Back to guides

Guide · Governance

AI System Ownership, RACI, and Risk Acceptance

Ungoverned AI is everyone-and-nobody's problem. APRF Organizational Governance requires a named owner, RACI for control gates, and explicit risk acceptance when you ship with residual gaps.

Orphan AI systems fail Organizational Governance—named owners, RACI, and time-boxed risk acceptance are mandatory. Primary control: Organizational Governance

Every AI system needs a human with a name

Organizational governance assigns who owns the system, who approves high-impact changes, who accepts residual risk, and who is paged on SEVs. A "temporary" support bot ran a year on a shared key; after a CRM leak, legal asked for the owner—there was none. The fix: register owner + deputy, RACI across Safety/Security/Data, and time-boxed risk acceptance for any waived Core Profile fail.

Make accountability operational

Maintain a system register (name, purpose, owner, deputy, data classes, tool impact). Publish RACI for Safety, Security, Data, Evaluation, Cost, and Incident. Define who can raise autonomy, add MCP tools, or expand corpus. Written exceptions with expiry and Approver—no infinite waivers. Quarterly ownership review to kill orphans. Incident roster must match the register.

Governance is an APRF pillar, not a slide

APRF Organizational Governance turns roles into gates. Link Change Management and Human Approval when autonomy or tools change.

Assess against APRF Core

Run the Core Profile quiz — gated pass/fail blockers for AI production readiness, not a vanity score.

Frequently asked questions

Can a committee be the owner?
Committees advise. APRF expects a single accountable owner (and deputy) who can make containment decisions.
How does this relate to Compliance?
Ownership and risk acceptance are how you produce Compliance evidence—policies without named humans fail audits.
What if we use a third-party bot?
You still own the business system: data sent, users affected, and kill/disable authority in your tenant.