Accountability must attach to an outcome
AI governance often begins with a committee, a policy and a list of prohibited tools. Walter Haydock’s public discussions focus attention on the harder question: who is accountable when an AI-enabled process causes harm or fails?
The answer cannot be “the AI team.” Accountability belongs with the business role that owns the outcome, supported by technical, legal, privacy, security and risk specialists.
Build a judgement-free AI inventory
Employees will experiment before governance catches up. An inventory process that threatens punishment encourages hidden use. A better discovery exercise asks teams what tools they use, what decisions those tools influence and what data they receive.
Record at least:
- Business purpose and accountable owner
- Users and people affected by outputs
- Model, provider and deployment method
- Input data, personal data and confidential information
- Degree of autonomy and human intervention
- External integrations and downstream actions
- Risk classification, approval and review date
Define risk appetite before scoring systems
A risk methodology is weak if leadership has not defined what the organisation will not accept. Set boundaries for uses involving legal rights, safety, employment, sensitive data, financial decisions, children or autonomous action.
| Decision tier | Example | Minimum governance |
|---|---|---|
| Prohibited | Manipulative or unlawful use | Block, monitor and investigate |
| High impact | Employment or eligibility decision | Impact assessment, validation, oversight and approval |
| Controlled | Customer support recommendation | Testing, disclosure, monitoring and escalation |
| Low impact | Internal drafting with no sensitive data | Approved tool and user review |
Connect ISO 42001 and NIST AI RMF
ISO/IEC 42001 provides a management system: policy, roles, objectives, risk treatment, controls, audit and improvement. NIST AI RMF provides practical outcomes across Govern, Map, Measure and Manage. Teams can use one evidence architecture and map it to both.
For example, the AI inventory supports context and governance. Impact assessments support risk identification and measurement. Monitoring, incident management and corrective action support ongoing management and improvement.
Mapping reduces duplication, but it does not make the frameworks identical or replace legal analysis.
Give owners real decision rights
An accountable owner must be able to delay deployment, require additional testing, accept residual risk within authority and escalate beyond that authority. Governance groups should challenge decisions, not merely record them.
Approval evidence should answer
- What outcome is the system intended to produce?
- Who could be harmed and how?
- What evidence supports performance and fairness claims?
- When must a human intervene?
- What changes trigger reassessment?
- Who receives and resolves incidents or appeals?
Monitor outcomes, not only models
Technical drift is only one signal. Monitor complaints, overrides, appeal outcomes, security incidents, privacy events, supplier changes and unexpected patterns across affected groups. Thresholds should lead to a defined action: investigate, restrict, suspend or retire.
ICyberWave perspective
Accountability becomes real when a named owner can explain the intended outcome, evidence, limits and response plan. ICyberWave supports AI inventories, ISO 42001 implementation, NIST AI RMF mapping, impact assessments and internal audit. Compare the frameworks in our integrated AI governance spotlight or contact us for a practical roadmap.

