Who is responsible for AI governance in a company?
In most UK organisations under 250 staff, one named person runs AI governance and the board stays accountable. When a committee is worth it, and who sits on it.
The board, or whoever runs the organisation, is accountable for how it uses AI. One named person should run it day to day, with the authority to refuse a tool. Most organisations under about 250 staff don’t need a committee to start, and plenty never will.
Who is ultimately responsible?
The board or senior team, or the partners in a partnership. They decide how much risk from AI the organisation will accept, and they agree the policy that says so. Handing the work to someone else doesn’t move that. When a client, an insurer or a regulator asks how your AI use is governed, the question is addressed to them.
In regulated firms the point is formal. The FCA says its rules on senior managers’ accountability are relevant to the safe use of AI, so in an FCA-regulated firm AI use sits inside responsibilities a named senior manager already holds.
Who should run it day to day?
One named person. In most organisations that’s whoever already owns risk, data protection, information security or operations. You don’t need a new hire. Add AI to an existing remit, and make sure the board backs that person when they say no to a tool.
A good owner has the authority to refuse, and is someone staff will ask before they sign up for something new. Time matters too. An owner who has no hours set aside for this will approve whatever lands on their desk.
It’s rarely a job for IT alone. IT can judge security and who gets access. Most AI decisions turn on what data goes in and whether anyone checks the output before it leaves the building. Those are business decisions. When IT owns AI governance on its own, it tends to shrink to a list of blocked websites.
The owner keeps a short set of records. That means the list of AI in use, the policy and its review date, an assessment for each approved tool, and a note of anything that went wrong and what was done about it.
Who else is involved?
The owner doesn’t work alone. In an organisation of this size the roles usually split like this.
| Who | What they do |
|---|---|
| Board or senior team | Agrees the policy and how much risk to accept. Gets a short report on AI use twice a year |
| AI owner | Keeps the list of AI in use, approves or refuses tools, owns the policy and handles incidents |
| IT | Sets up approved tools on company accounts and checks the security of anything new |
| Data protection lead | Answers the personal data questions for each tool, including whether it needs a DPIA |
| HR | Covers AI in hiring and staff matters, and keeps the record of AI training |
| Team leads | Say what their teams use and want, and make sure output is checked before it goes out |
| Everyone else | Uses approved tools and reports problems |
If you have a formal data protection officer, be careful about making them the AI owner as well. UK GDPR says a DPO’s other tasks mustn’t create a conflict of interest, and an owner who approves tools would then be advising on their own decisions. For the data protection lead’s part, the guide to whether an AI tool needs a DPIA has a screening test they can run.
Do you need an AI governance committee?
Usually not at first. A committee earns its place once one of these is true:
- several teams are buying or building AI on their own budgets
- you use AI for decisions about people, such as hiring or credit
- AI is part of what you sell to clients
- a client, a regulator or your insurer expects one
Below that point a committee mostly adds meetings. The owner, plus a standing item on the senior team’s agenda, does the same job with less ceremony.
Who should be on an AI governance committee?
Keep it small. The AI owner usually chairs it, and it needs one member of the senior team who can make decisions on the board’s behalf. Add IT, the data protection lead and HR, plus the heads of the one or two teams that use AI most. If AI touches client work, include whoever answers to clients. Five to seven people is enough.
Give it short terms of reference, a page at most. They should cover:
- its purpose, and which decisions it makes and which it only advises on
- the members, the chair and who stands in for each
- a quorum, such as three members including the chair
- the decisions it can take on its own, such as approving a tool or accepting a risk up to a level the board has set
- how often it meets, for example quarterly, and when it meets out of cycle, such as for an incident
- what it reports to the board, and how often
What do you tell a client who asks?
Supplier questionnaires and insurance renewal forms often ask who is responsible for AI in your organisation. Answer with a role, a name if they ask for one, and what the board does. For example:
Our operations director is responsible for AI use day to day, including approving new tools and keeping our register of AI in use. Our board agrees our AI policy and reviews how AI is used twice a year.
Swap in your own role and cadence. Only write what’s true today. A questionnaire answer can end up in a contract.
What ISO 42001 and the EU AI Act say about roles
ISO 42001, the AI management system standard, asks top management to assign responsibilities and authorities for the relevant roles and communicate them. That’s Clause 5.3, part of the leadership clause covered in the guide to the ISO 42001 requirements. A named owner and a table like the one above make a start on it.
The EU AI Act asks for named people too, if it reaches you. A deployer of a high-risk AI system must assign human oversight to people with the competence, training and authority to do it, under Article 26(2). And Article 4 asks organisations to support the development of AI literacy among staff who deal with AI, which in practice falls to the owner and HR.
If you’re working out what governance covers before deciding who owns it, what AI governance is sets out the pieces, and where to start with AI governance covers the first move.