what data they receive.

    Record at least:

    • Business purpose and accountable owner
    • Users and people affected by outputs
    • Model, provider and deployment method
    • Input data, personal data and confidential information
    • Degree of autonomy and human intervention
    • External integrations and downstream actions
    • Risk classification, approval and review date

    Define risk appetite before scoring systems

    A risk methodology is weak if leadership has not defined what the organisation will not accept. Set boundaries for uses involving legal rights, safety, employment, sensitive data, financial decisions, children or autonomous action.

    Decision tierExampleMinimum governance
    ProhibitedManipulative or unlawful useBlock, monitor and investigate
    High impactEmployment or eligibility decisionImpact assessment, validation, oversight and approval
    ControlledCustomer support recommendationTesting, disclosure, monitoring and escalation
    Low impactInternal drafting with no sensitive dataApproved tool and user review

    Connect ISO 42001 and NIST AI RMF

    ISO/IEC 42001 provides a management system: policy, roles, objectives, risk treatment, controls, audit and improvement. NIST AI RMF provides practical outcomes across Govern, Map, Measure and Manage. Teams can use one evidence architecture and map it to both.

    For example, the AI inventory supports context and governance. Impact assessments support risk identification and measurement. Monitoring, incident management and corrective action support ongoing management and improvement.

    Mapping reduces duplication, but it does not make the frameworks identical or replace legal analysis.

    Give owners real decision rights

    An accountable owner must be able to delay deployment, require additional testing, accept residual risk within authority and escalate beyond that authority. Governance groups should challenge decisions, not merely record them.

    Approval evidence should answer

    1. What outcome is the system intended to produce?
    2. Who could be harmed and how?
    3. What evidence supports performance and fairness claims?
    4. When must a human intervene?
    5. What changes trigger reassessment?
    6. Who receives and resolves incidents or appeals?

    Monitor outcomes, not only models

    Technical drift is only one signal. Monitor complaints, overrides, appeal outcomes, security incidents, privacy events, supplier changes and unexpected patterns across affected groups. Thresholds should lead to a defined action: investigate, restrict, suspend or retire.

    ICyberWave perspective

    Accountability becomes real when a named owner can explain the intended outcome, evidence, limits and response plan. ICyberWave supports AI inventories, ISO 42001 implementation, NIST AI RMF mapping, impact assessments and internal audit. Compare the frameworks in our integrated AI governance spotlight or contact us for a practical roadmap.

    Hi! I'm your AI Assistant 💬